{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-8d56c5e8e7340814", "name": "Possibly dead Python function: do_GET", "shortDescription": {"text": "Possibly dead Python function: do_GET"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7239b258eb136607", "name": "Possibly dead Python function: print_path_result", "shortDescription": {"text": "Possibly dead Python function: print_path_result"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fda48d50cd3ed6c", "name": "Possibly dead Python function: save_code_block", "shortDescription": {"text": "Possibly dead Python function: save_code_block"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a33910cbf737ce49", "name": "Possibly dead Python function: save_inline_code", "shortDescription": {"text": "Possibly dead Python function: save_inline_code"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-927c9c0444608eff", "name": "Possibly dead Python function: start_all", "shortDescription": {"text": "Possibly dead Python function: start_all"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c744bdbc1f2a9cf6", "name": "Possibly dead Python function: run_ws", "shortDescription": {"text": "Possibly dead Python function: run_ws"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-996f6d6800010195", "name": "Possibly dead Python function: do_POST", "shortDescription": {"text": "Possibly dead Python function: do_POST"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-794e51cec8ad83e2", "name": "Possibly dead Python function: fetch_messages_between_dates", "shortDescription": {"text": "Possibly dead Python function: fetch_messages_between_dates"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bfee88051c543a35", "name": "Possibly dead Python function: on_c2c_message_create", "shortDescription": {"text": "Possibly dead Python function: on_c2c_message_create"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70e69d3b87abc90b", "name": "Possibly dead Python function: migrate_config", "shortDescription": {"text": "Possibly dead Python function: migrate_config"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97b9eb9752891f73", "name": "Possibly dead Python function: cleanup_old_tasks", "shortDescription": {"text": "Possibly dead Python function: cleanup_old_tasks"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-576feecb668d0d07", "name": "Possibly dead Python function: require_auth", "shortDescription": {"text": "Possibly dead Python function: require_auth"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0e5702164c7711a", "name": "Possibly dead Python function: require_admin", "shortDescription": {"text": "Possibly dead Python function: require_admin"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af5c47d67c59fb2b", "name": "Possibly dead Python function: go", "shortDescription": {"text": "Possibly dead Python function: go"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c15c215bf42de679", "name": "Possibly dead Python function: ensure_root", "shortDescription": {"text": "Possibly dead Python function: ensure_root"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb0e6799d8edd865", "name": "Possibly dead Python function: advance_stage", "shortDescription": {"text": "Possibly dead Python function: advance_stage"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a329a4db61e4ee2", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/ThemeScript.tsx:45", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/ThemeScript.tsx:45"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-2141675e2fb7db20", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/Mermaid.tsx:174", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/Mermaid.tsx:174"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-a5c626ad775912a3", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/settings/ServiceConfigEditor.tsx:295", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/settings/ServiceConfigEditor.tsx:295"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d9a5a5fd9557542a", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/settings/SettingsSectionGrid.tsx:142", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/settings/SettingsSectionGrid.tsx:142"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d69580d30b810282", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/notebook/NotebookSelector.tsx:119", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/notebook/NotebookSelector.tsx:119"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-99bd705ad40d269a", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerModelPicker.tsx:48", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerModelPicker.tsx:48"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-47f59fd0d28b7198", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerChat.tsx:172", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerChat.tsx:172"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-110c4059dece2b53", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerChannels.tsx:228", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerChannels.tsx:228"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-748322bdbc32589a", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerComposer.tsx:388", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerComposer.tsx:388"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-9c8498360502c064", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerModelSelect.tsx:117", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerModelSelect.tsx:117"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-312ad3325c96864e", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerArchives.tsx:205", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerArchives.tsx:205"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-a4708c39bab85d26", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerConfigure.tsx:518", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerConfigure.tsx:518"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-d64dfe47ffc3983a", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/ToolPicker.tsx:39", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/ToolPicker.tsx:39"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-0daa67db6d6a461f", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/auth/ProfileLink.tsx:69", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/auth/ProfileLink.tsx:69"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bc8da81d87ad1bf0", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/PersonasSection.tsx:321", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/PersonasSection.tsx:321"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-01ceb98e80378ac9", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/ScopeEditorModal.tsx:157", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/ScopeEditorModal.tsx:157"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f46547ebf2b99ee5", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/SkillsSection.tsx:639", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/SkillsSection.tsx:639"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4a40aafe9e326ed5", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/MyAgentsSection.tsx:462", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/MyAgentsSection.tsx:462"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-1abd0673b9ced96d", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/ScopePicker.tsx:151", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/ScopePicker.tsx:151"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-195890279bb09f25", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/NotebooksSection.tsx:322", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/NotebooksSection.tsx:322"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-379882c5eff1479f", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/SpaceDashboard.tsx:247", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/SpaceDashboard.tsx:247"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-546a1694a49ef64d", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/EduHubImportModal.tsx:186", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/EduHubImportModal.tsx:186"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c580854df355cf21", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/common/InlineFileCard.tsx:360", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/common/InlineFileCard.tsx:360"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-dd69efdf451ad687", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/QuestionBankPicker.tsx:283", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/QuestionBankPicker.tsx:283"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-1bce499baca14c3e", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/HistorySessionPicker.tsx:248", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/HistorySessionPicker.tsx:248"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c36174edab1bf0ea", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/BookReferencePicker.tsx:272", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/BookReferencePicker.tsx:272"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c742d467e8541c23", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/PersonaPicker.tsx:161", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/PersonaPicker.tsx:161"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-037d00120227da69", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/MyAgentsPicker.tsx:533", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/MyAgentsPicker.tsx:533"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-b55f2bce39eb0ee8", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/space/ChatSpaceMenu.tsx:266", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/space/ChatSpaceMenu.tsx:266"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-aa59a46a9036b259", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/preview/FilePreviewDrawer.tsx:184", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/preview/FilePreviewDrawer.tsx:184"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-586b3fd04c01c770", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/preview/previewers/XlsxPreview.tsx:162", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/preview/previewers/XlsxPreview.tsx:162"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-fb8f42add3d81c08", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/AgentSelector.tsx:95", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/AgentSelector.tsx:95"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-927dcc6ddd9cfad9", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ChatComposer.tsx:121", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ChatComposer.tsx:121"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f485c91624e6a931", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/SessionActivityPanel.tsx:422", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/SessionActivityPanel.tsx:422"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2d535ea4d3d30a48", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/SessionViewerPanel.tsx:668", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/SessionViewerPanel.tsx:668"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c8b3e5b624733f75", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/CapabilityConfigCard.tsx:100", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/CapabilityConfigCard.tsx:100"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-2307a540c39c196b", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ContextReferenceTree.tsx:152", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ContextReferenceTree.tsx:152"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-387c022df34bb3a1", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/PersonaSelector.tsx:146", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/PersonaSelector.tsx:146"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-23ca23682aee5724", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/AskUserOptions.tsx:620", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/AskUserOptions.tsx:620"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-8c5d931fbbc1a1ee", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ModelSelector.tsx:69", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ModelSelector.tsx:69"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-fd18c465ecea3701", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ComposerInput.tsx:431", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ComposerInput.tsx:431"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-601905c6a74792ec", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ChatMessages.tsx:206", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ChatMessages.tsx:206"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-54c11cfbc7b549a4", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/composer-field.tsx:64", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/composer-field.tsx:64"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c3672eb4ce6b41d2", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/KnowledgeSelector.tsx:97", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/KnowledgeSelector.tsx:97"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-9fd592fa8137327a", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizFollowupTabBody.tsx:140", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizFollowupTabBody.tsx:140"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-bb8a9d22bfc5d5bc", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizConfigPanel.tsx:271", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizConfigPanel.tsx:271"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-3ee881316c94a226", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizViewer.tsx:1179", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizViewer.tsx:1179"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-9bcba163e6d83f28", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/agents/ConnectedAgents.tsx:187", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/agents/ConnectedAgents.tsx:187"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-6f91108edf75cd31", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryL1Workbench.tsx:172", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryL1Workbench.tsx:172"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-56cc919e8fe56123", "name": "React Flow <Controls> without dark theming \u2014 web/components/memory/MemoryGraph.tsx:275", "shortDescription": {"text": "React Flow <Controls> without dark theming \u2014 web/components/memory/MemoryGraph.tsx:275"}, "fullDescription": {"text": "`<Controls>` ships with white buttons. Override `.react-flow__controls` and `.react-flow__controls-button` in your stylesheet or pass a styled wrapper.\n\nWhy: P1 in CHECKLIST.md \u2014 vendor defaults bleed light through.\nRule id: fq.controls.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-a4dbb8542e754d25", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemorySection.tsx:1060", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemorySection.tsx:1060"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-878888c5547425e5", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryRunPanel.tsx:326", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryRunPanel.tsx:326"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-68a059e82a1f3bc0", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryWorkbench.tsx:368", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryWorkbench.tsx:368"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-54574705abe33629", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/visualize/VisualizationViewer.tsx:333", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/visualize/VisualizationViewer.tsx:333"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-b8e7630d592f4141", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/BookRecent.tsx:79", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/BookRecent.tsx:79"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-5e9c0d8556e6b882", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/CoWriterRecent.tsx:67", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/CoWriterRecent.tsx:67"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-c75b88b7855adc10", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/VersionBadge.tsx:27", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/VersionBadge.tsx:27"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ddf37b48e633d76f", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgePage.tsx:225", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgePage.tsx:225"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-5575aac8153394c3", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgeHome.tsx:175", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgeHome.tsx:175"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-e3d021438aaab0f0", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/EngineDetail.tsx:204", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/EngineDetail.tsx:204"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-4b28745c97ed37c7", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgeBaseDetail.tsx:152", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgeBaseDetail.tsx:152"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f4723475a13fc060", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KbDocumentList.tsx:304", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KbDocumentList.tsx:304"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-93b8fa173b21299e", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KbFilePreview.tsx:230", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KbFilePreview.tsx:230"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-62975a1999dcaafd", "name": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/FileDropZone.tsx:342", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/FileDropZone.tsx:342"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-65c934674c8060a3", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/page.tsx:206", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/page.tsx:206"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-220f93ee13894be9", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/[partnerId]/page.tsx:250", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/[partnerId]/page.tsx:250"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f142df69e7c695a7", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/new/page.tsx:465", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/new/page.tsx:465"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-39bb21818167743d", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/home/[[...sessionId]]/page.tsx:1816", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/home/[[...sessionId]]/page.tsx:1816"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-6594e5d948fb59d3", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/co-writer/[docId]/page.tsx:2063", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/co-writer/[docId]/page.tsx:2063"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f3e34d24e6b94ccc", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookCreator.tsx:433", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookCreator.tsx:433"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-f97b0a799258d822", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookChatPanel.tsx:429", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookChatPanel.tsx:429"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-02d736a600b4ca43", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookProgressTimeline.tsx:", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookProgressTimeline.tsx:233"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-fca20dd3868c50ac", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(admin)/admin/users/page.tsx:350", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(admin)/admin/users/page.tsx:350"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-cfea1b572f5a3bbb", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(utility)/space/learning/page.tsx:165", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(utility)/space/learning/page.tsx:165"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-b421b452b1912a2b", "name": "Truncated text has no discoverable full-value affordance \u2014 web/app/(utility)/profile/page.tsx:254", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(utility)/profile/page.tsx:254"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-25c352d66aa83a13", "name": "Truncated text has no discoverable full-value affordance \u2014 web/features/multi-user/components/GrantEditor.tsx:67", "shortDescription": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/features/multi-user/components/GrantEditor.tsx:67"}, "fullDescription": {"text": "A visibly truncated value should expose its full text through an accessible tooltip, description, or equivalent interaction. Native `title=` is one option, but it is not the only valid implementation.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.65}}, {"id": "scanner-ec8716b9dd7be9ad", "name": "insecure hash algorithm sha1 \u2014 deeptutor/partners/channels/manager.py:158", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/partners/channels/manager.py:158"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-8b29a8a35ebdcd2b", "name": "dynamic urllib use detected \u2014 deeptutor/runtime/launcher.py:429", "shortDescription": {"text": "dynamic urllib use detected \u2014 deeptutor/runtime/launcher.py:429"}, "fullDescription": {"text": "Detected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.\n\nRule: python.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detected\nSeverity: WARNING\nOWASP: A01:2017 - Injection\nCWE: CWE-939: Improper Authorization in Handler for Custom URL Scheme\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-2c24da87184b3747", "name": "insecure hash algorithm sha1 \u2014 deeptutor/services/memory/snapshot/adapters.py:33", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/services/memory/snapshot/adapters.py:33"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-09b6eff95a2cfe3e", "name": "insecure hash algorithm sha1 \u2014 deeptutor/services/partners/manager.py:116", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/services/partners/manager.py:116"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-ca15dc09d8966343", "name": "insecure hash algorithm sha1 \u2014 deeptutor/services/partners/runtime.py:519", "shortDescription": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/services/partners/runtime.py:519"}, "fullDescription": {"text": "Detected SHA1 hash algorithm which is considered insecure. SHA1 is not collision resistant and is therefore not suitable as a cryptographic signature. Use SHA256 or SHA3 instead.\n\nRule: python.lang.security.insecure-hash-algorithms.insecure-hash-algorithm-sha1\nSeverity: WARNING\nOWASP: A03:2017 - Sensitive Data Exposure, A02:2021 - Cryptographic Failures, A04:2025 - Cryptographic Failures\nCWE: CWE-327: Use of a Broken or Risky Cryptographic Algorithm\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.75}}, {"id": "scanner-9115c1af216ee250", "name": "subprocess shell true \u2014 deeptutor/services/sandbox/runner/server.py:217", "shortDescription": {"text": "subprocess shell true \u2014 deeptutor/services/sandbox/runner/server.py:217"}, "fullDescription": {"text": "Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.\n\nRule: python.lang.security.audit.subprocess-shell-true.subprocess-shell-true\nSeverity: ERROR\nOWASP: A01:2017 - Injection, A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-9c93156888d867c2", "name": "CVE-2026-13149: brace-expansion 1.1.14 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 1.1.14 \u2014 web/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 1.1.14\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a05f4c500f91e16", "name": "CVE-2026-13149: brace-expansion 2.1.1 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 2.1.1 \u2014 web/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 2.1.1\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1fea18ce3c855002", "name": "CVE-2026-49458: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7bd40700299a13f2", "name": "CVE-2026-49459: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-44416cca6c3853f9", "name": "CVE-2026-49978: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ac7ec7a2936251f", "name": "GHSA-76mc-f452-cxcm: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n# Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\n**CWE**: CWE-501 (Trust Boundary Violation \u2014 hook-scoped mutation leaks to global default sets) via CWE-693 (Protection Mechanism Failure \u2014 the default allow-list is silently widened for all subsequent sanitize calls)\n\n## Summary\n\nThe `data.allowedTags` and `data.allowedAttributes` fields passed to `uponSanitizeElement` and `uponSanitizeAttribute` hooks are **dir\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb09d3dfa44368ef", "name": "GHSA-cmwh-pvxp-8882: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\n## Summary\n\nDOMPurify 3.4.7 shipped a security fix (\"permanent hook pollution\") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** \u2014 so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALLOWED_ATTR` inside `_parseConfig`.\n\nThat guard is **silently bypassed whenever the application uses the persistent-config API `DOMPurify.setConfig()`.** `setConfig()` sets the module flag `SET_CONFIG = t\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e5b2e357cab1152", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b28170524c17c05", "name": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\n## Summary\n\nWhen DOMPurify is configured with both `SAFE_FOR_TEMPLATES: true` and `RETURN_DOM: true` (or `IN_PLACE: true`), an attacker can inject template expressions, such as `${evil}`, `{{evil}}`, or `<%evil%>`, that survive the sanitization pass inside `<template>` element content. This bypasses the explicit purpose of `SAFE_FOR_TEMPLATES`, which is to prevent template engine evaluation of user-supplied content.\n\n> **Note:** The string output path is **not** affected. Only the DOM return pat\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-533ad82f1737d3aa", "name": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output\n\n## Impact\n\nA DOMPurify instance that is reused across trust boundaries can stay bound to a previously supplied `TRUSTED_TYPES_POLICY` even after `clearConfig()` is called. A later caller that requests `RETURN_TRUSTED_TYPE` receives a `TrustedHTML` object created by the old policy, not by a clean default configuration.\n\nIf the old policy is unsafe or controlled by a less-trusted integration, this turns a later \"default\" sanitize call into script execution at a Trusted Types sink. `TRUSTED_TYPES_P\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73600bbf0a106a75", "name": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.0 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects\n\n## Summary\n\nWhen `DOMPurify.sanitize(root, { IN_PLACE: true })` is called on an attacker-supplied live DOM node, `DOMPurify` still trusts `currentNode.nodeName` for non-`form` nodes in the main `_sanitizeElements` pipeline. A real `<script>` child node whose observable `nodeName` is attacker-controlled can therefore be misclassified as an allowed element and retained. When the sanitized tree is inserted into a live document, the script executes.\n\nThis affects current `3.4.6`. The recent `IN_PLAC\n\nPackage: dompurify\nInstalled: 3.4.0\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33b3260f6fb18791", "name": "CVE-2026-41148: mermaid 11.14.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: CSS injection vulnerability allows page defacement and information disclosure\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style strings through the createCssStyles parser) captures classDef values using an unrestricted regex that matches everything up to a newline. That value then flows unsanitized through \n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-361ed789414a9cf6", "name": "CVE-2026-41149: mermaid 11.14.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: HTML injection via classDef directive in state diagrams\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM injection that escapes the SVG context. However, <script> tags are stripped, which prevents cross-site scripting (XSS). This issue has been fixed in versions 10.9.6 and 11.15.0. If de\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81e498f6946a76e2", "name": "CVE-2026-41150: mermaid 11.14.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Denial of Service via specially crafted gantt charts\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fbe80bac0abee1bc", "name": "CVE-2026-41159: mermaid 11.14.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "mermaid: Mermaid: Information disclosure and page defacement via CSS injection\n\nMermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0,  Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS exploits stylis's & (scope reference) handling. :not(&) escapes the #mermaid-xxx automatic scoping, applying styles to all page elements. Global at-rules (@font-face, @keyframes, @c\n\nPackage: mermaid\nInstalled: 11.14.0\nFixed in: 11.15.0, 10.9.6\nSeverity: MEDIUM\nFix: Upgrade mermaid to 11.15.0, 10.9.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-99cc41c6b7c3ac3e", "name": "CVE-2026-44573: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44573: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed data route, allowing an attacker to retrieve SSR JSON for protected pages without passing the intende\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-de3e4518cb40778c", "name": "CVE-2026-44574: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44574: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Authorization bypass via crafted query parameters\n\nNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnerability is fixed in 1\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8d43addef3f7d914", "name": "CVE-2026-44575: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44575: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Unauthorized access to protected content via middleware bypass\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the same page without being matched by the intended middleware rule, which can allow protected content to\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fd10c5ba94ed11cf", "name": "CVE-2026-44578: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44578: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests\n\nNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vulnerability is fixed\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-188950c91d40caae", "name": "CVE-2026-44579: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44579: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service via crafted POST requests to server actions\n\nNext.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open for an extended period, consuming file descriptors and server capacity until legitimate users are den\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-48a1fb7c2e28f674", "name": "CVE-2026-45109: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-45109: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Information disclosure via security fix bypass in middleware with Turbopack\n\nNext.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.18, 16.2.6\nSeverity: HIGH\nFix: Upgrade next to 15.5.18, 16.2.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb8ba3361968a14b", "name": "CVE-2026-64641: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64641: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in App Router using Server Actions\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.\n\n## Workarounds\n\nNo workaround exists besides upgrading. Applications using Pages Router or not using Server Actions are not vulnerable.\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-53ec088e86c457af", "name": "CVE-2026-64642: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64642: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\n## Impact\n\nCrafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.\n\n## Workarounds\n\nIf you cannot upgrade immediately, enforce authorization in the page's server-side data path instead of relying solely on middleware.\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76d19ed1f7b581ba", "name": "CVE-2026-64645: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64645: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\n## Impact\n\nA `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's\u00a0hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response from the application's origin, leading to Server-Side Request forgery. A `redirects()` rule configured this way is vulnerable to an Open Redirect.\n\nThis affects any destination that puts a dynamic segmen\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b9b6083696bb6457", "name": "CVE-2026-64649: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64649: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Server-Side Request Forgery in Server Actions on custom servers\n\n## Impact\n\nWhen a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to obtain internal values that weaken middleware/proxy authorization.\n\nApplications that use Server Actions are affected when the incoming host header is not fixed to a trusted value. This typically occurs\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: HIGH\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a13d5efd0c28afd", "name": "GHSA-8h8q-6873-q5fj: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-8h8q-6873-q5fj: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components\n\nA vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23870](https://github.com/facebook/react/security/advisories/GHSA-rv78-f8rc-xrxh). \n\nA specially crafted HTTP request can be sent to any App Router Server Function endpoint that, when deserialized, may trigger excessive CPU usage. This can result in denial of \n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: HIGH\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3fc29b6fc2ff0d53", "name": "CVE-2026-44576: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44576: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning vulnerability in React Server Components\n\nNext.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later visitors receive component payloads instead of the expected HTML. This vulnerability is fixed in 15.5\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d1e86583da8b084", "name": "CVE-2026-44577: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44577: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Denial of Service via Image Optimization API\n\nNext.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that match the images.localPatterns configuration (by default, all patterns are allowed). This vulnerability\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24d6d22462431ddd", "name": "CVE-2026-44580: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44580: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Cross-site scripting allows arbitrary code execution via untrusted script content\n\nNext.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to break out of the intended script context and execute arbitrary JavaScript in a visitor's browser. This vu\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dc044f1e63bcba7f", "name": "CVE-2026-44581: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44581: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Stored Cross-Site Scripting via malformed nonce values in cached responses\n\nNext.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to poison cached responses and cause script execution for later visitors. This vulnerability is fixed i\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-649befb39e80cfcd", "name": "CVE-2026-64643: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64643: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Unauthenticated disclosure of internal Server Function endpoints\n\n## Impact\n\nIn Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.\n\nServer Action IDs can be disclosed to unauthenticated users via publicly served client artifacts (for example, static chunks containing action references).\n\nAffected users are applications using App Router + Server Actions.  \n\nBy itself, this disclosure is typically a recon/enumeration primi\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-646418b4113a82f6", "name": "CVE-2026-64644: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64644: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Denial of Service in the Image Optimization API using SVGs\n\n### Impact\n\nWhen self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in  `/_next/image` endpoints.\n\n- If you are using `config.images.remotePatterns`, only the patterns in that array are impacted.\n- If you are using `config.images.unoptimized: true`, you are NOT impacted.\n- If you are using `config.images.loader: 'custom'`\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5999475aad96f80b", "name": "CVE-2026-64646: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64646: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Unbounded Server Action payload in Edge runtime\n\n## Impact\n\nRequests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime\n\n## Workarounds\n\nIf you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should be allowed at max by your hosting provider.\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8c40d0276e6b52a4", "name": "CVE-2026-64647: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64647: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis is only an issue when receiving request bodies with a content type charset other than UTF-8. For example, the UTF-16 byte sequences for `\uc083\uc083` and `\uc104\uc104` in the request body would share the same cache.\n\n##\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-63197c94a3693fdf", "name": "CVE-2026-64648: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-64648: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Cache confusion of response bodies for requests with bodies\n\n## Impact\n\nA server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.\n\nThis only applies to `fetch` calls with a request that has a different init than the one passed to `fetch`.\nSafe: `fetch(new Request(init), init)`\nUnsafe: `fetch(new Request(init), aDifferentInit)`\n\n## Work\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.21, 16.2.11\nSeverity: MEDIUM\nFix: Upgrade next to 15.5.21, 16.2.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16760f00ea730875", "name": "CVE-2026-44572: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44572: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "next.js: Next.js: Denial of Service due to improper handling of x-nextjs-data header with redirects\n\nNext.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nextjs-redirect header. Browsers do not follow x-nextjs-redirect, so the response became an unusable red\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2df29f9ede12ce44", "name": "CVE-2026-44582: next 16.2.3 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-44582: next 16.2.3 \u2014 web/package-lock.json"}, "fullDescription": {"text": "Next.js: Next.js: Cache poisoning allows incorrect response delivery\n\nNext.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the wrong response variant for a given URL. This vulnerability is fixed in 15.5.16 and 16.2.5.\n\nPackage: next\nInstalled: 16.2.3\nFixed in: 15.5.16, 16.2.5\nSeverity: LOW\nFix: Upgrade next to 15.5.16, 16.2.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-745c333bbc7b47df", "name": "CVE-2026-41305: postcss 8.4.31 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 web/package-lock.json"}, "fullDescription": {"text": "postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags\n\nPostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the style context, enabling XSS. Version 8.5.10 fixes the issue.\n\nPackage: postcss\nInstalled: 8.4.31\nFixed in: 8.5.10\nSeverity: MEDIUM\nFix: Upgrade postcss to 8.5.10"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-133910447fa2165a", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 web/package-lock.json", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 web/package-lock.json"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-876259069f5195e3", "name": "CVE-2026-41907: uuid 11.1.0 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 web/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 11.1.0\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81380ffa621907c4", "name": "CVE-2026-41907: uuid 8.3.2 \u2014 web/package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 web/package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 8.3.2\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a3527e70129fb18", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ad0c3fb4e1c91b75", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.runner", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.runner"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile.runner"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f76567934ce2c9e8", "name": "Privileged port 10 in use", "shortDescription": {"text": "Privileged port 10 in use"}, "fullDescription": {"text": "Port 10 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93e02e0d67c8f3e8", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e066691601852931", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0c875fab812197d", "name": "Docker base image uses a mutable or implicit tag: pathlib", "shortDescription": {"text": "Docker base image uses a mutable or implicit tag: pathlib"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f39b9f5db34a2774", "name": "Docker base image uses a mutable or implicit tag: deeptutor.services.setup", "shortDescription": {"text": "Docker base image uses a mutable or implicit tag: deeptutor.services.setup"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b8e6f9ee00b7ed30", "name": "Docker base image uses a mutable or implicit tag: deeptutor.services.config", "shortDescription": {"text": "Docker base image uses a mutable or implicit tag: deeptutor.services.config"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-295aa83a3709f7e3", "name": "Insecure pattern 'dangerous_innerhtml' in web/components/ThemeScript.tsx:45", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in web/components/ThemeScript.tsx:45"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-0d03a3721d1dccf8", "name": "Insecure pattern 'dangerous_innerhtml' in web/components/Mermaid.tsx:174", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in web/components/Mermaid.tsx:174"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-56ef3c080812c3d8", "name": "Insecure pattern 'dangerous_innerhtml' in web/components/visualize/VisualizationViewer.tsx:333", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in web/components/visualize/VisualizationViewer.tsx:333"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-c70e23b4a2eb0344", "name": "Insecure pattern 'subprocess_shell_true' in deeptutor/services/sandbox/runner/server.py:215", "shortDescription": {"text": "Insecure pattern 'subprocess_shell_true' in deeptutor/services/sandbox/runner/server.py:215"}, "fullDescription": {"text": "Found a known-risky pattern (subprocess_shell_true). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7092ef6b42892f71", "name": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/openai_http_client.py:42", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/openai_http_client.py:42"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b9b8e6f14bd2cce0", "name": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/providers/open_ai.py:65", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/providers/open_ai.py:65"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58b7c97a2cb428d0", "name": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/provider_core/openai_codex_provider.py:86", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/provider_core/openai_codex_provider.py:86"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fc13aaa9ee76962a", "name": "Insecure pattern 'tls_verify_false' in deeptutor/core/agentic/client.py:67", "shortDescription": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/core/agentic/client.py:67"}, "fullDescription": {"text": "Found a known-risky pattern (tls_verify_false). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58288fdbe718b8e9", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7e207e1f1c64778", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5af2dfac961b2a63", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f32678841e6e849", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a50467f36b413ec", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-365ae647c92ac3d5", "name": "Very large file: tests/services/test_subagent_backends.py (1359 lines)", "shortDescription": {"text": "Very large file: tests/services/test_subagent_backends.py (1359 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37e2b5ac18af03bd", "name": "Very large file: web/components/settings/ServiceConfigEditor.tsx (1191 lines)", "shortDescription": {"text": "Very large file: web/components/settings/ServiceConfigEditor.tsx (1191 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae1d0a7141c595b5", "name": "Very large file: web/components/chat/home/TracePanels.tsx (2589 lines)", "shortDescription": {"text": "Very large file: web/components/chat/home/TracePanels.tsx (2589 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82a299fdd6e0bbb2", "name": "Very large file: web/components/chat/home/ChatMessages.tsx (1496 lines)", "shortDescription": {"text": "Very large file: web/components/chat/home/ChatMessages.tsx (1496 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be6e747bfb9702fe", "name": "Very large file: web/components/quiz/QuizViewer.tsx (1431 lines)", "shortDescription": {"text": "Very large file: web/components/quiz/QuizViewer.tsx (1431 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e119636ad9c25b2", "name": "Very large file: web/components/memory/MemorySection.tsx (1522 lines)", "shortDescription": {"text": "Very large file: web/components/memory/MemorySection.tsx (1522 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20a9da65a69c425f", "name": "Very large file: web/app/(workspace)/playground/page.tsx (2077 lines)", "shortDescription": {"text": "Very large file: web/app/(workspace)/playground/page.tsx (2077 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2bb50cc0dda553f0", "name": "Very large file: web/app/(workspace)/home/[[...sessionId]]/page.tsx (2202 lines)", "shortDescription": {"text": "Very large file: web/app/(workspace)/home/[[...sessionId]]/page.tsx (2202 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8c78a0a1d4a1aa1", "name": "Very large file: web/app/(workspace)/co-writer/[docId]/page.tsx (2495 lines)", "shortDescription": {"text": "Very large file: web/app/(workspace)/co-writer/[docId]/page.tsx (2495 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba03f6a69be0ef66", "name": "Very large file: web/context/UnifiedChatContext.tsx (1885 lines)", "shortDescription": {"text": "Very large file: web/context/UnifiedChatContext.tsx (1885 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e2852e2f7e8b268", "name": "Very large file: deeptutor/partners/channels/feishu.py (1344 lines)", "shortDescription": {"text": "Very large file: deeptutor/partners/channels/feishu.py (1344 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a3eb3c545d90134", "name": "Very large file: deeptutor/partners/channels/weixin.py (1564 lines)", "shortDescription": {"text": "Very large file: deeptutor/partners/channels/weixin.py (1564 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec8c79ec4e9a027f", "name": "Very large file: deeptutor/api/routers/knowledge.py (2808 lines)", "shortDescription": {"text": "Very large file: deeptutor/api/routers/knowledge.py (2808 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4380e9f03167a520", "name": "Very large file: deeptutor/agents/question/pipeline.py (2161 lines)", "shortDescription": {"text": "Very large file: deeptutor/agents/question/pipeline.py (2161 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67260fb4f0ee55b4", "name": "Very large file: deeptutor/agents/research/pipeline.py (2800 lines)", "shortDescription": {"text": "Very large file: deeptutor/agents/research/pipeline.py (2800 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70c8b2b9e9de5e04", "name": "Very large file: deeptutor/agents/chat/agentic_pipeline.py (1420 lines)", "shortDescription": {"text": "Very large file: deeptutor/agents/chat/agentic_pipeline.py (1420 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ffb7730f7a6bf7fc", "name": "Very large file: deeptutor/services/partners/manager.py (1291 lines)", "shortDescription": {"text": "Very large file: deeptutor/services/partners/manager.py (1291 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fbb34a11e46e7c77", "name": "Very large file: deeptutor/services/session/turn_runtime.py (2042 lines)", "shortDescription": {"text": "Very large file: deeptutor/services/session/turn_runtime.py (2042 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0a2c31ffb8b93aa", "name": "Very large file: deeptutor/services/session/sqlite_store.py (1844 lines)", "shortDescription": {"text": "Very large file: deeptutor/services/session/sqlite_store.py (1844 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3269bae97c740d39", "name": "Very large file: deeptutor/tools/builtin/__init__.py (1595 lines)", "shortDescription": {"text": "Very large file: deeptutor/tools/builtin/__init__.py (1595 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96c8cf4f840335cd", "name": "Very large file: deeptutor/book/engine.py (1290 lines)", "shortDescription": {"text": "Very large file: deeptutor/book/engine.py (1290 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-097e319e326323e5", "name": "Very large file: deeptutor/knowledge/manager.py (1763 lines)", "shortDescription": {"text": "Very large file: deeptutor/knowledge/manager.py (1763 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 196 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 220 placeholder/mock markers across 83 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-398295a4d3bf2a0c", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/docker_compose.py:107", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/docker_compose.py:107"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-f1e68c70c216985a", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/prepare_web_package.py:33", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/prepare_web_package.py:33"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-b35dbf54c237b7b9", "name": "Legacy-named symbol `isLegacy` in web/components/knowledge/KbIndexVersionsSection.tsx:230", "shortDescription": {"text": "Legacy-named symbol `isLegacy` in web/components/knowledge/KbIndexVersionsSection.tsx:230"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-974abd53354bfa9b", "name": "Legacy-named symbol `mOld` in web/lib/memory-graph.ts:165", "shortDescription": {"text": "Legacy-named symbol `mOld` in web/lib/memory-graph.ts:165"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82afcc581d9413bb", "name": "Legacy-named symbol `migrateLegacy` in web/lib/chat-import/agent-store.ts:49", "shortDescription": {"text": "Legacy-named symbol `migrateLegacy` in web/lib/chat-import/agent-store.ts:49"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4da68657f8ba80ed", "name": "Legacy-named symbol `receive_v1` in deeptutor/partners/channels/feishu.py:274", "shortDescription": {"text": "Legacy-named symbol `receive_v1` in deeptutor/partners/channels/feishu.py:274"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-584548fbf58674b7", "name": "Blocking `time.sleep(...)` inside `async def start` \u2014 deeptutor/partners/channels/feishu.py:379", "shortDescription": {"text": "Blocking `time.sleep(...)` inside `async def start` \u2014 deeptutor/partners/channels/feishu.py:379"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `time.sleep(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bcf8edeca8402e2d", "name": "Stub function `log_message` (body is just `pass`/`return`) \u2014 deeptutor/partners/channels/msteams.py:215", "shortDescription": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 deeptutor/partners/channels/msteams.py:215"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6dab644f053f63c", "name": "Legacy-named symbol `files_upload_v2` in deeptutor/partners/channels/slack.py:154", "shortDescription": {"text": "Legacy-named symbol `files_upload_v2` in deeptutor/partners/channels/slack.py:154"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84a64e2a5b49eecb", "name": "Legacy-named symbol `data_copy` in deeptutor/agents/research/data_structures.py:229", "shortDescription": {"text": "Legacy-named symbol `data_copy` in deeptutor/agents/research/data_structures.py:229"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a759a9a2269810a", "name": "Stub function `emit_terminator` (body is just `pass`/`return`) \u2014 deeptutor/agents/research/pipeline.py:2422", "shortDescription": {"text": "Stub function `emit_terminator` (body is just `pass`/`return`) \u2014 deeptutor/agents/research/pipeline.py:2422"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5427f349a4397ef8", "name": "Network/subprocess call without timeout or try/except \u2014 deeptutor/runtime/launcher.py:122", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 deeptutor/runtime/launcher.py:122"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-09741fbf52192614", "name": "Legacy-named symbol `model_copy` in deeptutor/services/partners/model_runtime.py:32", "shortDescription": {"text": "Legacy-named symbol `model_copy` in deeptutor/services/partners/model_runtime.py:32"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad43c1f596c2e7ad", "name": "Legacy-named symbol `_migrated_legacy` in deeptutor/services/partners/manager.py:286", "shortDescription": {"text": "Legacy-named symbol `_migrated_legacy` in deeptutor/services/partners/manager.py:286"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-039b242ab55b75ba", "name": "Legacy-named symbol `nested_legacy` in deeptutor/services/rag/index_versioning.py:135", "shortDescription": {"text": "Legacy-named symbol `nested_legacy` in deeptutor/services/rag/index_versioning.py:135"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6040d91dfded6d75", "name": "Legacy-named symbol `nested_legacy` in deeptutor/services/rag/pipelines/llamaindex/storage.py:41", "shortDescription": {"text": "Legacy-named symbol `nested_legacy` in deeptutor/services/rag/pipelines/llamaindex/storage.py:41"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b0fe5b3ba01e677", "name": "Legacy-named symbol `baidu_search_v2` in deeptutor/services/search/providers/baidu.py:37", "shortDescription": {"text": "Legacy-named symbol `baidu_search_v2` in deeptutor/services/search/providers/baidu.py:37"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-445415a8b8f6bc5f", "name": "Stub function `_get_session_id_prefix` (body is just `pass`/`return`) \u2014 deeptutor/services/session/base_session_manager.", "shortDescription": {"text": "Stub function `_get_session_id_prefix` (body is just `pass`/`return`) \u2014 deeptutor/services/session/base_session_manager.py:70"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c81ba773b1b44aa", "name": "Legacy-named symbol `model_copy` in deeptutor/services/llm/config.py:120", "shortDescription": {"text": "Legacy-named symbol `model_copy` in deeptutor/services/llm/config.py:120"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a94b4b16d9a3baa5", "name": "Legacy-named symbol `model_copy` in deeptutor/services/llm/factory.py:230", "shortDescription": {"text": "Legacy-named symbol `model_copy` in deeptutor/services/llm/factory.py:230"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd1e7ac900f10ce2", "name": "Stub function `_default_sleep` (body is just `pass`/`return`) \u2014 deeptutor/services/llm/providers/base_provider.py:185", "shortDescription": {"text": "Stub function `_default_sleep` (body is just `pass`/`return`) \u2014 deeptutor/services/llm/providers/base_provider.py:185"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-575a8ec6d52e99da", "name": "Legacy-named symbol `no_backup` in deeptutor/knowledge/manager.py:1754", "shortDescription": {"text": "Legacy-named symbol `no_backup` in deeptutor/knowledge/manager.py:1754"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a260e355ea7d9f89", "name": "32 env vars used in code but missing from .env.example", "shortDescription": {"text": "32 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AUTH_ENABLED`, `BACKEND_PORT`, `CI`, `CODEX_HOME`, `DEEPTUTOR_API_BASE_URL`, `DEEPTUTOR_AUTH_ENABLED`, `DEEPTUTOR_HUB_TOKEN`, `DEEPTUTOR_MODE` + 24 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same substantial AST body hash:\ndeeptutor/services/rag/pipelines/graphrag/storage.py:65:write_meta, deeptutor/services/rag/pipelines/lightrag/storage.py:145:write_meta\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faade12274512e92", "name": "FastAPI DELETE `delete_book` without auth dependency \u2014 deeptutor/api/routers/book.py:189", "shortDescription": {"text": "FastAPI DELETE `delete_book` without auth dependency \u2014 deeptutor/api/routers/book.py:189"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-fe9fa73788605f1a", "name": "FastAPI POST `create_book` without auth dependency \u2014 deeptutor/api/routers/book.py:198", "shortDescription": {"text": "FastAPI POST `create_book` without auth dependency \u2014 deeptutor/api/routers/book.py:198"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8bf640620ab68f81", "name": "FastAPI POST `confirm_proposal` without auth dependency \u2014 deeptutor/api/routers/book.py:224", "shortDescription": {"text": "FastAPI POST `confirm_proposal` without auth dependency \u2014 deeptutor/api/routers/book.py:224"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d7f1af5627c3e784", "name": "FastAPI POST `confirm_spine` without auth dependency \u2014 deeptutor/api/routers/book.py:247", "shortDescription": {"text": "FastAPI POST `confirm_spine` without auth dependency \u2014 deeptutor/api/routers/book.py:247"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-223d1dc82f8d0477", "name": "FastAPI POST `compile_page` without auth dependency \u2014 deeptutor/api/routers/book.py:271", "shortDescription": {"text": "FastAPI POST `compile_page` without auth dependency \u2014 deeptutor/api/routers/book.py:271"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3f45242b804fd2f6", "name": "FastAPI POST `regenerate_block` without auth dependency \u2014 deeptutor/api/routers/book.py:285", "shortDescription": {"text": "FastAPI POST `regenerate_block` without auth dependency \u2014 deeptutor/api/routers/book.py:285"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ba1614efe4eea97c", "name": "FastAPI POST `insert_block` without auth dependency \u2014 deeptutor/api/routers/book.py:317", "shortDescription": {"text": "FastAPI POST `insert_block` without auth dependency \u2014 deeptutor/api/routers/book.py:317"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d4bdcf7c7f2adfd7", "name": "FastAPI POST `delete_block` without auth dependency \u2014 deeptutor/api/routers/book.py:338", "shortDescription": {"text": "FastAPI POST `delete_block` without auth dependency \u2014 deeptutor/api/routers/book.py:338"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bc35c26dd40929f5", "name": "FastAPI POST `move_block` without auth dependency \u2014 deeptutor/api/routers/book.py:347", "shortDescription": {"text": "FastAPI POST `move_block` without auth dependency \u2014 deeptutor/api/routers/book.py:347"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-973dc6be67482625", "name": "FastAPI POST `change_block_type` without auth dependency \u2014 deeptutor/api/routers/book.py:361", "shortDescription": {"text": "FastAPI POST `change_block_type` without auth dependency \u2014 deeptutor/api/routers/book.py:361"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bebdab58ba7651cb", "name": "FastAPI POST `deep_dive` without auth dependency \u2014 deeptutor/api/routers/book.py:381", "shortDescription": {"text": "FastAPI POST `deep_dive` without auth dependency \u2014 deeptutor/api/routers/book.py:381"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-822d1bc911a412e2", "name": "FastAPI POST `quiz_attempt` without auth dependency \u2014 deeptutor/api/routers/book.py:401", "shortDescription": {"text": "FastAPI POST `quiz_attempt` without auth dependency \u2014 deeptutor/api/routers/book.py:401"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3f00d480b5d60885", "name": "FastAPI POST `refresh_fingerprints` without auth dependency \u2014 deeptutor/api/routers/book.py:423", "shortDescription": {"text": "FastAPI POST `refresh_fingerprints` without auth dependency \u2014 deeptutor/api/routers/book.py:423"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-afd11434706cb7d3", "name": "FastAPI POST `supplement` without auth dependency \u2014 deeptutor/api/routers/book.py:432", "shortDescription": {"text": "FastAPI POST `supplement` without auth dependency \u2014 deeptutor/api/routers/book.py:432"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7b6d642a6dc71ff1", "name": "FastAPI POST `set_page_chat_session` without auth dependency \u2014 deeptutor/api/routers/book.py:449", "shortDescription": {"text": "FastAPI POST `set_page_chat_session` without auth dependency \u2014 deeptutor/api/routers/book.py:449"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1d63f8e719eacfc7", "name": "FastAPI POST `rebuild_book` without auth dependency \u2014 deeptutor/api/routers/book.py:462", "shortDescription": {"text": "FastAPI POST `rebuild_book` without auth dependency \u2014 deeptutor/api/routers/book.py:462"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-79e9a196ed1b8cfe", "name": "FastAPI POST `sync_backend` without auth dependency \u2014 deeptutor/api/routers/subagents.py:79", "shortDescription": {"text": "FastAPI POST `sync_backend` without auth dependency \u2014 deeptutor/api/routers/subagents.py:79"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ad2731eb7d5b4097", "name": "FastAPI POST `create_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:132", "shortDescription": {"text": "FastAPI POST `create_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:132"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-78f3b14fe75c9873", "name": "FastAPI DELETE `delete_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:193", "shortDescription": {"text": "FastAPI DELETE `delete_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:193"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f744a1572a8aae0c", "name": "FastAPI POST `message_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:216", "shortDescription": {"text": "FastAPI POST `message_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:216"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8d6d0c3543bd576e", "name": "FastAPI POST `create_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:83", "shortDescription": {"text": "FastAPI POST `create_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:83"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-218fb75a2784dfdc", "name": "FastAPI PUT `rename_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:95", "shortDescription": {"text": "FastAPI PUT `rename_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:95"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bbbb15952bec1c41", "name": "FastAPI DELETE `delete_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:109", "shortDescription": {"text": "FastAPI DELETE `delete_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:109"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5424d52147ab6600", "name": "FastAPI POST `create_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:214", "shortDescription": {"text": "FastAPI POST `create_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:214"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-82cc516ffdac8e19", "name": "FastAPI POST `install_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:233", "shortDescription": {"text": "FastAPI POST `install_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:233"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-12bb9ab3946d3de4", "name": "FastAPI PUT `update_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:270", "shortDescription": {"text": "FastAPI PUT `update_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:270"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-a79924abf8fe37a9", "name": "FastAPI DELETE `delete_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:294", "shortDescription": {"text": "FastAPI DELETE `delete_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:294"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-a96141667f8a7959", "name": "FastAPI POST `edit_text` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:379", "shortDescription": {"text": "FastAPI POST `edit_text` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:379"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2f2325c50afbc37b", "name": "FastAPI POST `edit_text_react` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:403", "shortDescription": {"text": "FastAPI POST `edit_text_react` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:403"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3ad1b2ce35dc9916", "name": "FastAPI POST `edit_text_react_stream` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:414", "shortDescription": {"text": "FastAPI POST `edit_text_react_stream` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:414"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c981c42e503628e9", "name": "FastAPI POST `auto_mark_text` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:427", "shortDescription": {"text": "FastAPI POST `auto_mark_text` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:427"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5e5941ac9fd06fb2", "name": "FastAPI POST `create_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:558", "shortDescription": {"text": "FastAPI POST `create_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:558"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1aa86e3873a50cd5", "name": "FastAPI PUT `update_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:586", "shortDescription": {"text": "FastAPI PUT `update_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:586"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-aaea06d2d91fb298", "name": "FastAPI DELETE `delete_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:604", "shortDescription": {"text": "FastAPI DELETE `delete_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:604"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ab90b50c2e583efb", "name": "FastAPI PUT `set_rag_provider_mode` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1007", "shortDescription": {"text": "FastAPI PUT `set_rag_provider_mode` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1007"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bb6791eb4d41441f", "name": "FastAPI PUT `update_pageindex_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1062", "shortDescription": {"text": "FastAPI PUT `update_pageindex_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1062"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-23743522019fc909", "name": "FastAPI PUT `update_llamaindex_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1120", "shortDescription": {"text": "FastAPI PUT `update_llamaindex_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1120"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c0020dad9fa57ffd", "name": "FastAPI PUT `update_graphrag_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1160", "shortDescription": {"text": "FastAPI PUT `update_graphrag_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1160"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2e062f061d7eeca3", "name": "FastAPI PUT `update_lightrag_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1194", "shortDescription": {"text": "FastAPI PUT `update_lightrag_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1194"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-26f108f2cfa00164", "name": "FastAPI PUT `set_rag_active_model` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1293", "shortDescription": {"text": "FastAPI PUT `set_rag_active_model` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1293"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3be8c6ea28e248ce", "name": "FastAPI PUT `update_kb_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1374", "shortDescription": {"text": "FastAPI PUT `update_kb_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1374"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6b794ccd9c9354a8", "name": "FastAPI POST `sync_configs_from_metadata` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1424", "shortDescription": {"text": "FastAPI POST `sync_configs_from_metadata` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1424"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d5a4f5e0421e66d9", "name": "FastAPI PUT `set_default_kb` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1450", "shortDescription": {"text": "FastAPI PUT `set_default_kb` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1450"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-e43133e23040506a", "name": "FastAPI POST `connect_obsidian_vault` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1474", "shortDescription": {"text": "FastAPI POST `connect_obsidian_vault` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1474"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3f048647c84ba874", "name": "FastAPI POST `probe_linked_folder_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1512", "shortDescription": {"text": "FastAPI POST `probe_linked_folder_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1512"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-30e42421ad4368da", "name": "FastAPI POST `connect_linked_folder_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1531", "shortDescription": {"text": "FastAPI POST `connect_linked_folder_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1531"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7763595e1a1292d3", "name": "FastAPI POST `probe_lightrag_server_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1594", "shortDescription": {"text": "FastAPI POST `probe_lightrag_server_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1594"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-e6a40ec259ae238d", "name": "FastAPI POST `connect_lightrag_server_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1610", "shortDescription": {"text": "FastAPI POST `connect_lightrag_server_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1610"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ca9a4db6d1ed6630", "name": "FastAPI POST `create_kb_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1923", "shortDescription": {"text": "FastAPI POST `create_kb_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1923"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1e9aa37fa7f9fb6e", "name": "FastAPI POST `move_kb_file` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1937", "shortDescription": {"text": "FastAPI POST `move_kb_file` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1937"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c775ed4d407fc677", "name": "FastAPI DELETE `delete_kb_file` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2009", "shortDescription": {"text": "FastAPI DELETE `delete_kb_file` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2009"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7e74c092e13076b5", "name": "FastAPI DELETE `delete_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2033", "shortDescription": {"text": "FastAPI DELETE `delete_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2033"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-89852abedfc657e3", "name": "FastAPI POST `upload_files` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2061", "shortDescription": {"text": "FastAPI POST `upload_files` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2061"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-0e1d8772e0f495d9", "name": "FastAPI POST `create_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2140", "shortDescription": {"text": "FastAPI POST `create_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2140"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d826c0e04f49510e", "name": "FastAPI POST `reindex_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2379", "shortDescription": {"text": "FastAPI POST `reindex_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2379"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1691b8f630d8d0d0", "name": "FastAPI POST `retry_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2465", "shortDescription": {"text": "FastAPI POST `retry_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2465"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-08d0bb0ff261ac4e", "name": "FastAPI POST `clear_progress` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2511", "shortDescription": {"text": "FastAPI POST `clear_progress` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2511"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-69978076ef4ed629", "name": "FastAPI POST `link_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2671", "shortDescription": {"text": "FastAPI POST `link_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2671"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7d7738e13e5a597c", "name": "FastAPI DELETE `unlink_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2717", "shortDescription": {"text": "FastAPI DELETE `unlink_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2717"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c254a02ebbe3f045", "name": "FastAPI POST `sync_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2735", "shortDescription": {"text": "FastAPI POST `sync_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2735"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8b68bbb0d79882ad", "name": "FastAPI POST `execute_tool` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:114", "shortDescription": {"text": "FastAPI POST `execute_tool` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:114"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-28a0c0a0989f6342", "name": "FastAPI POST `execute_tool_stream` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:281", "shortDescription": {"text": "FastAPI POST `execute_tool_stream` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:281"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8521f88f39e3a5ed", "name": "FastAPI POST `execute_capability_stream` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:422", "shortDescription": {"text": "FastAPI POST `execute_capability_stream` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:422"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-844cdc2e07724656", "name": "FastAPI POST `upsert_single_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:182", "shortDescription": {"text": "FastAPI POST `upsert_single_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:182"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bc96943b3c068311", "name": "FastAPI PATCH `update_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:257", "shortDescription": {"text": "FastAPI PATCH `update_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:257"}, "fullDescription": {"text": "`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ac3a03bafa0ed09d", "name": "FastAPI DELETE `delete_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:269", "shortDescription": {"text": "FastAPI DELETE `delete_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:269"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ad5ed4b792a0e284", "name": "FastAPI POST `add_entry_to_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:281", "shortDescription": {"text": "FastAPI POST `add_entry_to_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:281"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-63c836afc7d5dc0f", "name": "FastAPI DELETE `remove_entry_from_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:293", "shortDescription": {"text": "FastAPI DELETE `remove_entry_from_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:293"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-55fe1b24bfe1b927", "name": "FastAPI POST `create_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:311", "shortDescription": {"text": "FastAPI POST `create_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:311"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d4c4868cf75769a5", "name": "FastAPI PATCH `rename_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:320", "shortDescription": {"text": "FastAPI PATCH `rename_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:320"}, "fullDescription": {"text": "`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6dc360ec17da581c", "name": "FastAPI DELETE `delete_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:329", "shortDescription": {"text": "FastAPI DELETE `delete_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:329"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1863777f892b69b6", "name": "FastAPI POST `text_to_speech` without auth dependency \u2014 deeptutor/api/routers/voice.py:78", "shortDescription": {"text": "FastAPI POST `text_to_speech` without auth dependency \u2014 deeptutor/api/routers/voice.py:78"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d1a38e21efdbe153", "name": "FastAPI POST `speech_to_text` without auth dependency \u2014 deeptutor/api/routers/voice.py:104", "shortDescription": {"text": "FastAPI POST `speech_to_text` without auth dependency \u2014 deeptutor/api/routers/voice.py:104"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5f37ea5ae255c2f3", "name": "FastAPI PUT `put_capabilities_settings` without auth dependency \u2014 deeptutor/api/routers/capabilities_settings.py:34", "shortDescription": {"text": "FastAPI PUT `put_capabilities_settings` without auth dependency \u2014 deeptutor/api/routers/capabilities_settings.py:34"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-44aa2f5e93b5eb01", "name": "FastAPI PUT `put_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:151", "shortDescription": {"text": "FastAPI PUT `put_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:151"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c2d789f9b745e227", "name": "FastAPI DELETE `delete_entry` without auth dependency \u2014 deeptutor/api/routers/memory.py:159", "shortDescription": {"text": "FastAPI DELETE `delete_entry` without auth dependency \u2014 deeptutor/api/routers/memory.py:159"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-60f0387efd897161", "name": "FastAPI POST `reset_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:169", "shortDescription": {"text": "FastAPI POST `reset_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:169"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-264ddc7819bcb679", "name": "FastAPI POST `start_run` without auth dependency \u2014 deeptutor/api/routers/memory.py:308", "shortDescription": {"text": "FastAPI POST `start_run` without auth dependency \u2014 deeptutor/api/routers/memory.py:308"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-870607768e0a9c23", "name": "FastAPI POST `cancel_run` without auth dependency \u2014 deeptutor/api/routers/memory.py:363", "shortDescription": {"text": "FastAPI POST `cancel_run` without auth dependency \u2014 deeptutor/api/routers/memory.py:363"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b3ab7fc622593214", "name": "FastAPI POST `undo_run_edit` without auth dependency \u2014 deeptutor/api/routers/memory.py:373", "shortDescription": {"text": "FastAPI POST `undo_run_edit` without auth dependency \u2014 deeptutor/api/routers/memory.py:373"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-827cdd8b3c5694bd", "name": "FastAPI POST `update_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:529", "shortDescription": {"text": "FastAPI POST `update_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:529"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-aaef327deb4e71b5", "name": "FastAPI POST `audit_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:544", "shortDescription": {"text": "FastAPI POST `audit_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:544"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-03147c680f4a15ec", "name": "FastAPI POST `dedup_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:559", "shortDescription": {"text": "FastAPI POST `dedup_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:559"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-0196713758d57ebf", "name": "FastAPI PUT `put_memory_settings` without auth dependency \u2014 deeptutor/api/routers/memory.py:622", "shortDescription": {"text": "FastAPI PUT `put_memory_settings` without auth dependency \u2014 deeptutor/api/routers/memory.py:622"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-94980d0fab5d2aba", "name": "FastAPI POST `apply_doc_ops` without auth dependency \u2014 deeptutor/api/routers/memory.py:649", "shortDescription": {"text": "FastAPI POST `apply_doc_ops` without auth dependency \u2014 deeptutor/api/routers/memory.py:649"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-0137f360b92ceb8d", "name": "FastAPI DELETE `clear_trace` without auth dependency \u2014 deeptutor/api/routers/memory.py:695", "shortDescription": {"text": "FastAPI DELETE `clear_trace` without auth dependency \u2014 deeptutor/api/routers/memory.py:695"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ef3e170fe0325315", "name": "FastAPI DELETE `clear_trace_day` without auth dependency \u2014 deeptutor/api/routers/memory.py:708", "shortDescription": {"text": "FastAPI DELETE `clear_trace_day` without auth dependency \u2014 deeptutor/api/routers/memory.py:708"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-74efd573575e82e9", "name": "FastAPI POST `refresh_snapshot` without auth dependency \u2014 deeptutor/api/routers/memory.py:750", "shortDescription": {"text": "FastAPI POST `refresh_snapshot` without auth dependency \u2014 deeptutor/api/routers/memory.py:750"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d6516cff29bfbf58", "name": "FastAPI DELETE `clear_snapshot_changes` without auth dependency \u2014 deeptutor/api/routers/memory.py:779", "shortDescription": {"text": "FastAPI DELETE `clear_snapshot_changes` without auth dependency \u2014 deeptutor/api/routers/memory.py:779"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-043ee9d6378baabb", "name": "FastAPI POST `create_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:170", "shortDescription": {"text": "FastAPI POST `create_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:170"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b3dac2289e4a6869", "name": "FastAPI PUT `update_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:215", "shortDescription": {"text": "FastAPI PUT `update_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:215"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-532fc04a52298a06", "name": "FastAPI DELETE `delete_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:244", "shortDescription": {"text": "FastAPI DELETE `delete_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:244"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-285f4dd4169fcec2", "name": "FastAPI POST `add_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:266", "shortDescription": {"text": "FastAPI POST `add_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:266"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bb45a728c45a11f8", "name": "FastAPI POST `add_record_with_summary` without auth dependency \u2014 deeptutor/api/routers/notebook.py:299", "shortDescription": {"text": "FastAPI POST `add_record_with_summary` without auth dependency \u2014 deeptutor/api/routers/notebook.py:299"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-157739536497df96", "name": "FastAPI DELETE `remove_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:309", "shortDescription": {"text": "FastAPI DELETE `remove_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:309"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b4d71e110b673683", "name": "FastAPI PUT `update_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:332", "shortDescription": {"text": "FastAPI PUT `update_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:332"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-efd9639bd7ec8830", "name": "FastAPI POST `init_modules` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:134", "shortDescription": {"text": "FastAPI POST `init_modules` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:134"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-cb45fa0b82495b42", "name": "FastAPI POST `import_from_book` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:149", "shortDescription": {"text": "FastAPI POST `import_from_book` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:149"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ef677a88e3b98dcd", "name": "FastAPI DELETE `delete_progress` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:183", "shortDescription": {"text": "FastAPI DELETE `delete_progress` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:183"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d87593ef147a5ec9", "name": "FastAPI POST `redo_progress` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:193", "shortDescription": {"text": "FastAPI POST `redo_progress` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:193"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-18ad691f8d13a40e", "name": "FastAPI POST `generate_from_notebook` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:231", "shortDescription": {"text": "FastAPI POST `generate_from_notebook` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:231"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ec6d859a92db72a6", "name": "FastAPI POST `create_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:330", "shortDescription": {"text": "FastAPI POST `create_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:330"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-67839f80d54d2fc7", "name": "FastAPI PUT `update_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:350", "shortDescription": {"text": "FastAPI PUT `update_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:350"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8d40481314068ee3", "name": "FastAPI DELETE `delete_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:358", "shortDescription": {"text": "FastAPI DELETE `delete_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:358"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3b9b396feb6f04f9", "name": "FastAPI POST `create_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:445", "shortDescription": {"text": "FastAPI POST `create_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:445"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-19d0cb1c7e1fa703", "name": "FastAPI PATCH `update_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:587", "shortDescription": {"text": "FastAPI PATCH `update_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:587"}, "fullDescription": {"text": "`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bfd2fe898e7571fc", "name": "FastAPI POST `start_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:621", "shortDescription": {"text": "FastAPI POST `start_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:621"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-30a75ced869f9a88", "name": "FastAPI POST `stop_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:631", "shortDescription": {"text": "FastAPI POST `stop_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:631"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3a5579fdd2207bcb", "name": "FastAPI DELETE `destroy_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:639", "shortDescription": {"text": "FastAPI DELETE `destroy_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:639"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-afe8695ad3f00fc8", "name": "FastAPI POST `reload_partner_channels` without auth dependency \u2014 deeptutor/api/routers/partners.py:647", "shortDescription": {"text": "FastAPI POST `reload_partner_channels` without auth dependency \u2014 deeptutor/api/routers/partners.py:647"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-aff66e432eca1dcc", "name": "FastAPI PUT `put_partner_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:674", "shortDescription": {"text": "FastAPI PUT `put_partner_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:674"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-47313f7701f82375", "name": "FastAPI POST `add_partner_assets` without auth dependency \u2014 deeptutor/api/routers/partners.py:694", "shortDescription": {"text": "FastAPI POST `add_partner_assets` without auth dependency \u2014 deeptutor/api/routers/partners.py:694"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-315fb9dc0b5b01f2", "name": "FastAPI DELETE `delete_partner_asset` without auth dependency \u2014 deeptutor/api/routers/partners.py:708", "shortDescription": {"text": "FastAPI DELETE `delete_partner_asset` without auth dependency \u2014 deeptutor/api/routers/partners.py:708"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7d5920ffe21c6f2c", "name": "FastAPI POST `archive_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:749", "shortDescription": {"text": "FastAPI POST `archive_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:749"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-9d7968059e219d26", "name": "FastAPI POST `resume_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:759", "shortDescription": {"text": "FastAPI POST `resume_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:759"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f03ea859040c2718", "name": "FastAPI POST `delete_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:771", "shortDescription": {"text": "FastAPI POST `delete_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:771"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-079e8c8d817678c9", "name": "FastAPI POST `branch_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:782", "shortDescription": {"text": "FastAPI POST `branch_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:782"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-124edb3510c0ccd3", "name": "FastAPI POST `partner_chat_http` without auth dependency \u2014 deeptutor/api/routers/partners.py:890", "shortDescription": {"text": "FastAPI POST `partner_chat_http` without auth dependency \u2014 deeptutor/api/routers/partners.py:890"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2ed7dffaed2b1f5b", "name": "FastAPI POST `partner_chat_http_stream` without auth dependency \u2014 deeptutor/api/routers/partners.py:981", "shortDescription": {"text": "FastAPI POST `partner_chat_http_stream` without auth dependency \u2014 deeptutor/api/routers/partners.py:981"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f8fe2b08d500d2dc", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 deeptutor/api/routers/chat.py:47", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 deeptutor/api/routers/chat.py:47"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-bdcfa622782412cc", "name": "FastAPI PUT `update_network_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:523", "shortDescription": {"text": "FastAPI PUT `update_network_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:523"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-184e4a6d929f040b", "name": "FastAPI PUT `update_chat_attachment_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:579", "shortDescription": {"text": "FastAPI PUT `update_chat_attachment_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:579"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-44c43524f530fce6", "name": "FastAPI PUT `update_mineru_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:678", "shortDescription": {"text": "FastAPI PUT `update_mineru_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:678"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-716168a676e12b53", "name": "FastAPI PUT `update_document_parsing_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:712", "shortDescription": {"text": "FastAPI PUT `update_document_parsing_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:712"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-142d89614de3df9b", "name": "FastAPI POST `test_document_parsing` without auth dependency \u2014 deeptutor/api/routers/settings.py:733", "shortDescription": {"text": "FastAPI POST `test_document_parsing` without auth dependency \u2014 deeptutor/api/routers/settings.py:733"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5fefc7c52fde27f4", "name": "FastAPI POST `start_document_parsing_install` without auth dependency \u2014 deeptutor/api/routers/settings.py:760", "shortDescription": {"text": "FastAPI POST `start_document_parsing_install` without auth dependency \u2014 deeptutor/api/routers/settings.py:760"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-3abc376be52b7d3a", "name": "FastAPI POST `start_document_parsing_model_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:780", "shortDescription": {"text": "FastAPI POST `start_document_parsing_model_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:780"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-8c137a1893d8ee48", "name": "FastAPI POST `cancel_document_parsing_job` without auth dependency \u2014 deeptutor/api/routers/settings.py:818", "shortDescription": {"text": "FastAPI POST `cancel_document_parsing_job` without auth dependency \u2014 deeptutor/api/routers/settings.py:818"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-23b3209302bee0d4", "name": "FastAPI POST `start_mineru_models_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:826", "shortDescription": {"text": "FastAPI POST `start_mineru_models_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:826"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-749899e743af8599", "name": "FastAPI POST `cancel_mineru_models_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:870", "shortDescription": {"text": "FastAPI POST `cancel_mineru_models_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:870"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2d0497a846739ebf", "name": "FastAPI POST `test_mineru_connection` without auth dependency \u2014 deeptutor/api/routers/settings.py:878", "shortDescription": {"text": "FastAPI POST `test_mineru_connection` without auth dependency \u2014 deeptutor/api/routers/settings.py:878"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-eb54373c65d0a5af", "name": "FastAPI PUT `update_catalog` without auth dependency \u2014 deeptutor/api/routers/settings.py:955", "shortDescription": {"text": "FastAPI PUT `update_catalog` without auth dependency \u2014 deeptutor/api/routers/settings.py:955"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-a45a8f6129d55fd9", "name": "FastAPI POST `apply_catalog` without auth dependency \u2014 deeptutor/api/routers/settings.py:963", "shortDescription": {"text": "FastAPI POST `apply_catalog` without auth dependency \u2014 deeptutor/api/routers/settings.py:963"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-953fd991f16da925", "name": "FastAPI POST `fetch_models_from_provider` without auth dependency \u2014 deeptutor/api/routers/settings.py:976", "shortDescription": {"text": "FastAPI POST `fetch_models_from_provider` without auth dependency \u2014 deeptutor/api/routers/settings.py:976"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-ee5526272284b4b9", "name": "FastAPI PUT `update_theme` without auth dependency \u2014 deeptutor/api/routers/settings.py:1007", "shortDescription": {"text": "FastAPI PUT `update_theme` without auth dependency \u2014 deeptutor/api/routers/settings.py:1007"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-b3acd60da01ee1d5", "name": "FastAPI PUT `update_language` without auth dependency \u2014 deeptutor/api/routers/settings.py:1015", "shortDescription": {"text": "FastAPI PUT `update_language` without auth dependency \u2014 deeptutor/api/routers/settings.py:1015"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-211ffacc995533ba", "name": "FastAPI PUT `update_voice_autoplay` without auth dependency \u2014 deeptutor/api/routers/settings.py:1023", "shortDescription": {"text": "FastAPI PUT `update_voice_autoplay` without auth dependency \u2014 deeptutor/api/routers/settings.py:1023"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6c15d8d81381175e", "name": "FastAPI PUT `update_chat_response_timeout` without auth dependency \u2014 deeptutor/api/routers/settings.py:1036", "shortDescription": {"text": "FastAPI PUT `update_chat_response_timeout` without auth dependency \u2014 deeptutor/api/routers/settings.py:1036"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6b7cfd9ad32dc08b", "name": "FastAPI PUT `update_ui_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:1050", "shortDescription": {"text": "FastAPI PUT `update_ui_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:1050"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-626fcb55238945d0", "name": "FastAPI POST `reset_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:1065", "shortDescription": {"text": "FastAPI POST `reset_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:1065"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-9aa6fedf1e8cb157", "name": "FastAPI PUT `update_sidebar_description` without auth dependency \u2014 deeptutor/api/routers/settings.py:1094", "shortDescription": {"text": "FastAPI PUT `update_sidebar_description` without auth dependency \u2014 deeptutor/api/routers/settings.py:1094"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-6c0d19375456efe0", "name": "FastAPI PUT `update_sidebar_nav_order` without auth dependency \u2014 deeptutor/api/routers/settings.py:1102", "shortDescription": {"text": "FastAPI PUT `update_sidebar_nav_order` without auth dependency \u2014 deeptutor/api/routers/settings.py:1102"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-7275711f9a52a5f9", "name": "FastAPI PUT `update_enabled_tools` without auth dependency \u2014 deeptutor/api/routers/settings.py:1110", "shortDescription": {"text": "FastAPI PUT `update_enabled_tools` without auth dependency \u2014 deeptutor/api/routers/settings.py:1110"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-989c3b2e0fad2997", "name": "FastAPI POST `start_service_test` without auth dependency \u2014 deeptutor/api/routers/settings.py:1119", "shortDescription": {"text": "FastAPI POST `start_service_test` without auth dependency \u2014 deeptutor/api/routers/settings.py:1119"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-98f4f42b5c25824a", "name": "FastAPI POST `cancel_service_test` without auth dependency \u2014 deeptutor/api/routers/settings.py:1151", "shortDescription": {"text": "FastAPI POST `cancel_service_test` without auth dependency \u2014 deeptutor/api/routers/settings.py:1151"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-e8795302e83c5419", "name": "FastAPI POST `complete_tour` without auth dependency \u2014 deeptutor/api/routers/settings.py:1180", "shortDescription": {"text": "FastAPI POST `complete_tour` without auth dependency \u2014 deeptutor/api/routers/settings.py:1180"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f2c28c3f15247d8f", "name": "FastAPI POST `reopen_tour` without auth dependency \u2014 deeptutor/api/routers/settings.py:1212", "shortDescription": {"text": "FastAPI POST `reopen_tour` without auth dependency \u2014 deeptutor/api/routers/settings.py:1212"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-2f2758d995ff5c44", "name": "FastAPI POST `create_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:91", "shortDescription": {"text": "FastAPI POST `create_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:91"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-1ef7f6b88c8f51e3", "name": "FastAPI PUT `update_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:110", "shortDescription": {"text": "FastAPI PUT `update_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:110"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f8aec3f5c351ba1e", "name": "FastAPI DELETE `delete_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:129", "shortDescription": {"text": "FastAPI DELETE `delete_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:129"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f4291267ab551b7e", "name": "FastAPI POST `import_chat_history` without auth dependency \u2014 deeptutor/api/routers/imports.py:74", "shortDescription": {"text": "FastAPI POST `import_chat_history` without auth dependency \u2014 deeptutor/api/routers/imports.py:74"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-5ac02e3989aea9b6", "name": "FastAPI PATCH `rename_session` without auth dependency \u2014 deeptutor/api/routers/sessions.py:143", "shortDescription": {"text": "FastAPI PATCH `rename_session` without auth dependency \u2014 deeptutor/api/routers/sessions.py:143"}, "fullDescription": {"text": "`@router.patch` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-d556ed33844f6412", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 deeptutor/api/routers/sessions.py:153", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 deeptutor/api/routers/sessions.py:153"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-4e7054d258481b5f", "name": "FastAPI PUT `update_branch_selection` without auth dependency \u2014 deeptutor/api/routers/sessions.py:166", "shortDescription": {"text": "FastAPI PUT `update_branch_selection` without auth dependency \u2014 deeptutor/api/routers/sessions.py:166"}, "fullDescription": {"text": "`@router.put` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-f4c8353ffc2e2dca", "name": "FastAPI DELETE `delete_turn_by_message` without auth dependency \u2014 deeptutor/api/routers/sessions.py:180", "shortDescription": {"text": "FastAPI DELETE `delete_turn_by_message` without auth dependency \u2014 deeptutor/api/routers/sessions.py:180"}, "fullDescription": {"text": "`@router.delete` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-98e566273ee36cd2", "name": "FastAPI POST `record_quiz_results` without auth dependency \u2014 deeptutor/api/routers/sessions.py:199", "shortDescription": {"text": "FastAPI POST `record_quiz_results` without auth dependency \u2014 deeptutor/api/routers/sessions.py:199"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-109ea23cf85b145c", "name": "FastAPI POST `test_llm_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:148", "shortDescription": {"text": "FastAPI POST `test_llm_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:148"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-c8285ad78ab3ddc4", "name": "FastAPI POST `test_embeddings_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:216", "shortDescription": {"text": "FastAPI POST `test_embeddings_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:216"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-95c9329e96a75a18", "name": "FastAPI POST `test_search_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:273", "shortDescription": {"text": "FastAPI POST `test_search_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:273"}, "fullDescription": {"text": "`@router.post` has no route-local auth dependency, and `router` has no auth-shaped constructor dependency in this file. Mutating endpoints should normally authenticate. Auth enforced where the router is mounted, by a trusted gateway, or by a local-only deployment can make this finding non-reachable."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.75}}, {"id": "scanner-4d94ccba38a24fb3", "name": "Vulnerable dependency mermaid 11.14.0: GHSA-6m6c-36f7-fhxh", "shortDescription": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-6m6c-36f7-fhxh"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.14.0` (resolved in `web/package-lock.json`) is affected by GHSA-6m6c-36f7-fhxh (aka CVE-2026-41150).\n\nMermaid Gantt Charts are vulnerable to an Infinite Loop DoS\n\nAliases: CVE-2026-41150\nAdvisory: https://osv.dev/vulnerability/GHSA-6m6c-36f7-fhxh\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b6695e7bb5b1f2f9", "name": "Vulnerable dependency mermaid 11.14.0: GHSA-87f9-hvmw-gh4p", "shortDescription": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-87f9-hvmw-gh4p"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.14.0` (resolved in `web/package-lock.json`) is affected by GHSA-87f9-hvmw-gh4p (aka CVE-2026-41159).\n\nMermaid: Improper sanitization of configuration leads to CSS injection\n\nAliases: CVE-2026-41159\nAdvisory: https://osv.dev/vulnerability/GHSA-87f9-hvmw-gh4p\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c7405a856a9e34e4", "name": "Vulnerable dependency mermaid 11.14.0: GHSA-ghcm-xqfw-q4vr", "shortDescription": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-ghcm-xqfw-q4vr"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.14.0` (resolved in `web/package-lock.json`) is affected by GHSA-ghcm-xqfw-q4vr (aka CVE-2026-41149).\n\nMermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection\n\nAliases: CVE-2026-41149\nAdvisory: https://osv.dev/vulnerability/GHSA-ghcm-xqfw-q4vr\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-741ab58ddebd06a0", "name": "Vulnerable dependency mermaid 11.14.0: GHSA-xcj9-5m2h-648r", "shortDescription": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-xcj9-5m2h-648r"}, "fullDescription": {"text": "OSV.dev reports `mermaid` at version `11.14.0` (resolved in `web/package-lock.json`) is affected by GHSA-xcj9-5m2h-648r.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xcj9-5m2h-648r\nFix: upgrade `mermaid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-43221fdfcd8c3db1", "name": "Vulnerable dependency next 16.2.3: GHSA-267c-6grr-h53f", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-267c-6grr-h53f (aka CVE-2026-44575).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes\n\nAliases: CVE-2026-44575\nAdvisory: https://osv.dev/vulnerability/GHSA-267c-6grr-h53f\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-25a996e40d29b82c", "name": "Vulnerable dependency next 16.2.3: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-26hh-7cqf-hhc6 (aka CVE-2026-45109).\n\nNext.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up\n\nAliases: CVE-2026-45109\nAdvisory: https://osv.dev/vulnerability/GHSA-26hh-7cqf-hhc6\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-664bc51897707a0e", "name": "Vulnerable dependency next 16.2.3: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-36qx-fr4f-26g5 (aka CVE-2026-44573).\n\nNext.js has a Middleware / Proxy bypass in Pages Router applications using i18n\n\nAliases: CVE-2026-44573\nAdvisory: https://osv.dev/vulnerability/GHSA-36qx-fr4f-26g5\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-540cf51e05e06206", "name": "Vulnerable dependency next 16.2.3: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-3g8h-86w9-wvmq (aka CVE-2026-44572).\n\nNext.js's Middleware / Proxy redirects can be cache-poisoned\n\nAliases: CVE-2026-44572\nAdvisory: https://osv.dev/vulnerability/GHSA-3g8h-86w9-wvmq\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81546a7fa18a2b56", "name": "Vulnerable dependency next 16.2.3: GHSA-4633-3j49-mh5q", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-4633-3j49-mh5q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-4633-3j49-mh5q (aka CVE-2026-64647).\n\nNext.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences\n\nAliases: CVE-2026-64647\nAdvisory: https://osv.dev/vulnerability/GHSA-4633-3j49-mh5q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2057301faa826bfc", "name": "Vulnerable dependency next 16.2.3: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-492v-c6pp-mqqv (aka CVE-2026-44574).\n\nNext.js has a Middleware / Proxy bypass through dynamic route parameter injection\n\nAliases: CVE-2026-44574\nAdvisory: https://osv.dev/vulnerability/GHSA-492v-c6pp-mqqv\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-003757ac01fe6a09", "name": "Vulnerable dependency next 16.2.3: GHSA-4c39-4ccg-62r3", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-4c39-4ccg-62r3"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-4c39-4ccg-62r3 (aka CVE-2026-64646).\n\nNext.js: Unbounded Server Action payload in Edge runtime\n\nAliases: CVE-2026-64646\nAdvisory: https://osv.dev/vulnerability/GHSA-4c39-4ccg-62r3\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c51a0519d0283e37", "name": "Vulnerable dependency next 16.2.3: GHSA-68g3-v927-f742", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-68g3-v927-f742"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-68g3-v927-f742 (aka CVE-2026-64648).\n\nNext.js: Cache confusion of response bodies for requests with bodies\n\nAliases: CVE-2026-64648\nAdvisory: https://osv.dev/vulnerability/GHSA-68g3-v927-f742\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9f6a8200185089d", "name": "Vulnerable dependency next 16.2.3: GHSA-6gpp-xcg3-4w24", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-6gpp-xcg3-4w24"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-6gpp-xcg3-4w24 (aka CVE-2026-64642).\n\nNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale\n\nAliases: CVE-2026-64642\nAdvisory: https://osv.dev/vulnerability/GHSA-6gpp-xcg3-4w24\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-678bf574096d3dd3", "name": "Vulnerable dependency next 16.2.3: GHSA-89xv-2m56-2m9x", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-89xv-2m56-2m9x"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-89xv-2m56-2m9x (aka CVE-2026-64649).\n\nNext.js: Server-Side Request Forgery in Server Actions on custom servers\n\nAliases: CVE-2026-64649\nAdvisory: https://osv.dev/vulnerability/GHSA-89xv-2m56-2m9x\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1066f2256483362b", "name": "Vulnerable dependency next 16.2.3: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-8h8q-6873-q5fj.\n\nNext.js Vulnerable to Denial of Service with Server Components\n\nAdvisory: https://osv.dev/vulnerability/GHSA-8h8q-6873-q5fj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c134ed07b4d981a0", "name": "Vulnerable dependency next 16.2.3: GHSA-955p-x3mx-jcvp", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-955p-x3mx-jcvp"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-955p-x3mx-jcvp (aka CVE-2026-64643).\n\nNext.js: Unauthenticated disclosure of internal Server Function endpoints\n\nAliases: CVE-2026-64643\nAdvisory: https://osv.dev/vulnerability/GHSA-955p-x3mx-jcvp\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c20a36b4601b4799", "name": "Vulnerable dependency next 16.2.3: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-c4j6-fc7j-m34r (aka CVE-2026-44578).\n\nNext.js vulnerable to server-side request forgery in applications using WebSocket upgrades\n\nAliases: CVE-2026-44578\nAdvisory: https://osv.dev/vulnerability/GHSA-c4j6-fc7j-m34r\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bea136ed86c29b59", "name": "Vulnerable dependency next 16.2.3: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-ffhc-5mcf-pf4q (aka CVE-2026-44581).\n\nNext.js vulnerable to cross-site scripting in App Router applications using CSP nonces\n\nAliases: CVE-2026-44581\nAdvisory: https://osv.dev/vulnerability/GHSA-ffhc-5mcf-pf4q\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efcf7b275cc569b9", "name": "Vulnerable dependency next 16.2.3: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-gx5p-jg67-6x7h (aka CVE-2026-44580).\n\nNext.js has cross-site scripting in beforeInteractive scripts with untrusted input\n\nAliases: CVE-2026-44580\nAdvisory: https://osv.dev/vulnerability/GHSA-gx5p-jg67-6x7h\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af56e5f4d0beb3a6", "name": "Vulnerable dependency next 16.2.3: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-h64f-5h5j-jqjh (aka CVE-2026-44577).\n\nNext.js has a Denial of Service in the Image Optimization API\n\nAliases: CVE-2026-44577\nAdvisory: https://osv.dev/vulnerability/GHSA-h64f-5h5j-jqjh\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0076add513a89bad", "name": "Vulnerable dependency next 16.2.3: GHSA-m99w-x7hq-7vfj", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-m99w-x7hq-7vfj"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-m99w-x7hq-7vfj (aka CVE-2026-64641).\n\nNext.js: Denial of Service in App Router using Server Actions\n\nAliases: CVE-2026-64641\nAdvisory: https://osv.dev/vulnerability/GHSA-m99w-x7hq-7vfj\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c7ecbac08a8bed19", "name": "Vulnerable dependency next 16.2.3: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-mg66-mrh9-m8jx (aka CVE-2026-44579).\n\nNext.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components\n\nAliases: CVE-2026-44579\nAdvisory: https://osv.dev/vulnerability/GHSA-mg66-mrh9-m8jx\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-05ca0e7959284077", "name": "Vulnerable dependency next 16.2.3: GHSA-p9j2-gv94-2wf4", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-p9j2-gv94-2wf4"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-p9j2-gv94-2wf4 (aka CVE-2026-64645).\n\nNext.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname\n\nAliases: CVE-2026-64645\nAdvisory: https://osv.dev/vulnerability/GHSA-p9j2-gv94-2wf4\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-331fd92b435a94da", "name": "Vulnerable dependency next 16.2.3: GHSA-q8wf-6r8g-63ch", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-q8wf-6r8g-63ch"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-q8wf-6r8g-63ch (aka CVE-2026-64644).\n\nNext.js: Denial of Service in the Image Optimization API using SVGs\n\nAliases: CVE-2026-64644\nAdvisory: https://osv.dev/vulnerability/GHSA-q8wf-6r8g-63ch\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7cd8c649a51c1e18", "name": "Vulnerable dependency next 16.2.3: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-vfv6-92ff-j949.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vfv6-92ff-j949\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5794ed7ed8424a51", "name": "Vulnerable dependency next 16.2.3: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "Vulnerable dependency next 16.2.3: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "OSV.dev reports `next` at version `16.2.3` (resolved in `web/package-lock.json`) is affected by GHSA-wfc6-r584-vfw7.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-wfc6-r584-vfw7\nFix: upgrade `next` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-401d7ee6ff3add6c", "name": "Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.4.31` (resolved in `web/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-840edaacc0bd06d7", "name": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.4.31` (resolved in `web/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-680067153df8469f", "name": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `web/package-lock.json`) is affected by GHSA-6g55-p6wh-862q (aka CVE-2026-45623).\n\nPostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments\n\nAliases: CVE-2026-45623\nAdvisory: https://osv.dev/vulnerability/GHSA-6g55-p6wh-862q\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6b1e1c9739855def", "name": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.6` (resolved in `web/package-lock.json`) is affected by GHSA-qx2v-qp2m-jg93 (aka CVE-2026-41305).\n\nPostCSS has XSS via Unescaped </style> in its CSS Stringify Output\n\nAliases: CVE-2026-41305\nAdvisory: https://osv.dev/vulnerability/GHSA-qx2v-qp2m-jg93\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b1656f062b59c2b5", "name": "Vulnerable dependency @babel/core 7.28.5: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "Vulnerable dependency @babel/core 7.28.5: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "OSV.dev reports `@babel/core` at version `7.28.5` (resolved in `web/package-lock.json`) is affected by GHSA-4x5r-pxfx-6jf8 (aka CVE-2026-49356).\nNote: `@babel/core` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\n@babel/core: Arbitrary File Read via sourceMappingURL Comment\n\nAliases: CVE-2026-49356\nAdvisory: https://osv.dev/vulnerability/GHSA-4x5r-pxfx-6jf8\nFix: upgrade `@babel/core` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-f6d645899ba265c1", "name": "Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.1.0` (resolved in `web/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-da436a552d441f90", "name": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.14` (resolved in `web/package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4a451de39b670107", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-76mc-f452-cxcm", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-76mc-f452-cxcm"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-76mc-f452-cxcm (aka CVE-2026-65902).\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\nAliases: CVE-2026-65902\nAdvisory: https://osv.dev/vulnerability/GHSA-76mc-f452-cxcm\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7be4da00dffe13ed", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-c2j3-45gr-mqc4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-c2j3-45gr-mqc4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-c2j3-45gr-mqc4.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c2j3-45gr-mqc4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-95e09fe7afecf753", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-cmwh-pvxp-8882", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-cmwh-pvxp-8882"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-cmwh-pvxp-8882 (aka CVE-2026-65898).\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\nAliases: CVE-2026-65898\nAdvisory: https://osv.dev/vulnerability/GHSA-cmwh-pvxp-8882\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9c5ee34cb020e7fa", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-gvmj-g25r-r7wr", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-gvmj-g25r-r7wr"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-gvmj-g25r-r7wr (aka CVE-2026-65900).\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\nAliases: CVE-2026-65900\nAdvisory: https://osv.dev/vulnerability/GHSA-gvmj-g25r-r7wr\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-459c78f8755406e9", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-hpcv-96wg-7vj8", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-hpcv-96wg-7vj8"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-hpcv-96wg-7vj8 (aka CVE-2026-49458).\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks\n\nAliases: CVE-2026-49458\nAdvisory: https://osv.dev/vulnerability/GHSA-hpcv-96wg-7vj8\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-f07f6e1cb9851f49", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-r47g-fvhr-h676", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-r47g-fvhr-h676"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-r47g-fvhr-h676 (aka CVE-2026-49459).\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nDOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM\n\nAliases: CVE-2026-49459\nAdvisory: https://osv.dev/vulnerability/GHSA-r47g-fvhr-h676\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-db82421595ecceaa", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-rp9w-3fw7-7cwq", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-rp9w-3fw7-7cwq"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-rp9w-3fw7-7cwq.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rp9w-3fw7-7cwq\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5bdb0bee39833393", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-vxr8-fq34-vvx9", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-vxr8-fq34-vvx9"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-vxr8-fq34-vvx9.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vxr8-fq34-vvx9\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e245014afe71ccb1", "name": "Vulnerable dependency dompurify 3.4.0: GHSA-x4vx-rjvf-j5p4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-x4vx-rjvf-j5p4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.0` (resolved in `web/package-lock.json`) is affected by GHSA-x4vx-rjvf-j5p4.\nNote: `dompurify` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x4vx-rjvf-j5p4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4dcc6a16f3851a9a", "name": "Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq", "shortDescription": {"text": "Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq"}, "fullDescription": {"text": "OSV.dev reports `uuid` at version `8.3.2` (resolved in `web/package-lock.json`) is affected by GHSA-w5hq-g745-h8pq (aka CVE-2026-41907, CVE-2026-41988).\nNote: `uuid` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nuuid: Missing buffer bounds check in v3/v5/v6 when buf is provided\n\nAliases: CVE-2026-41907, CVE-2026-41988\nAdvisory: https://osv.dev/vulnerability/GHSA-w5hq-g745-h8pq\nFix: upgrade `uuid` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1b62672b5c8588c6", "name": "Dependency i18next is a major version behind", "shortDescription": {"text": "Dependency i18next is a major version behind"}, "fullDescription": {"text": "`i18next` is pinned at `25.8.0` in `web/package.json` while the latest release on the npm registry is `26.3.6` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `i18next` to `26.3.6`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-df0951a6a3ddcafc", "name": "Dependency lucide-react is a major version behind", "shortDescription": {"text": "Dependency lucide-react is a major version behind"}, "fullDescription": {"text": "`lucide-react` is pinned at `0.562.0` in `web/package.json` while the latest release on the npm registry is `1.26.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `lucide-react` to `1.26.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-ae833d4a886bff6d", "name": "Dependency react-i18next is a major version behind", "shortDescription": {"text": "Dependency react-i18next is a major version behind"}, "fullDescription": {"text": "`react-i18next` is pinned at `16.5.3` in `web/package.json` while the latest release on the npm registry is `17.0.11` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `react-i18next` to `17.0.11`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30753"}, "properties": {"repository": "HKUDS/DeepTutor", "repoUrl": "https://github.com/HKUDS/DeepTutor", "branch": "main"}, "results": [{"ruleId": "scanner-8d56c5e8e7340814", "level": "note", "message": {"text": "Possibly dead Python function: do_GET"}, "properties": {"repobilityId": "2d943bb45e4f13bd", "scanner": "scanner-primary", "fingerprint": "8d56c5e8e7340814", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor_cli/skill_login.py:81"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7239b258eb136607", "level": "note", "message": {"text": "Possibly dead Python function: print_path_result"}, "properties": {"repobilityId": "04b580dfe230c128", "scanner": "scanner-primary", "fingerprint": "7239b258eb136607", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor_cli/common.py:897"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4fda48d50cd3ed6c", "level": "note", "message": {"text": "Possibly dead Python function: save_code_block"}, "properties": {"repobilityId": "7e557cd1d06f6460", "scanner": "scanner-primary", "fingerprint": "4fda48d50cd3ed6c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/telegram.py:116"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a33910cbf737ce49", "level": "note", "message": {"text": "Possibly dead Python function: save_inline_code"}, "properties": {"repobilityId": "d4707890b2333508", "scanner": "scanner-primary", "fingerprint": "a33910cbf737ce49", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/telegram.py:146"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-927c9c0444608eff", "level": "note", "message": {"text": "Possibly dead Python function: start_all"}, "properties": {"repobilityId": "c7e8894878f5695e", "scanner": "scanner-primary", "fingerprint": "927c9c0444608eff", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/manager.py:122"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c744bdbc1f2a9cf6", "level": "note", "message": {"text": "Possibly dead Python function: run_ws"}, "properties": {"repobilityId": "a67c83834a3cc85d", "scanner": "scanner-primary", "fingerprint": "c744bdbc1f2a9cf6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/feishu.py:363"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-996f6d6800010195", "level": "note", "message": {"text": "Possibly dead Python function: do_POST"}, "properties": {"repobilityId": "53357410ca9379a9", "scanner": "scanner-primary", "fingerprint": "996f6d6800010195", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/msteams.py:170"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-794e51cec8ad83e2", "level": "note", "message": {"text": "Possibly dead Python function: fetch_messages_between_dates"}, "properties": {"repobilityId": "20912d80a84db27a", "scanner": "scanner-primary", "fingerprint": "794e51cec8ad83e2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/email.py:239"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bfee88051c543a35", "level": "note", "message": {"text": "Possibly dead Python function: on_c2c_message_create"}, "properties": {"repobilityId": "2fcd6ffed816658c", "scanner": "scanner-primary", "fingerprint": "bfee88051c543a35", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/qq.py:42"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-70e69d3b87abc90b", "level": "note", "message": {"text": "Possibly dead Python function: migrate_config"}, "properties": {"repobilityId": "9229f7c643fb66c6", "scanner": "scanner-primary", "fingerprint": "70e69d3b87abc90b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/config/schema.py:34"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-97b9eb9752891f73", "level": "note", "message": {"text": "Possibly dead Python function: cleanup_old_tasks"}, "properties": {"repobilityId": "6c6fd3cc71c6449b", "scanner": "scanner-primary", "fingerprint": "97b9eb9752891f73", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/utils/task_id_manager.py:82"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-576feecb668d0d07", "level": "note", "message": {"text": "Possibly dead Python function: require_auth"}, "properties": {"repobilityId": "d7855475dea79341", "scanner": "scanner-primary", "fingerprint": "576feecb668d0d07", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/auth.py:234"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b0e5702164c7711a", "level": "note", "message": {"text": "Possibly dead Python function: require_admin"}, "properties": {"repobilityId": "3c06db2e25566bf7", "scanner": "scanner-primary", "fingerprint": "b0e5702164c7711a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/auth.py:324"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-af5c47d67c59fb2b", "level": "note", "message": {"text": "Possibly dead Python function: go"}, "properties": {"repobilityId": "4b0bb0f4d33f4075", "scanner": "scanner-primary", "fingerprint": "af5c47d67c59fb2b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py:296"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c15c215bf42de679", "level": "note", "message": {"text": "Possibly dead Python function: ensure_root"}, "properties": {"repobilityId": "169afa477577b77c", "scanner": "scanner-primary", "fingerprint": "c15c215bf42de679", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/co_writer/storage.py:119"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb0e6799d8edd865", "level": "note", "message": {"text": "Possibly dead Python function: advance_stage"}, "properties": {"repobilityId": "13a5ae0480405c86", "scanner": "scanner-primary", "fingerprint": "cb0e6799d8edd865", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/learning/service.py:77"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a329a4db61e4ee2", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/ThemeScript.tsx:45"}, "properties": {"repobilityId": "886f2ceb33104c17", "scanner": "scanner-primary", "fingerprint": "5a329a4db61e4ee2", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/ThemeScript.tsx"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-2141675e2fb7db20", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/Mermaid.tsx:174"}, "properties": {"repobilityId": "a43bf047dc94ca33", "scanner": "scanner-primary", "fingerprint": "2141675e2fb7db20", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/Mermaid.tsx"}, "region": {"startLine": 174}}}]}, {"ruleId": "scanner-a5c626ad775912a3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/settings/ServiceConfigEditor.tsx:295"}, "properties": {"repobilityId": "3845efa09b9cc468", "scanner": "scanner-primary", "fingerprint": "a5c626ad775912a3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/settings/ServiceConfigEditor.tsx"}, "region": {"startLine": 295}}}]}, {"ruleId": "scanner-d9a5a5fd9557542a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/settings/SettingsSectionGrid.tsx:142"}, "properties": {"repobilityId": "23b787cb8dda3a48", "scanner": "scanner-primary", "fingerprint": "d9a5a5fd9557542a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/settings/SettingsSectionGrid.tsx"}, "region": {"startLine": 142}}}]}, {"ruleId": "scanner-d69580d30b810282", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/notebook/NotebookSelector.tsx:119"}, "properties": {"repobilityId": "414c4e807d0e1120", "scanner": "scanner-primary", "fingerprint": "d69580d30b810282", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/notebook/NotebookSelector.tsx"}, "region": {"startLine": 119}}}]}, {"ruleId": "scanner-99bd705ad40d269a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerModelPicker.tsx:48"}, "properties": {"repobilityId": "3b5204a46e8323d8", "scanner": "scanner-primary", "fingerprint": "99bd705ad40d269a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerModelPicker.tsx"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-47f59fd0d28b7198", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerChat.tsx:172"}, "properties": {"repobilityId": "f3e941e4524cf366", "scanner": "scanner-primary", "fingerprint": "47f59fd0d28b7198", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerChat.tsx"}, "region": {"startLine": 172}}}]}, {"ruleId": "scanner-110c4059dece2b53", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerChannels.tsx:228"}, "properties": {"repobilityId": "568b830d0c579ffd", "scanner": "scanner-primary", "fingerprint": "110c4059dece2b53", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerChannels.tsx"}, "region": {"startLine": 228}}}]}, {"ruleId": "scanner-748322bdbc32589a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerComposer.tsx:388"}, "properties": {"repobilityId": "0234e425ced74320", "scanner": "scanner-primary", "fingerprint": "748322bdbc32589a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerComposer.tsx"}, "region": {"startLine": 388}}}]}, {"ruleId": "scanner-9c8498360502c064", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerModelSelect.tsx:117"}, "properties": {"repobilityId": "f43494b70224bf1b", "scanner": "scanner-primary", "fingerprint": "9c8498360502c064", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerModelSelect.tsx"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-312ad3325c96864e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerArchives.tsx:205"}, "properties": {"repobilityId": "d58310603469817d", "scanner": "scanner-primary", "fingerprint": "312ad3325c96864e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerArchives.tsx"}, "region": {"startLine": 205}}}]}, {"ruleId": "scanner-a4708c39bab85d26", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/PartnerConfigure.tsx:518"}, "properties": {"repobilityId": "17e4bd12a47df9c3", "scanner": "scanner-primary", "fingerprint": "a4708c39bab85d26", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/PartnerConfigure.tsx"}, "region": {"startLine": 518}}}]}, {"ruleId": "scanner-d64dfe47ffc3983a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/partners/ToolPicker.tsx:39"}, "properties": {"repobilityId": "527255daf25b8ed0", "scanner": "scanner-primary", "fingerprint": "d64dfe47ffc3983a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/partners/ToolPicker.tsx"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-0daa67db6d6a461f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/auth/ProfileLink.tsx:69"}, "properties": {"repobilityId": "7e29225c5c2f0a60", "scanner": "scanner-primary", "fingerprint": "0daa67db6d6a461f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/auth/ProfileLink.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-bc8da81d87ad1bf0", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/PersonasSection.tsx:321"}, "properties": {"repobilityId": "45b5289eb183c1c8", "scanner": "scanner-primary", "fingerprint": "bc8da81d87ad1bf0", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/PersonasSection.tsx"}, "region": {"startLine": 321}}}]}, {"ruleId": "scanner-01ceb98e80378ac9", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/ScopeEditorModal.tsx:157"}, "properties": {"repobilityId": "5c15967b1d1ed692", "scanner": "scanner-primary", "fingerprint": "01ceb98e80378ac9", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/ScopeEditorModal.tsx"}, "region": {"startLine": 157}}}]}, {"ruleId": "scanner-f46547ebf2b99ee5", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/SkillsSection.tsx:639"}, "properties": {"repobilityId": "68e5f8c37c762072", "scanner": "scanner-primary", "fingerprint": "f46547ebf2b99ee5", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/SkillsSection.tsx"}, "region": {"startLine": 639}}}]}, {"ruleId": "scanner-4a40aafe9e326ed5", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/MyAgentsSection.tsx:462"}, "properties": {"repobilityId": "cf9bdc17085d6ba9", "scanner": "scanner-primary", "fingerprint": "4a40aafe9e326ed5", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/MyAgentsSection.tsx"}, "region": {"startLine": 462}}}]}, {"ruleId": "scanner-1abd0673b9ced96d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/ScopePicker.tsx:151"}, "properties": {"repobilityId": "8427c45dd951978a", "scanner": "scanner-primary", "fingerprint": "1abd0673b9ced96d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/ScopePicker.tsx"}, "region": {"startLine": 151}}}]}, {"ruleId": "scanner-195890279bb09f25", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/NotebooksSection.tsx:322"}, "properties": {"repobilityId": "4e6fd3da7526cea6", "scanner": "scanner-primary", "fingerprint": "195890279bb09f25", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/NotebooksSection.tsx"}, "region": {"startLine": 322}}}]}, {"ruleId": "scanner-379882c5eff1479f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/SpaceDashboard.tsx:247"}, "properties": {"repobilityId": "e7813641e84fcd1c", "scanner": "scanner-primary", "fingerprint": "379882c5eff1479f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/SpaceDashboard.tsx"}, "region": {"startLine": 247}}}]}, {"ruleId": "scanner-546a1694a49ef64d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/space/EduHubImportModal.tsx:186"}, "properties": {"repobilityId": "8755c6a306856654", "scanner": "scanner-primary", "fingerprint": "546a1694a49ef64d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/space/EduHubImportModal.tsx"}, "region": {"startLine": 186}}}]}, {"ruleId": "scanner-c580854df355cf21", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/common/InlineFileCard.tsx:360"}, "properties": {"repobilityId": "3a041e0c473d572f", "scanner": "scanner-primary", "fingerprint": "c580854df355cf21", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/common/InlineFileCard.tsx"}, "region": {"startLine": 360}}}]}, {"ruleId": "scanner-dd69efdf451ad687", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/QuestionBankPicker.tsx:283"}, "properties": {"repobilityId": "5a376f22c4841449", "scanner": "scanner-primary", "fingerprint": "dd69efdf451ad687", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/QuestionBankPicker.tsx"}, "region": {"startLine": 283}}}]}, {"ruleId": "scanner-1bce499baca14c3e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/HistorySessionPicker.tsx:248"}, "properties": {"repobilityId": "0fecd42d528107e1", "scanner": "scanner-primary", "fingerprint": "1bce499baca14c3e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/HistorySessionPicker.tsx"}, "region": {"startLine": 248}}}]}, {"ruleId": "scanner-c36174edab1bf0ea", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/BookReferencePicker.tsx:272"}, "properties": {"repobilityId": "1000926f80680bfd", "scanner": "scanner-primary", "fingerprint": "c36174edab1bf0ea", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/BookReferencePicker.tsx"}, "region": {"startLine": 272}}}]}, {"ruleId": "scanner-c742d467e8541c23", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/PersonaPicker.tsx:161"}, "properties": {"repobilityId": "a54f1ccacc0cb53f", "scanner": "scanner-primary", "fingerprint": "c742d467e8541c23", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/PersonaPicker.tsx"}, "region": {"startLine": 161}}}]}, {"ruleId": "scanner-037d00120227da69", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/MyAgentsPicker.tsx:533"}, "properties": {"repobilityId": "14587c170eace553", "scanner": "scanner-primary", "fingerprint": "037d00120227da69", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/MyAgentsPicker.tsx"}, "region": {"startLine": 533}}}]}, {"ruleId": "scanner-b55f2bce39eb0ee8", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/space/ChatSpaceMenu.tsx:266"}, "properties": {"repobilityId": "75c029103a0fe8ab", "scanner": "scanner-primary", "fingerprint": "b55f2bce39eb0ee8", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/space/ChatSpaceMenu.tsx"}, "region": {"startLine": 266}}}]}, {"ruleId": "scanner-aa59a46a9036b259", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/preview/FilePreviewDrawer.tsx:184"}, "properties": {"repobilityId": "dc755cdb4b0471dc", "scanner": "scanner-primary", "fingerprint": "aa59a46a9036b259", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/preview/FilePreviewDrawer.tsx"}, "region": {"startLine": 184}}}]}, {"ruleId": "scanner-586b3fd04c01c770", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/preview/previewers/XlsxPreview.tsx:162"}, "properties": {"repobilityId": "6aacc75d12e5fa34", "scanner": "scanner-primary", "fingerprint": "586b3fd04c01c770", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/preview/previewers/XlsxPreview.tsx"}, "region": {"startLine": 162}}}]}, {"ruleId": "scanner-fb8f42add3d81c08", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/AgentSelector.tsx:95"}, "properties": {"repobilityId": "50816ebce3e8c4a5", "scanner": "scanner-primary", "fingerprint": "fb8f42add3d81c08", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/AgentSelector.tsx"}, "region": {"startLine": 95}}}]}, {"ruleId": "scanner-927dcc6ddd9cfad9", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ChatComposer.tsx:121"}, "properties": {"repobilityId": "83c0982ad1b1d8cb", "scanner": "scanner-primary", "fingerprint": "927dcc6ddd9cfad9", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/ChatComposer.tsx"}, "region": {"startLine": 121}}}]}, {"ruleId": "scanner-f485c91624e6a931", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/SessionActivityPanel.tsx:422"}, "properties": {"repobilityId": "8175afd21fd449e7", "scanner": "scanner-primary", "fingerprint": "f485c91624e6a931", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/SessionActivityPanel.tsx"}, "region": {"startLine": 422}}}]}, {"ruleId": "scanner-2d535ea4d3d30a48", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/SessionViewerPanel.tsx:668"}, "properties": {"repobilityId": "4332a2ac210af362", "scanner": "scanner-primary", "fingerprint": "2d535ea4d3d30a48", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/SessionViewerPanel.tsx"}, "region": {"startLine": 668}}}]}, {"ruleId": "scanner-c8b3e5b624733f75", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/CapabilityConfigCard.tsx:100"}, "properties": {"repobilityId": "62a3c289e4def14f", "scanner": "scanner-primary", "fingerprint": "c8b3e5b624733f75", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/CapabilityConfigCard.tsx"}, "region": {"startLine": 100}}}]}, {"ruleId": "scanner-2307a540c39c196b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ContextReferenceTree.tsx:152"}, "properties": {"repobilityId": "6ed0eb7d26c89ca8", "scanner": "scanner-primary", "fingerprint": "2307a540c39c196b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/ContextReferenceTree.tsx"}, "region": {"startLine": 152}}}]}, {"ruleId": "scanner-387c022df34bb3a1", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/PersonaSelector.tsx:146"}, "properties": {"repobilityId": "022eef6b6e6949cf", "scanner": "scanner-primary", "fingerprint": "387c022df34bb3a1", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/PersonaSelector.tsx"}, "region": {"startLine": 146}}}]}, {"ruleId": "scanner-23ca23682aee5724", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/AskUserOptions.tsx:620"}, "properties": {"repobilityId": "5e63043f14cbb58d", "scanner": "scanner-primary", "fingerprint": "23ca23682aee5724", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/AskUserOptions.tsx"}, "region": {"startLine": 620}}}]}, {"ruleId": "scanner-8c5d931fbbc1a1ee", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ModelSelector.tsx:69"}, "properties": {"repobilityId": "1c88edc1fed7e286", "scanner": "scanner-primary", "fingerprint": "8c5d931fbbc1a1ee", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/ModelSelector.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-fd18c465ecea3701", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ComposerInput.tsx:431"}, "properties": {"repobilityId": "602000c2da5dbcb5", "scanner": "scanner-primary", "fingerprint": "fd18c465ecea3701", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/ComposerInput.tsx"}, "region": {"startLine": 431}}}]}, {"ruleId": "scanner-601905c6a74792ec", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/ChatMessages.tsx:206"}, "properties": {"repobilityId": "54cfe5e23dd7df5b", "scanner": "scanner-primary", "fingerprint": "601905c6a74792ec", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/ChatMessages.tsx"}, "region": {"startLine": 206}}}]}, {"ruleId": "scanner-54c11cfbc7b549a4", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/composer-field.tsx:64"}, "properties": {"repobilityId": "5fc07bc01b140aac", "scanner": "scanner-primary", "fingerprint": "54c11cfbc7b549a4", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/composer-field.tsx"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-c3672eb4ce6b41d2", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/chat/home/KnowledgeSelector.tsx:97"}, "properties": {"repobilityId": "4f894e77d9fa34fb", "scanner": "scanner-primary", "fingerprint": "c3672eb4ce6b41d2", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/chat/home/KnowledgeSelector.tsx"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-9fd592fa8137327a", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizFollowupTabBody.tsx:140"}, "properties": {"repobilityId": "4d0b0e9cae7f8500", "scanner": "scanner-primary", "fingerprint": "9fd592fa8137327a", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/quiz/QuizFollowupTabBody.tsx"}, "region": {"startLine": 140}}}]}, {"ruleId": "scanner-bb8a9d22bfc5d5bc", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizConfigPanel.tsx:271"}, "properties": {"repobilityId": "707e2084f2f5b45c", "scanner": "scanner-primary", "fingerprint": "bb8a9d22bfc5d5bc", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/quiz/QuizConfigPanel.tsx"}, "region": {"startLine": 271}}}]}, {"ruleId": "scanner-3ee881316c94a226", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/quiz/QuizViewer.tsx:1179"}, "properties": {"repobilityId": "c02e7b4b00d81281", "scanner": "scanner-primary", "fingerprint": "3ee881316c94a226", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/quiz/QuizViewer.tsx"}, "region": {"startLine": 1179}}}]}, {"ruleId": "scanner-9bcba163e6d83f28", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/agents/ConnectedAgents.tsx:187"}, "properties": {"repobilityId": "2138d0c29ae7a22b", "scanner": "scanner-primary", "fingerprint": "9bcba163e6d83f28", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/agents/ConnectedAgents.tsx"}, "region": {"startLine": 187}}}]}, {"ruleId": "scanner-6f91108edf75cd31", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryL1Workbench.tsx:172"}, "properties": {"repobilityId": "37d89f4723b09190", "scanner": "scanner-primary", "fingerprint": "6f91108edf75cd31", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/memory/MemoryL1Workbench.tsx"}, "region": {"startLine": 172}}}]}, {"ruleId": "scanner-56cc919e8fe56123", "level": "note", "message": {"text": "React Flow <Controls> without dark theming \u2014 web/components/memory/MemoryGraph.tsx:275"}, "properties": {"repobilityId": "653ba874da16dc60", "scanner": "scanner-primary", "fingerprint": "56cc919e8fe56123", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.controls.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/memory/MemoryGraph.tsx"}, "region": {"startLine": 275}}}]}, {"ruleId": "scanner-a4dbb8542e754d25", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemorySection.tsx:1060"}, "properties": {"repobilityId": "30703796bac7769b", "scanner": "scanner-primary", "fingerprint": "a4dbb8542e754d25", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/memory/MemorySection.tsx"}, "region": {"startLine": 1060}}}]}, {"ruleId": "scanner-878888c5547425e5", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryRunPanel.tsx:326"}, "properties": {"repobilityId": "e59cca53e19ff046", "scanner": "scanner-primary", "fingerprint": "878888c5547425e5", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/memory/MemoryRunPanel.tsx"}, "region": {"startLine": 326}}}]}, {"ruleId": "scanner-68a059e82a1f3bc0", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/memory/MemoryWorkbench.tsx:368"}, "properties": {"repobilityId": "799cc76a45a63e64", "scanner": "scanner-primary", "fingerprint": "68a059e82a1f3bc0", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/memory/MemoryWorkbench.tsx"}, "region": {"startLine": 368}}}]}, {"ruleId": "scanner-54574705abe33629", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 web/components/visualize/VisualizationViewer.tsx:333"}, "properties": {"repobilityId": "2bd96c5edd7bf9df", "scanner": "scanner-primary", "fingerprint": "54574705abe33629", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/visualize/VisualizationViewer.tsx"}, "region": {"startLine": 333}}}]}, {"ruleId": "scanner-b8e7630d592f4141", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/BookRecent.tsx:79"}, "properties": {"repobilityId": "b411e619823528ad", "scanner": "scanner-primary", "fingerprint": "b8e7630d592f4141", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/sidebar/BookRecent.tsx"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-5e9c0d8556e6b882", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/CoWriterRecent.tsx:67"}, "properties": {"repobilityId": "bf200548f90c8f08", "scanner": "scanner-primary", "fingerprint": "5e9c0d8556e6b882", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/sidebar/CoWriterRecent.tsx"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-c75b88b7855adc10", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/sidebar/VersionBadge.tsx:27"}, "properties": {"repobilityId": "ab1fb285b32d3b3f", "scanner": "scanner-primary", "fingerprint": "c75b88b7855adc10", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/sidebar/VersionBadge.tsx"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-ddf37b48e633d76f", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgePage.tsx:225"}, "properties": {"repobilityId": "5c11e74ae9308de3", "scanner": "scanner-primary", "fingerprint": "ddf37b48e633d76f", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/KnowledgePage.tsx"}, "region": {"startLine": 225}}}]}, {"ruleId": "scanner-5575aac8153394c3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgeHome.tsx:175"}, "properties": {"repobilityId": "823270e02f146f76", "scanner": "scanner-primary", "fingerprint": "5575aac8153394c3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/KnowledgeHome.tsx"}, "region": {"startLine": 175}}}]}, {"ruleId": "scanner-e3d021438aaab0f0", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/EngineDetail.tsx:204"}, "properties": {"repobilityId": "57564a16f91aefc4", "scanner": "scanner-primary", "fingerprint": "e3d021438aaab0f0", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/EngineDetail.tsx"}, "region": {"startLine": 204}}}]}, {"ruleId": "scanner-4b28745c97ed37c7", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KnowledgeBaseDetail.tsx:152"}, "properties": {"repobilityId": "d59ba7da4de29da5", "scanner": "scanner-primary", "fingerprint": "4b28745c97ed37c7", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/KnowledgeBaseDetail.tsx"}, "region": {"startLine": 152}}}]}, {"ruleId": "scanner-f4723475a13fc060", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KbDocumentList.tsx:304"}, "properties": {"repobilityId": "223831320e8426f6", "scanner": "scanner-primary", "fingerprint": "f4723475a13fc060", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/KbDocumentList.tsx"}, "region": {"startLine": 304}}}]}, {"ruleId": "scanner-93b8fa173b21299e", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/KbFilePreview.tsx:230"}, "properties": {"repobilityId": "3d4692684f948f45", "scanner": "scanner-primary", "fingerprint": "93b8fa173b21299e", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/KbFilePreview.tsx"}, "region": {"startLine": 230}}}]}, {"ruleId": "scanner-62975a1999dcaafd", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/components/knowledge/FileDropZone.tsx:342"}, "properties": {"repobilityId": "65ecbfbd207ee38e", "scanner": "scanner-primary", "fingerprint": "62975a1999dcaafd", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/knowledge/FileDropZone.tsx"}, "region": {"startLine": 342}}}]}, {"ruleId": "scanner-65c934674c8060a3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/page.tsx:206"}, "properties": {"repobilityId": "287f687da88b9452", "scanner": "scanner-primary", "fingerprint": "65c934674c8060a3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/partners/page.tsx"}, "region": {"startLine": 206}}}]}, {"ruleId": "scanner-220f93ee13894be9", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/[partnerId]/page.tsx:250"}, "properties": {"repobilityId": "411b75317ae4dbce", "scanner": "scanner-primary", "fingerprint": "220f93ee13894be9", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/partners/[partnerId]/page.tsx"}, "region": {"startLine": 250}}}]}, {"ruleId": "scanner-f142df69e7c695a7", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/partners/new/page.tsx:465"}, "properties": {"repobilityId": "4a7d0e431bf609ee", "scanner": "scanner-primary", "fingerprint": "f142df69e7c695a7", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/partners/new/page.tsx"}, "region": {"startLine": 465}}}]}, {"ruleId": "scanner-39bb21818167743d", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/home/[[...sessionId]]/page.tsx:1816"}, "properties": {"repobilityId": "57abd35e560616e5", "scanner": "scanner-primary", "fingerprint": "39bb21818167743d", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/home/[[...sessionId]]/page.tsx"}, "region": {"startLine": 1816}}}]}, {"ruleId": "scanner-6594e5d948fb59d3", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/co-writer/[docId]/page.tsx:2063"}, "properties": {"repobilityId": "8613d962d99fc2fd", "scanner": "scanner-primary", "fingerprint": "6594e5d948fb59d3", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/co-writer/[docId]/page.tsx"}, "region": {"startLine": 2063}}}]}, {"ruleId": "scanner-f3e34d24e6b94ccc", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookCreator.tsx:433"}, "properties": {"repobilityId": "e698f4ee3b6a3412", "scanner": "scanner-primary", "fingerprint": "f3e34d24e6b94ccc", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/book/components/BookCreator.tsx"}, "region": {"startLine": 433}}}]}, {"ruleId": "scanner-f97b0a799258d822", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookChatPanel.tsx:429"}, "properties": {"repobilityId": "5675f476b4dd7711", "scanner": "scanner-primary", "fingerprint": "f97b0a799258d822", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/book/components/BookChatPanel.tsx"}, "region": {"startLine": 429}}}]}, {"ruleId": "scanner-02d736a600b4ca43", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(workspace)/book/components/BookProgressTimeline.tsx:233"}, "properties": {"repobilityId": "fa74a956f056bc02", "scanner": "scanner-primary", "fingerprint": "02d736a600b4ca43", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(workspace)/book/components/BookProgressTimeline.tsx"}, "region": {"startLine": 233}}}]}, {"ruleId": "scanner-fca20dd3868c50ac", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(admin)/admin/users/page.tsx:350"}, "properties": {"repobilityId": "84de0eb814fdfc7d", "scanner": "scanner-primary", "fingerprint": "fca20dd3868c50ac", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(admin)/admin/users/page.tsx"}, "region": {"startLine": 350}}}]}, {"ruleId": "scanner-cfea1b572f5a3bbb", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(utility)/space/learning/page.tsx:165"}, "properties": {"repobilityId": "8286c720240b5c08", "scanner": "scanner-primary", "fingerprint": "cfea1b572f5a3bbb", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(utility)/space/learning/page.tsx"}, "region": {"startLine": 165}}}]}, {"ruleId": "scanner-b421b452b1912a2b", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/app/(utility)/profile/page.tsx:254"}, "properties": {"repobilityId": "3a6a8771c3333aee", "scanner": "scanner-primary", "fingerprint": "b421b452b1912a2b", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/app/(utility)/profile/page.tsx"}, "region": {"startLine": 254}}}]}, {"ruleId": "scanner-25c352d66aa83a13", "level": "none", "message": {"text": "Truncated text has no discoverable full-value affordance \u2014 web/features/multi-user/components/GrantEditor.tsx:67"}, "properties": {"repobilityId": "80d992189d175394", "scanner": "scanner-primary", "fingerprint": "25c352d66aa83a13", "layer": "frontend", "severity": "info", "confidence": 0.65, "tags": ["frontend-quality", "fq.truncate.no-title"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/features/multi-user/components/GrantEditor.tsx"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-ec8716b9dd7be9ad", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/partners/channels/manager.py:158"}, "properties": {"repobilityId": "c389481fa5812482", "scanner": "scanner-primary", "fingerprint": "ec8716b9dd7be9ad", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/manager.py"}, "region": {"startLine": 158}}}]}, {"ruleId": "scanner-8b29a8a35ebdcd2b", "level": "warning", "message": {"text": "dynamic urllib use detected \u2014 deeptutor/runtime/launcher.py:429"}, "properties": {"repobilityId": "48a428be39e476ff", "scanner": "scanner-primary", "fingerprint": "8b29a8a35ebdcd2b", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/runtime/launcher.py"}, "region": {"startLine": 429}}}]}, {"ruleId": "scanner-2c24da87184b3747", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/services/memory/snapshot/adapters.py:33"}, "properties": {"repobilityId": "23303386c9ca5869", "scanner": "scanner-primary", "fingerprint": "2c24da87184b3747", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/memory/snapshot/adapters.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-09b6eff95a2cfe3e", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/services/partners/manager.py:116"}, "properties": {"repobilityId": "31c451c5b737ea50", "scanner": "scanner-primary", "fingerprint": "09b6eff95a2cfe3e", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/partners/manager.py"}, "region": {"startLine": 116}}}]}, {"ruleId": "scanner-ca15dc09d8966343", "level": "warning", "message": {"text": "insecure hash algorithm sha1 \u2014 deeptutor/services/partners/runtime.py:519"}, "properties": {"repobilityId": "b1162850f5a39071", "scanner": "scanner-primary", "fingerprint": "ca15dc09d8966343", "layer": "security", "severity": "medium", "confidence": 0.75, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/partners/runtime.py"}, "region": {"startLine": 519}}}]}, {"ruleId": "scanner-9115c1af216ee250", "level": "error", "message": {"text": "subprocess shell true \u2014 deeptutor/services/sandbox/runner/server.py:217"}, "properties": {"repobilityId": "505d1a6ce57b0d16", "scanner": "scanner-primary", "fingerprint": "9115c1af216ee250", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["semgrep", "security", "python"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/sandbox/runner/server.py"}, "region": {"startLine": 217}}}]}, {"ruleId": "scanner-9c93156888d867c2", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 1.1.14 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "d283290da906832d", "scanner": "scanner-primary", "fingerprint": "9c93156888d867c2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-5a05f4c500f91e16", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 2.1.1 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "d283290da906832d", "scanner": "scanner-primary", "fingerprint": "5a05f4c500f91e16", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-1fea18ce3c855002", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "2b8b00dfea20e15a", "scanner": "scanner-primary", "fingerprint": "1fea18ce3c855002", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-7bd40700299a13f2", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "75c1e64287721fe9", "scanner": "scanner-primary", "fingerprint": "7bd40700299a13f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-44416cca6c3853f9", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "cf050cba5605d8c6", "scanner": "scanner-primary", "fingerprint": "44416cca6c3853f9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-4ac7ec7a2936251f", "level": "warning", "message": {"text": "GHSA-76mc-f452-cxcm: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "66a02bb7b3c5de03", "scanner": "scanner-primary", "fingerprint": "4ac7ec7a2936251f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-76mc-f452-cxcm"]}}, {"ruleId": "scanner-eb09d3dfa44368ef", "level": "warning", "message": {"text": "GHSA-cmwh-pvxp-8882: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "8aa5a56c33315a3f", "scanner": "scanner-primary", "fingerprint": "eb09d3dfa44368ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-cmwh-pvxp-8882"]}}, {"ruleId": "scanner-6e5b2e357cab1152", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "34904be9ab0ce7b6", "scanner": "scanner-primary", "fingerprint": "6e5b2e357cab1152", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-5b28170524c17c05", "level": "note", "message": {"text": "GHSA-gvmj-g25r-r7wr: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e4b1f4512f08ccd3", "scanner": "scanner-primary", "fingerprint": "5b28170524c17c05", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gvmj-g25r-r7wr"]}}, {"ruleId": "scanner-533ad82f1737d3aa", "level": "note", "message": {"text": "GHSA-vxr8-fq34-vvx9: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "f7e135356d2f19e8", "scanner": "scanner-primary", "fingerprint": "533ad82f1737d3aa", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-vxr8-fq34-vvx9"]}}, {"ruleId": "scanner-73600bbf0a106a75", "level": "note", "message": {"text": "GHSA-x4vx-rjvf-j5p4: dompurify 3.4.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "38da1643ba15162e", "scanner": "scanner-primary", "fingerprint": "73600bbf0a106a75", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-x4vx-rjvf-j5p4"]}}, {"ruleId": "scanner-33b3260f6fb18791", "level": "warning", "message": {"text": "CVE-2026-41148: mermaid 11.14.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "4896e407d4de072d", "scanner": "scanner-primary", "fingerprint": "33b3260f6fb18791", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41148"]}}, {"ruleId": "scanner-361ed789414a9cf6", "level": "warning", "message": {"text": "CVE-2026-41149: mermaid 11.14.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "14bade9d7e035a4b", "scanner": "scanner-primary", "fingerprint": "361ed789414a9cf6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41149"]}}, {"ruleId": "scanner-81e498f6946a76e2", "level": "warning", "message": {"text": "CVE-2026-41150: mermaid 11.14.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "b641b66631283ce3", "scanner": "scanner-primary", "fingerprint": "81e498f6946a76e2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41150"]}}, {"ruleId": "scanner-fbe80bac0abee1bc", "level": "warning", "message": {"text": "CVE-2026-41159: mermaid 11.14.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "8f3385dd72e81b2b", "scanner": "scanner-primary", "fingerprint": "fbe80bac0abee1bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41159"]}}, {"ruleId": "scanner-99cc41c6b7c3ac3e", "level": "error", "message": {"text": "CVE-2026-44573: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "af45b46aabc78a4f", "scanner": "scanner-primary", "fingerprint": "99cc41c6b7c3ac3e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44573"]}}, {"ruleId": "scanner-de3e4518cb40778c", "level": "error", "message": {"text": "CVE-2026-44574: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "af5257372005af33", "scanner": "scanner-primary", "fingerprint": "de3e4518cb40778c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44574"]}}, {"ruleId": "scanner-8d43addef3f7d914", "level": "error", "message": {"text": "CVE-2026-44575: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "0f7798271c1e2882", "scanner": "scanner-primary", "fingerprint": "8d43addef3f7d914", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44575"]}}, {"ruleId": "scanner-fd10c5ba94ed11cf", "level": "error", "message": {"text": "CVE-2026-44578: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "63f88c8318c28781", "scanner": "scanner-primary", "fingerprint": "fd10c5ba94ed11cf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44578"]}}, {"ruleId": "scanner-188950c91d40caae", "level": "error", "message": {"text": "CVE-2026-44579: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "294f9a464075de4b", "scanner": "scanner-primary", "fingerprint": "188950c91d40caae", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44579"]}}, {"ruleId": "scanner-48a1fb7c2e28f674", "level": "error", "message": {"text": "CVE-2026-45109: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "76ec0465adf29dd4", "scanner": "scanner-primary", "fingerprint": "48a1fb7c2e28f674", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45109"]}}, {"ruleId": "scanner-eb8ba3361968a14b", "level": "error", "message": {"text": "CVE-2026-64641: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "b9ea8e2d531ea336", "scanner": "scanner-primary", "fingerprint": "eb8ba3361968a14b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64641"]}}, {"ruleId": "scanner-53ec088e86c457af", "level": "error", "message": {"text": "CVE-2026-64642: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "2897514d5c11639e", "scanner": "scanner-primary", "fingerprint": "53ec088e86c457af", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64642"]}}, {"ruleId": "scanner-76d19ed1f7b581ba", "level": "error", "message": {"text": "CVE-2026-64645: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "858a5a3b9f07c825", "scanner": "scanner-primary", "fingerprint": "76d19ed1f7b581ba", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64645"]}}, {"ruleId": "scanner-b9b6083696bb6457", "level": "error", "message": {"text": "CVE-2026-64649: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "db0bc21e0dcefb5a", "scanner": "scanner-primary", "fingerprint": "b9b6083696bb6457", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64649"]}}, {"ruleId": "scanner-9a13d5efd0c28afd", "level": "error", "message": {"text": "GHSA-8h8q-6873-q5fj: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "24acd41d963d1f01", "scanner": "scanner-primary", "fingerprint": "9a13d5efd0c28afd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-8h8q-6873-q5fj"]}}, {"ruleId": "scanner-3fc29b6fc2ff0d53", "level": "warning", "message": {"text": "CVE-2026-44576: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "93c87032a02c1a73", "scanner": "scanner-primary", "fingerprint": "3fc29b6fc2ff0d53", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44576"]}}, {"ruleId": "scanner-5d1e86583da8b084", "level": "warning", "message": {"text": "CVE-2026-44577: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "47cf4e65f3f16813", "scanner": "scanner-primary", "fingerprint": "5d1e86583da8b084", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44577"]}}, {"ruleId": "scanner-24d6d22462431ddd", "level": "warning", "message": {"text": "CVE-2026-44580: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "5c762ced1ee4db71", "scanner": "scanner-primary", "fingerprint": "24d6d22462431ddd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44580"]}}, {"ruleId": "scanner-dc044f1e63bcba7f", "level": "warning", "message": {"text": "CVE-2026-44581: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "651d30edf3fa71d0", "scanner": "scanner-primary", "fingerprint": "dc044f1e63bcba7f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44581"]}}, {"ruleId": "scanner-649befb39e80cfcd", "level": "warning", "message": {"text": "CVE-2026-64643: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "af4493266c11ce72", "scanner": "scanner-primary", "fingerprint": "649befb39e80cfcd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64643"]}}, {"ruleId": "scanner-646418b4113a82f6", "level": "warning", "message": {"text": "CVE-2026-64644: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "d0261c87de6c28c1", "scanner": "scanner-primary", "fingerprint": "646418b4113a82f6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64644"]}}, {"ruleId": "scanner-5999475aad96f80b", "level": "warning", "message": {"text": "CVE-2026-64646: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "d75eae28fdee0b1c", "scanner": "scanner-primary", "fingerprint": "5999475aad96f80b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64646"]}}, {"ruleId": "scanner-8c40d0276e6b52a4", "level": "warning", "message": {"text": "CVE-2026-64647: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "b36fa7bd5b12cdf6", "scanner": "scanner-primary", "fingerprint": "8c40d0276e6b52a4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64647"]}}, {"ruleId": "scanner-63197c94a3693fdf", "level": "warning", "message": {"text": "CVE-2026-64648: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "ca0a9f0e493fe5fe", "scanner": "scanner-primary", "fingerprint": "63197c94a3693fdf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-64648"]}}, {"ruleId": "scanner-16760f00ea730875", "level": "note", "message": {"text": "CVE-2026-44572: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "5f3677f784a74537", "scanner": "scanner-primary", "fingerprint": "16760f00ea730875", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44572"]}}, {"ruleId": "scanner-2df29f9ede12ce44", "level": "note", "message": {"text": "CVE-2026-44582: next 16.2.3 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "0b6d6780846c556a", "scanner": "scanner-primary", "fingerprint": "2df29f9ede12ce44", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44582"]}}, {"ruleId": "scanner-745c333bbc7b47df", "level": "warning", "message": {"text": "CVE-2026-41305: postcss 8.4.31 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "ec981160862bd975", "scanner": "scanner-primary", "fingerprint": "745c333bbc7b47df", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41305"]}}, {"ruleId": "scanner-133910447fa2165a", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "4b11c5d885ad6f48", "scanner": "scanner-primary", "fingerprint": "133910447fa2165a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-876259069f5195e3", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 11.1.0 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e6fe637fa2839979", "scanner": "scanner-primary", "fingerprint": "876259069f5195e3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-81380ffa621907c4", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 8.3.2 \u2014 web/package-lock.json"}, "properties": {"repobilityId": "e6fe637fa2839979", "scanner": "scanner-primary", "fingerprint": "81380ffa621907c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-3a3527e70129fb18", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "properties": {"repobilityId": "691787f6b20605df", "scanner": "scanner-primary", "fingerprint": "3a3527e70129fb18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-ad0c3fb4e1c91b75", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile.runner"}, "properties": {"repobilityId": "b12176107de79e91", "scanner": "scanner-primary", "fingerprint": "ad0c3fb4e1c91b75", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-f76567934ce2c9e8", "level": "warning", "message": {"text": "Privileged port 10 in use"}, "properties": {"repobilityId": "735372d6b5594915", "scanner": "scanner-primary", "fingerprint": "f76567934ce2c9e8", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.ghcr.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-93e02e0d67c8f3e8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "properties": {"repobilityId": "0f4d4003ef2ac487", "scanner": "scanner-primary", "fingerprint": "93e02e0d67c8f3e8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-e066691601852931", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "7b0194d9426cbd2f", "scanner": "scanner-primary", "fingerprint": "e066691601852931", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-d0c875fab812197d", "level": "warning", "message": {"text": "Docker base image uses a mutable or implicit tag: pathlib"}, "properties": {"repobilityId": "b6fd1bd91ba3dea6", "scanner": "scanner-primary", "fingerprint": "d0c875fab812197d", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 346}}}]}, {"ruleId": "scanner-f39b9f5db34a2774", "level": "warning", "message": {"text": "Docker base image uses a mutable or implicit tag: deeptutor.services.setup"}, "properties": {"repobilityId": "df2aec25d3fa9e8c", "scanner": "scanner-primary", "fingerprint": "f39b9f5db34a2774", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 347}}}]}, {"ruleId": "scanner-b8e6f9ee00b7ed30", "level": "warning", "message": {"text": "Docker base image uses a mutable or implicit tag: deeptutor.services.config"}, "properties": {"repobilityId": "9f15c5817023ec68", "scanner": "scanner-primary", "fingerprint": "b8e6f9ee00b7ed30", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 358}}}]}, {"ruleId": "scanner-295aa83a3709f7e3", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in web/components/ThemeScript.tsx:45"}, "properties": {"repobilityId": "7fb9665bd7598924", "scanner": "scanner-primary", "fingerprint": "295aa83a3709f7e3", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/ThemeScript.tsx"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-0d03a3721d1dccf8", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in web/components/Mermaid.tsx:174"}, "properties": {"repobilityId": "2617f133c12281d6", "scanner": "scanner-primary", "fingerprint": "0d03a3721d1dccf8", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/Mermaid.tsx"}, "region": {"startLine": 174}}}]}, {"ruleId": "scanner-56ef3c080812c3d8", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in web/components/visualize/VisualizationViewer.tsx:333"}, "properties": {"repobilityId": "9b3488d814e676cd", "scanner": "scanner-primary", "fingerprint": "56ef3c080812c3d8", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/components/visualize/VisualizationViewer.tsx"}, "region": {"startLine": 333}}}]}, {"ruleId": "scanner-c70e23b4a2eb0344", "level": "error", "message": {"text": "Insecure pattern 'subprocess_shell_true' in deeptutor/services/sandbox/runner/server.py:215"}, "properties": {"repobilityId": "cbd43b24ea8d298d", "scanner": "scanner-primary", "fingerprint": "c70e23b4a2eb0344", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "subprocess_shell_true"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/sandbox/runner/server.py"}, "region": {"startLine": 215}}}]}, {"ruleId": "scanner-7092ef6b42892f71", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/openai_http_client.py:42"}, "properties": {"repobilityId": "2bec6667b7317905", "scanner": "scanner-primary", "fingerprint": "7092ef6b42892f71", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/llm/openai_http_client.py"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-b9b8e6f14bd2cce0", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/providers/open_ai.py:65"}, "properties": {"repobilityId": "6d9206a28e6ca440", "scanner": "scanner-primary", "fingerprint": "b9b8e6f14bd2cce0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/llm/providers/open_ai.py"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-58b7c97a2cb428d0", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/services/llm/provider_core/openai_codex_provider.py:86"}, "properties": {"repobilityId": "62a7a4af6db187e5", "scanner": "scanner-primary", "fingerprint": "58b7c97a2cb428d0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/services/llm/provider_core/openai_codex_provider.py"}, "region": {"startLine": 86}}}]}, {"ruleId": "scanner-fc13aaa9ee76962a", "level": "error", "message": {"text": "Insecure pattern 'tls_verify_false' in deeptutor/core/agentic/client.py:67"}, "properties": {"repobilityId": "eca29af122dee0eb", "scanner": "scanner-primary", "fingerprint": "fc13aaa9ee76962a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "tls_verify_false"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/core/agentic/client.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-58288fdbe718b8e9", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b62ecc4474f14386", "scanner": "scanner-primary", "fingerprint": "58288fdbe718b8e9", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pypi-release.yml"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-d7e207e1f1c64778", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "6a22a520cba8a937", "scanner": "scanner-primary", "fingerprint": "d7e207e1f1c64778", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pypi-release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5af2dfac961b2a63", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "fd17382537d0b6cc", "scanner": "scanner-primary", "fingerprint": "5af2dfac961b2a63", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-release.yml"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-4f32678841e6e849", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "4fe1f869113bbe04", "scanner": "scanner-primary", "fingerprint": "4f32678841e6e849", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1a50467f36b413ec", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "aecc3f31ca3f42da", "scanner": "scanner-primary", "fingerprint": "1a50467f36b413ec", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/tests.yml"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-365ae647c92ac3d5", "level": "note", "message": {"text": "Very large file: tests/services/test_subagent_backends.py (1359 lines)"}, "properties": {"repobilityId": "7caa96d1b9c3a626", "scanner": "scanner-primary", "fingerprint": "365ae647c92ac3d5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-37e2b5ac18af03bd", "level": "note", "message": {"text": "Very large file: web/components/settings/ServiceConfigEditor.tsx (1191 lines)"}, "properties": {"repobilityId": "acef9726684324fe", "scanner": "scanner-primary", "fingerprint": "37e2b5ac18af03bd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ae1d0a7141c595b5", "level": "note", "message": {"text": "Very large file: web/components/chat/home/TracePanels.tsx (2589 lines)"}, "properties": {"repobilityId": "a7fa80e44fdb6a13", "scanner": "scanner-primary", "fingerprint": "ae1d0a7141c595b5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-82a299fdd6e0bbb2", "level": "note", "message": {"text": "Very large file: web/components/chat/home/ChatMessages.tsx (1496 lines)"}, "properties": {"repobilityId": "0f4dd3de698019ba", "scanner": "scanner-primary", "fingerprint": "82a299fdd6e0bbb2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-be6e747bfb9702fe", "level": "note", "message": {"text": "Very large file: web/components/quiz/QuizViewer.tsx (1431 lines)"}, "properties": {"repobilityId": "db92a5726fc803d0", "scanner": "scanner-primary", "fingerprint": "be6e747bfb9702fe", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2e119636ad9c25b2", "level": "note", "message": {"text": "Very large file: web/components/memory/MemorySection.tsx (1522 lines)"}, "properties": {"repobilityId": "6fc11e4f5e1ab99a", "scanner": "scanner-primary", "fingerprint": "2e119636ad9c25b2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-20a9da65a69c425f", "level": "note", "message": {"text": "Very large file: web/app/(workspace)/playground/page.tsx (2077 lines)"}, "properties": {"repobilityId": "9d6b493c66f2f0d3", "scanner": "scanner-primary", "fingerprint": "20a9da65a69c425f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2bb50cc0dda553f0", "level": "note", "message": {"text": "Very large file: web/app/(workspace)/home/[[...sessionId]]/page.tsx (2202 lines)"}, "properties": {"repobilityId": "97edb78bc6c2a1b7", "scanner": "scanner-primary", "fingerprint": "2bb50cc0dda553f0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b8c78a0a1d4a1aa1", "level": "note", "message": {"text": "Very large file: web/app/(workspace)/co-writer/[docId]/page.tsx (2495 lines)"}, "properties": {"repobilityId": "2b5ca380a2bd1b5c", "scanner": "scanner-primary", "fingerprint": "b8c78a0a1d4a1aa1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ba03f6a69be0ef66", "level": "note", "message": {"text": "Very large file: web/context/UnifiedChatContext.tsx (1885 lines)"}, "properties": {"repobilityId": "9a31946d51c62e11", "scanner": "scanner-primary", "fingerprint": "ba03f6a69be0ef66", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3e2852e2f7e8b268", "level": "note", "message": {"text": "Very large file: deeptutor/partners/channels/feishu.py (1344 lines)"}, "properties": {"repobilityId": "ea4a3715b19f2281", "scanner": "scanner-primary", "fingerprint": "3e2852e2f7e8b268", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5a3eb3c545d90134", "level": "note", "message": {"text": "Very large file: deeptutor/partners/channels/weixin.py (1564 lines)"}, "properties": {"repobilityId": "e287aa1299cbcbce", "scanner": "scanner-primary", "fingerprint": "5a3eb3c545d90134", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ec8c79ec4e9a027f", "level": "note", "message": {"text": "Very large file: deeptutor/api/routers/knowledge.py (2808 lines)"}, "properties": {"repobilityId": "5ac9076f87edac82", "scanner": "scanner-primary", "fingerprint": "ec8c79ec4e9a027f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4380e9f03167a520", "level": "note", "message": {"text": "Very large file: deeptutor/agents/question/pipeline.py (2161 lines)"}, "properties": {"repobilityId": "8f8d524f5ec58bac", "scanner": "scanner-primary", "fingerprint": "4380e9f03167a520", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-67260fb4f0ee55b4", "level": "note", "message": {"text": "Very large file: deeptutor/agents/research/pipeline.py (2800 lines)"}, "properties": {"repobilityId": "61e68d94891dca81", "scanner": "scanner-primary", "fingerprint": "67260fb4f0ee55b4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-70c8b2b9e9de5e04", "level": "note", "message": {"text": "Very large file: deeptutor/agents/chat/agentic_pipeline.py (1420 lines)"}, "properties": {"repobilityId": "133de60f9381ea0c", "scanner": "scanner-primary", "fingerprint": "70c8b2b9e9de5e04", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ffb7730f7a6bf7fc", "level": "note", "message": {"text": "Very large file: deeptutor/services/partners/manager.py (1291 lines)"}, "properties": {"repobilityId": "3122543dd9e774f0", "scanner": "scanner-primary", "fingerprint": "ffb7730f7a6bf7fc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-fbb34a11e46e7c77", "level": "note", "message": {"text": "Very large file: deeptutor/services/session/turn_runtime.py (2042 lines)"}, "properties": {"repobilityId": "da2651873bc09529", "scanner": "scanner-primary", "fingerprint": "fbb34a11e46e7c77", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d0a2c31ffb8b93aa", "level": "note", "message": {"text": "Very large file: deeptutor/services/session/sqlite_store.py (1844 lines)"}, "properties": {"repobilityId": "b62eb000e9cf4d12", "scanner": "scanner-primary", "fingerprint": "d0a2c31ffb8b93aa", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3269bae97c740d39", "level": "note", "message": {"text": "Very large file: deeptutor/tools/builtin/__init__.py (1595 lines)"}, "properties": {"repobilityId": "0cfcd134cd1d9360", "scanner": "scanner-primary", "fingerprint": "3269bae97c740d39", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-96c8cf4f840335cd", "level": "note", "message": {"text": "Very large file: deeptutor/book/engine.py (1290 lines)"}, "properties": {"repobilityId": "c6e21e1ff4fb1cba", "scanner": "scanner-primary", "fingerprint": "96c8cf4f840335cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-097e319e326323e5", "level": "note", "message": {"text": "Very large file: deeptutor/knowledge/manager.py (1763 lines)"}, "properties": {"repobilityId": "6f3c6ae215f32ea3", "scanner": "scanner-primary", "fingerprint": "097e319e326323e5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "4e13bafcb9fade5d", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "e5cb1d268df63401", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "426342839604b2e9", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "350cda71d98263fa", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-398295a4d3bf2a0c", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/docker_compose.py:107"}, "properties": {"repobilityId": "6620f359dde5775c", "scanner": "scanner-primary", "fingerprint": "398295a4d3bf2a0c", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/docker_compose.py"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-f1e68c70c216985a", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/prepare_web_package.py:33"}, "properties": {"repobilityId": "ce081ed9c0a84ada", "scanner": "scanner-primary", "fingerprint": "f1e68c70c216985a", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/prepare_web_package.py"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-b35dbf54c237b7b9", "level": "note", "message": {"text": "Legacy-named symbol `isLegacy` in web/components/knowledge/KbIndexVersionsSection.tsx:230"}, "properties": {"repobilityId": "20aea8da7298065e", "scanner": "scanner-primary", "fingerprint": "b35dbf54c237b7b9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-974abd53354bfa9b", "level": "note", "message": {"text": "Legacy-named symbol `mOld` in web/lib/memory-graph.ts:165"}, "properties": {"repobilityId": "17168e2a460c5b60", "scanner": "scanner-primary", "fingerprint": "974abd53354bfa9b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-82afcc581d9413bb", "level": "note", "message": {"text": "Legacy-named symbol `migrateLegacy` in web/lib/chat-import/agent-store.ts:49"}, "properties": {"repobilityId": "048c54634e0274c2", "scanner": "scanner-primary", "fingerprint": "82afcc581d9413bb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4da68657f8ba80ed", "level": "note", "message": {"text": "Legacy-named symbol `receive_v1` in deeptutor/partners/channels/feishu.py:274"}, "properties": {"repobilityId": "cfa939275d7456c2", "scanner": "scanner-primary", "fingerprint": "4da68657f8ba80ed", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-584548fbf58674b7", "level": "error", "message": {"text": "Blocking `time.sleep(...)` inside `async def start` \u2014 deeptutor/partners/channels/feishu.py:379"}, "properties": {"repobilityId": "3d74fe44acf3d0c0", "scanner": "scanner-primary", "fingerprint": "584548fbf58674b7", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/partners/channels/feishu.py"}, "region": {"startLine": 379}}}]}, {"ruleId": "scanner-bcf8edeca8402e2d", "level": "note", "message": {"text": "Stub function `log_message` (body is just `pass`/`return`) \u2014 deeptutor/partners/channels/msteams.py:215"}, "properties": {"repobilityId": "d78138c6e2971e7c", "scanner": "scanner-primary", "fingerprint": "bcf8edeca8402e2d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-f6dab644f053f63c", "level": "note", "message": {"text": "Legacy-named symbol `files_upload_v2` in deeptutor/partners/channels/slack.py:154"}, "properties": {"repobilityId": "7f8c77740e5311c1", "scanner": "scanner-primary", "fingerprint": "f6dab644f053f63c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-84a64e2a5b49eecb", "level": "note", "message": {"text": "Legacy-named symbol `data_copy` in deeptutor/agents/research/data_structures.py:229"}, "properties": {"repobilityId": "5d891bdc244e5b83", "scanner": "scanner-primary", "fingerprint": "84a64e2a5b49eecb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9a759a9a2269810a", "level": "note", "message": {"text": "Stub function `emit_terminator` (body is just `pass`/`return`) \u2014 deeptutor/agents/research/pipeline.py:2422"}, "properties": {"repobilityId": "53e3ef43ec1a5b97", "scanner": "scanner-primary", "fingerprint": "9a759a9a2269810a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-5427f349a4397ef8", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 deeptutor/runtime/launcher.py:122"}, "properties": {"repobilityId": "0f56966a19e48f0a", "scanner": "scanner-primary", "fingerprint": "5427f349a4397ef8", "layer": "quality", "severity": "medium", "confidence": 0.85, "tags": ["integrity", "fragile-runtime", "robustness"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/runtime/launcher.py"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-09741fbf52192614", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in deeptutor/services/partners/model_runtime.py:32"}, "properties": {"repobilityId": "7b377da89bf7920b", "scanner": "scanner-primary", "fingerprint": "09741fbf52192614", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-ad43c1f596c2e7ad", "level": "note", "message": {"text": "Legacy-named symbol `_migrated_legacy` in deeptutor/services/partners/manager.py:286"}, "properties": {"repobilityId": "de51ce8dc8abb007", "scanner": "scanner-primary", "fingerprint": "ad43c1f596c2e7ad", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-039b242ab55b75ba", "level": "note", "message": {"text": "Legacy-named symbol `nested_legacy` in deeptutor/services/rag/index_versioning.py:135"}, "properties": {"repobilityId": "fc41afc2b665dab0", "scanner": "scanner-primary", "fingerprint": "039b242ab55b75ba", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6040d91dfded6d75", "level": "note", "message": {"text": "Legacy-named symbol `nested_legacy` in deeptutor/services/rag/pipelines/llamaindex/storage.py:41"}, "properties": {"repobilityId": "225a60142d0ff91d", "scanner": "scanner-primary", "fingerprint": "6040d91dfded6d75", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4b0fe5b3ba01e677", "level": "note", "message": {"text": "Legacy-named symbol `baidu_search_v2` in deeptutor/services/search/providers/baidu.py:37"}, "properties": {"repobilityId": "888326b13e5c6b04", "scanner": "scanner-primary", "fingerprint": "4b0fe5b3ba01e677", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-445415a8b8f6bc5f", "level": "note", "message": {"text": "Stub function `_get_session_id_prefix` (body is just `pass`/`return`) \u2014 deeptutor/services/session/base_session_manager.py:70"}, "properties": {"repobilityId": "a024f97dc15c8247", "scanner": "scanner-primary", "fingerprint": "445415a8b8f6bc5f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-1c81ba773b1b44aa", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in deeptutor/services/llm/config.py:120"}, "properties": {"repobilityId": "1e1e9027dd4bd6c6", "scanner": "scanner-primary", "fingerprint": "1c81ba773b1b44aa", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a94b4b16d9a3baa5", "level": "note", "message": {"text": "Legacy-named symbol `model_copy` in deeptutor/services/llm/factory.py:230"}, "properties": {"repobilityId": "a3088ff68adea04b", "scanner": "scanner-primary", "fingerprint": "a94b4b16d9a3baa5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-bd1e7ac900f10ce2", "level": "note", "message": {"text": "Stub function `_default_sleep` (body is just `pass`/`return`) \u2014 deeptutor/services/llm/providers/base_provider.py:185"}, "properties": {"repobilityId": "6cb4f6d5e358124c", "scanner": "scanner-primary", "fingerprint": "bd1e7ac900f10ce2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-575a8ec6d52e99da", "level": "note", "message": {"text": "Legacy-named symbol `no_backup` in deeptutor/knowledge/manager.py:1754"}, "properties": {"repobilityId": "1f542aad9b186080", "scanner": "scanner-primary", "fingerprint": "575a8ec6d52e99da", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a260e355ea7d9f89", "level": "note", "message": {"text": "32 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "e735cee6f43259c2", "scanner": "scanner-primary", "fingerprint": "a260e355ea7d9f89", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "9bf2fa3b0d0f28f1", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-faade12274512e92", "level": "error", "message": {"text": "FastAPI DELETE `delete_book` without auth dependency \u2014 deeptutor/api/routers/book.py:189"}, "properties": {"repobilityId": "1f7ad0a88f85da8e", "scanner": "scanner-primary", "fingerprint": "faade12274512e92", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 189}}}]}, {"ruleId": "scanner-fe9fa73788605f1a", "level": "error", "message": {"text": "FastAPI POST `create_book` without auth dependency \u2014 deeptutor/api/routers/book.py:198"}, "properties": {"repobilityId": "27c3544ffec3bf29", "scanner": "scanner-primary", "fingerprint": "fe9fa73788605f1a", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 198}}}]}, {"ruleId": "scanner-8bf640620ab68f81", "level": "error", "message": {"text": "FastAPI POST `confirm_proposal` without auth dependency \u2014 deeptutor/api/routers/book.py:224"}, "properties": {"repobilityId": "772e4dd4fe06cd36", "scanner": "scanner-primary", "fingerprint": "8bf640620ab68f81", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 224}}}]}, {"ruleId": "scanner-d7f1af5627c3e784", "level": "error", "message": {"text": "FastAPI POST `confirm_spine` without auth dependency \u2014 deeptutor/api/routers/book.py:247"}, "properties": {"repobilityId": "580de14bd165fc2d", "scanner": "scanner-primary", "fingerprint": "d7f1af5627c3e784", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 247}}}]}, {"ruleId": "scanner-223d1dc82f8d0477", "level": "error", "message": {"text": "FastAPI POST `compile_page` without auth dependency \u2014 deeptutor/api/routers/book.py:271"}, "properties": {"repobilityId": "7a5337d813e493f7", "scanner": "scanner-primary", "fingerprint": "223d1dc82f8d0477", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 271}}}]}, {"ruleId": "scanner-3f45242b804fd2f6", "level": "error", "message": {"text": "FastAPI POST `regenerate_block` without auth dependency \u2014 deeptutor/api/routers/book.py:285"}, "properties": {"repobilityId": "228b020527b9202a", "scanner": "scanner-primary", "fingerprint": "3f45242b804fd2f6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 285}}}]}, {"ruleId": "scanner-ba1614efe4eea97c", "level": "error", "message": {"text": "FastAPI POST `insert_block` without auth dependency \u2014 deeptutor/api/routers/book.py:317"}, "properties": {"repobilityId": "3aff9849b3d857cf", "scanner": "scanner-primary", "fingerprint": "ba1614efe4eea97c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 317}}}]}, {"ruleId": "scanner-d4bdcf7c7f2adfd7", "level": "error", "message": {"text": "FastAPI POST `delete_block` without auth dependency \u2014 deeptutor/api/routers/book.py:338"}, "properties": {"repobilityId": "63160c0ec23f5650", "scanner": "scanner-primary", "fingerprint": "d4bdcf7c7f2adfd7", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 338}}}]}, {"ruleId": "scanner-bc35c26dd40929f5", "level": "error", "message": {"text": "FastAPI POST `move_block` without auth dependency \u2014 deeptutor/api/routers/book.py:347"}, "properties": {"repobilityId": "1105b37dccd43fa9", "scanner": "scanner-primary", "fingerprint": "bc35c26dd40929f5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 347}}}]}, {"ruleId": "scanner-973dc6be67482625", "level": "error", "message": {"text": "FastAPI POST `change_block_type` without auth dependency \u2014 deeptutor/api/routers/book.py:361"}, "properties": {"repobilityId": "736f016e83724c4b", "scanner": "scanner-primary", "fingerprint": "973dc6be67482625", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 361}}}]}, {"ruleId": "scanner-bebdab58ba7651cb", "level": "error", "message": {"text": "FastAPI POST `deep_dive` without auth dependency \u2014 deeptutor/api/routers/book.py:381"}, "properties": {"repobilityId": "7dcfdcec69a08de2", "scanner": "scanner-primary", "fingerprint": "bebdab58ba7651cb", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 381}}}]}, {"ruleId": "scanner-822d1bc911a412e2", "level": "error", "message": {"text": "FastAPI POST `quiz_attempt` without auth dependency \u2014 deeptutor/api/routers/book.py:401"}, "properties": {"repobilityId": "011ab914f7173358", "scanner": "scanner-primary", "fingerprint": "822d1bc911a412e2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 401}}}]}, {"ruleId": "scanner-3f00d480b5d60885", "level": "error", "message": {"text": "FastAPI POST `refresh_fingerprints` without auth dependency \u2014 deeptutor/api/routers/book.py:423"}, "properties": {"repobilityId": "de47f551b69663d3", "scanner": "scanner-primary", "fingerprint": "3f00d480b5d60885", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 423}}}]}, {"ruleId": "scanner-afd11434706cb7d3", "level": "error", "message": {"text": "FastAPI POST `supplement` without auth dependency \u2014 deeptutor/api/routers/book.py:432"}, "properties": {"repobilityId": "3ba3e38cb5422f37", "scanner": "scanner-primary", "fingerprint": "afd11434706cb7d3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 432}}}]}, {"ruleId": "scanner-7b6d642a6dc71ff1", "level": "error", "message": {"text": "FastAPI POST `set_page_chat_session` without auth dependency \u2014 deeptutor/api/routers/book.py:449"}, "properties": {"repobilityId": "5cdbd1729d5d0fa8", "scanner": "scanner-primary", "fingerprint": "7b6d642a6dc71ff1", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 449}}}]}, {"ruleId": "scanner-1d63f8e719eacfc7", "level": "error", "message": {"text": "FastAPI POST `rebuild_book` without auth dependency \u2014 deeptutor/api/routers/book.py:462"}, "properties": {"repobilityId": "5acb3f8d811dfc66", "scanner": "scanner-primary", "fingerprint": "1d63f8e719eacfc7", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/book.py"}, "region": {"startLine": 462}}}]}, {"ruleId": "scanner-79e9a196ed1b8cfe", "level": "error", "message": {"text": "FastAPI POST `sync_backend` without auth dependency \u2014 deeptutor/api/routers/subagents.py:79"}, "properties": {"repobilityId": "a3cf923d6ee43600", "scanner": "scanner-primary", "fingerprint": "79e9a196ed1b8cfe", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/subagents.py"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-ad2731eb7d5b4097", "level": "error", "message": {"text": "FastAPI POST `create_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:132"}, "properties": {"repobilityId": "f52f0722d41206e9", "scanner": "scanner-primary", "fingerprint": "ad2731eb7d5b4097", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/subagents.py"}, "region": {"startLine": 132}}}]}, {"ruleId": "scanner-78f3b14fe75c9873", "level": "error", "message": {"text": "FastAPI DELETE `delete_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:193"}, "properties": {"repobilityId": "a315c4263ed7c8d4", "scanner": "scanner-primary", "fingerprint": "78f3b14fe75c9873", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/subagents.py"}, "region": {"startLine": 193}}}]}, {"ruleId": "scanner-f744a1572a8aae0c", "level": "error", "message": {"text": "FastAPI POST `message_connection` without auth dependency \u2014 deeptutor/api/routers/subagents.py:216"}, "properties": {"repobilityId": "e1ff863c1fdd294d", "scanner": "scanner-primary", "fingerprint": "f744a1572a8aae0c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/subagents.py"}, "region": {"startLine": 216}}}]}, {"ruleId": "scanner-8d6d0c3543bd576e", "level": "error", "message": {"text": "FastAPI POST `create_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:83"}, "properties": {"repobilityId": "74840e2fafc10873", "scanner": "scanner-primary", "fingerprint": "8d6d0c3543bd576e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-218fb75a2784dfdc", "level": "error", "message": {"text": "FastAPI PUT `rename_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:95"}, "properties": {"repobilityId": "cf9f455ac42547b9", "scanner": "scanner-primary", "fingerprint": "218fb75a2784dfdc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 95}}}]}, {"ruleId": "scanner-bbbb15952bec1c41", "level": "error", "message": {"text": "FastAPI DELETE `delete_tag` without auth dependency \u2014 deeptutor/api/routers/skills.py:109"}, "properties": {"repobilityId": "212611b4df0ff424", "scanner": "scanner-primary", "fingerprint": "bbbb15952bec1c41", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 109}}}]}, {"ruleId": "scanner-5424d52147ab6600", "level": "error", "message": {"text": "FastAPI POST `create_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:214"}, "properties": {"repobilityId": "8604e2215ebf296b", "scanner": "scanner-primary", "fingerprint": "5424d52147ab6600", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 214}}}]}, {"ruleId": "scanner-82cc516ffdac8e19", "level": "error", "message": {"text": "FastAPI POST `install_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:233"}, "properties": {"repobilityId": "30cbfd129a307161", "scanner": "scanner-primary", "fingerprint": "82cc516ffdac8e19", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 233}}}]}, {"ruleId": "scanner-12bb9ab3946d3de4", "level": "error", "message": {"text": "FastAPI PUT `update_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:270"}, "properties": {"repobilityId": "414e50f0dae102dd", "scanner": "scanner-primary", "fingerprint": "12bb9ab3946d3de4", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 270}}}]}, {"ruleId": "scanner-a79924abf8fe37a9", "level": "error", "message": {"text": "FastAPI DELETE `delete_skill` without auth dependency \u2014 deeptutor/api/routers/skills.py:294"}, "properties": {"repobilityId": "bde5f24a5247d5c7", "scanner": "scanner-primary", "fingerprint": "a79924abf8fe37a9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/skills.py"}, "region": {"startLine": 294}}}]}, {"ruleId": "scanner-a96141667f8a7959", "level": "error", "message": {"text": "FastAPI POST `edit_text` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:379"}, "properties": {"repobilityId": "39c71986b95ad33a", "scanner": "scanner-primary", "fingerprint": "a96141667f8a7959", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 379}}}]}, {"ruleId": "scanner-2f2325c50afbc37b", "level": "error", "message": {"text": "FastAPI POST `edit_text_react` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:403"}, "properties": {"repobilityId": "df5aafd0757a9e51", "scanner": "scanner-primary", "fingerprint": "2f2325c50afbc37b", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 403}}}]}, {"ruleId": "scanner-3ad1b2ce35dc9916", "level": "error", "message": {"text": "FastAPI POST `edit_text_react_stream` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:414"}, "properties": {"repobilityId": "fefaa0a02bb386a1", "scanner": "scanner-primary", "fingerprint": "3ad1b2ce35dc9916", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 414}}}]}, {"ruleId": "scanner-c981c42e503628e9", "level": "error", "message": {"text": "FastAPI POST `auto_mark_text` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:427"}, "properties": {"repobilityId": "4795ae38c0b69e2b", "scanner": "scanner-primary", "fingerprint": "c981c42e503628e9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-5e5941ac9fd06fb2", "level": "error", "message": {"text": "FastAPI POST `create_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:558"}, "properties": {"repobilityId": "c1efae4ceb3ccd26", "scanner": "scanner-primary", "fingerprint": "5e5941ac9fd06fb2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 558}}}]}, {"ruleId": "scanner-1aa86e3873a50cd5", "level": "error", "message": {"text": "FastAPI PUT `update_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:586"}, "properties": {"repobilityId": "5eda4ff7855c5d9e", "scanner": "scanner-primary", "fingerprint": "1aa86e3873a50cd5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 586}}}]}, {"ruleId": "scanner-aaea06d2d91fb298", "level": "error", "message": {"text": "FastAPI DELETE `delete_document` without auth dependency \u2014 deeptutor/api/routers/co_writer.py:604"}, "properties": {"repobilityId": "b9d122dc3947479a", "scanner": "scanner-primary", "fingerprint": "aaea06d2d91fb298", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/co_writer.py"}, "region": {"startLine": 604}}}]}, {"ruleId": "scanner-ab90b50c2e583efb", "level": "error", "message": {"text": "FastAPI PUT `set_rag_provider_mode` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1007"}, "properties": {"repobilityId": "6d3fa235cf8786e2", "scanner": "scanner-primary", "fingerprint": "ab90b50c2e583efb", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1007}}}]}, {"ruleId": "scanner-bb6791eb4d41441f", "level": "error", "message": {"text": "FastAPI PUT `update_pageindex_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1062"}, "properties": {"repobilityId": "ed90d46b6ce93b16", "scanner": "scanner-primary", "fingerprint": "bb6791eb4d41441f", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1062}}}]}, {"ruleId": "scanner-23743522019fc909", "level": "error", "message": {"text": "FastAPI PUT `update_llamaindex_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1120"}, "properties": {"repobilityId": "18a40bcdc6637dd2", "scanner": "scanner-primary", "fingerprint": "23743522019fc909", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1120}}}]}, {"ruleId": "scanner-c0020dad9fa57ffd", "level": "error", "message": {"text": "FastAPI PUT `update_graphrag_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1160"}, "properties": {"repobilityId": "d524a094c06c55b1", "scanner": "scanner-primary", "fingerprint": "c0020dad9fa57ffd", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1160}}}]}, {"ruleId": "scanner-2e062f061d7eeca3", "level": "error", "message": {"text": "FastAPI PUT `update_lightrag_pipeline_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1194"}, "properties": {"repobilityId": "13d9a69fee421805", "scanner": "scanner-primary", "fingerprint": "2e062f061d7eeca3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1194}}}]}, {"ruleId": "scanner-26f108f2cfa00164", "level": "error", "message": {"text": "FastAPI PUT `set_rag_active_model` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1293"}, "properties": {"repobilityId": "3472fe81d25583a0", "scanner": "scanner-primary", "fingerprint": "26f108f2cfa00164", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1293}}}]}, {"ruleId": "scanner-3be8c6ea28e248ce", "level": "error", "message": {"text": "FastAPI PUT `update_kb_config` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1374"}, "properties": {"repobilityId": "e764076172b1da18", "scanner": "scanner-primary", "fingerprint": "3be8c6ea28e248ce", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1374}}}]}, {"ruleId": "scanner-6b794ccd9c9354a8", "level": "error", "message": {"text": "FastAPI POST `sync_configs_from_metadata` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1424"}, "properties": {"repobilityId": "b235a447d9a23946", "scanner": "scanner-primary", "fingerprint": "6b794ccd9c9354a8", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1424}}}]}, {"ruleId": "scanner-d5a4f5e0421e66d9", "level": "error", "message": {"text": "FastAPI PUT `set_default_kb` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1450"}, "properties": {"repobilityId": "248b6d6abb93f256", "scanner": "scanner-primary", "fingerprint": "d5a4f5e0421e66d9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1450}}}]}, {"ruleId": "scanner-e43133e23040506a", "level": "error", "message": {"text": "FastAPI POST `connect_obsidian_vault` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1474"}, "properties": {"repobilityId": "ee21ebd353b33c45", "scanner": "scanner-primary", "fingerprint": "e43133e23040506a", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1474}}}]}, {"ruleId": "scanner-3f048647c84ba874", "level": "error", "message": {"text": "FastAPI POST `probe_linked_folder_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1512"}, "properties": {"repobilityId": "b4dff7a7f494a14f", "scanner": "scanner-primary", "fingerprint": "3f048647c84ba874", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1512}}}]}, {"ruleId": "scanner-30e42421ad4368da", "level": "error", "message": {"text": "FastAPI POST `connect_linked_folder_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1531"}, "properties": {"repobilityId": "9ff283bc6f7f79b4", "scanner": "scanner-primary", "fingerprint": "30e42421ad4368da", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1531}}}]}, {"ruleId": "scanner-7763595e1a1292d3", "level": "error", "message": {"text": "FastAPI POST `probe_lightrag_server_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1594"}, "properties": {"repobilityId": "8da6a0eafd704b04", "scanner": "scanner-primary", "fingerprint": "7763595e1a1292d3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1594}}}]}, {"ruleId": "scanner-e6a40ec259ae238d", "level": "error", "message": {"text": "FastAPI POST `connect_lightrag_server_route` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1610"}, "properties": {"repobilityId": "ae51bd1dbdd8606a", "scanner": "scanner-primary", "fingerprint": "e6a40ec259ae238d", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1610}}}]}, {"ruleId": "scanner-ca9a4db6d1ed6630", "level": "error", "message": {"text": "FastAPI POST `create_kb_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1923"}, "properties": {"repobilityId": "091726bb38a42451", "scanner": "scanner-primary", "fingerprint": "ca9a4db6d1ed6630", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1923}}}]}, {"ruleId": "scanner-1e9aa37fa7f9fb6e", "level": "error", "message": {"text": "FastAPI POST `move_kb_file` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:1937"}, "properties": {"repobilityId": "3a7380a2d0f33965", "scanner": "scanner-primary", "fingerprint": "1e9aa37fa7f9fb6e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 1937}}}]}, {"ruleId": "scanner-c775ed4d407fc677", "level": "error", "message": {"text": "FastAPI DELETE `delete_kb_file` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2009"}, "properties": {"repobilityId": "ce79e6742133ca8b", "scanner": "scanner-primary", "fingerprint": "c775ed4d407fc677", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2009}}}]}, {"ruleId": "scanner-7e74c092e13076b5", "level": "error", "message": {"text": "FastAPI DELETE `delete_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2033"}, "properties": {"repobilityId": "472596a479f0976c", "scanner": "scanner-primary", "fingerprint": "7e74c092e13076b5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2033}}}]}, {"ruleId": "scanner-89852abedfc657e3", "level": "error", "message": {"text": "FastAPI POST `upload_files` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2061"}, "properties": {"repobilityId": "6449a5efbfd41b28", "scanner": "scanner-primary", "fingerprint": "89852abedfc657e3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2061}}}]}, {"ruleId": "scanner-0e1d8772e0f495d9", "level": "error", "message": {"text": "FastAPI POST `create_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2140"}, "properties": {"repobilityId": "1943dfa36d438223", "scanner": "scanner-primary", "fingerprint": "0e1d8772e0f495d9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2140}}}]}, {"ruleId": "scanner-d826c0e04f49510e", "level": "error", "message": {"text": "FastAPI POST `reindex_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2379"}, "properties": {"repobilityId": "49b8e8f65a7c50ed", "scanner": "scanner-primary", "fingerprint": "d826c0e04f49510e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2379}}}]}, {"ruleId": "scanner-1691b8f630d8d0d0", "level": "error", "message": {"text": "FastAPI POST `retry_knowledge_base` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2465"}, "properties": {"repobilityId": "e3c80bef9bd669e8", "scanner": "scanner-primary", "fingerprint": "1691b8f630d8d0d0", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2465}}}]}, {"ruleId": "scanner-08d0bb0ff261ac4e", "level": "error", "message": {"text": "FastAPI POST `clear_progress` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2511"}, "properties": {"repobilityId": "5797831845529573", "scanner": "scanner-primary", "fingerprint": "08d0bb0ff261ac4e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2511}}}]}, {"ruleId": "scanner-69978076ef4ed629", "level": "error", "message": {"text": "FastAPI POST `link_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2671"}, "properties": {"repobilityId": "b4ee0b4a42bb4f61", "scanner": "scanner-primary", "fingerprint": "69978076ef4ed629", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2671}}}]}, {"ruleId": "scanner-7d7738e13e5a597c", "level": "error", "message": {"text": "FastAPI DELETE `unlink_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2717"}, "properties": {"repobilityId": "a7b632b9a12481d9", "scanner": "scanner-primary", "fingerprint": "7d7738e13e5a597c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2717}}}]}, {"ruleId": "scanner-c254a02ebbe3f045", "level": "error", "message": {"text": "FastAPI POST `sync_folder` without auth dependency \u2014 deeptutor/api/routers/knowledge.py:2735"}, "properties": {"repobilityId": "cf403106bf7a1640", "scanner": "scanner-primary", "fingerprint": "c254a02ebbe3f045", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/knowledge.py"}, "region": {"startLine": 2735}}}]}, {"ruleId": "scanner-8b68bbb0d79882ad", "level": "error", "message": {"text": "FastAPI POST `execute_tool` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:114"}, "properties": {"repobilityId": "b891652a71652792", "scanner": "scanner-primary", "fingerprint": "8b68bbb0d79882ad", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/plugins_api.py"}, "region": {"startLine": 114}}}]}, {"ruleId": "scanner-28a0c0a0989f6342", "level": "error", "message": {"text": "FastAPI POST `execute_tool_stream` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:281"}, "properties": {"repobilityId": "d12121afa8d8ad75", "scanner": "scanner-primary", "fingerprint": "28a0c0a0989f6342", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/plugins_api.py"}, "region": {"startLine": 281}}}]}, {"ruleId": "scanner-8521f88f39e3a5ed", "level": "error", "message": {"text": "FastAPI POST `execute_capability_stream` without auth dependency \u2014 deeptutor/api/routers/plugins_api.py:422"}, "properties": {"repobilityId": "975211e4923e5830", "scanner": "scanner-primary", "fingerprint": "8521f88f39e3a5ed", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/plugins_api.py"}, "region": {"startLine": 422}}}]}, {"ruleId": "scanner-844cdc2e07724656", "level": "error", "message": {"text": "FastAPI POST `upsert_single_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:182"}, "properties": {"repobilityId": "245cfd95aeeeb98f", "scanner": "scanner-primary", "fingerprint": "844cdc2e07724656", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 182}}}]}, {"ruleId": "scanner-bc96943b3c068311", "level": "error", "message": {"text": "FastAPI PATCH `update_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:257"}, "properties": {"repobilityId": "e4eff8e13051a26d", "scanner": "scanner-primary", "fingerprint": "bc96943b3c068311", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 257}}}]}, {"ruleId": "scanner-ac3a03bafa0ed09d", "level": "error", "message": {"text": "FastAPI DELETE `delete_entry` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:269"}, "properties": {"repobilityId": "df86635f4c80dc27", "scanner": "scanner-primary", "fingerprint": "ac3a03bafa0ed09d", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 269}}}]}, {"ruleId": "scanner-ad5ed4b792a0e284", "level": "error", "message": {"text": "FastAPI POST `add_entry_to_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:281"}, "properties": {"repobilityId": "79bcf5098c27d417", "scanner": "scanner-primary", "fingerprint": "ad5ed4b792a0e284", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 281}}}]}, {"ruleId": "scanner-63c836afc7d5dc0f", "level": "error", "message": {"text": "FastAPI DELETE `remove_entry_from_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:293"}, "properties": {"repobilityId": "79978dac1f022840", "scanner": "scanner-primary", "fingerprint": "63c836afc7d5dc0f", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 293}}}]}, {"ruleId": "scanner-55fe1b24bfe1b927", "level": "error", "message": {"text": "FastAPI POST `create_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:311"}, "properties": {"repobilityId": "9b7df8102335a7fd", "scanner": "scanner-primary", "fingerprint": "55fe1b24bfe1b927", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 311}}}]}, {"ruleId": "scanner-d4c4868cf75769a5", "level": "error", "message": {"text": "FastAPI PATCH `rename_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:320"}, "properties": {"repobilityId": "a02fe2c89dce685a", "scanner": "scanner-primary", "fingerprint": "d4c4868cf75769a5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 320}}}]}, {"ruleId": "scanner-6dc360ec17da581c", "level": "error", "message": {"text": "FastAPI DELETE `delete_category` without auth dependency \u2014 deeptutor/api/routers/question_notebook.py:329"}, "properties": {"repobilityId": "e0e7a0ee1f341295", "scanner": "scanner-primary", "fingerprint": "6dc360ec17da581c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/question_notebook.py"}, "region": {"startLine": 329}}}]}, {"ruleId": "scanner-1863777f892b69b6", "level": "error", "message": {"text": "FastAPI POST `text_to_speech` without auth dependency \u2014 deeptutor/api/routers/voice.py:78"}, "properties": {"repobilityId": "ea691ce11d2b87ab", "scanner": "scanner-primary", "fingerprint": "1863777f892b69b6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/voice.py"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-d1a38e21efdbe153", "level": "error", "message": {"text": "FastAPI POST `speech_to_text` without auth dependency \u2014 deeptutor/api/routers/voice.py:104"}, "properties": {"repobilityId": "a715e585d5c780c4", "scanner": "scanner-primary", "fingerprint": "d1a38e21efdbe153", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/voice.py"}, "region": {"startLine": 104}}}]}, {"ruleId": "scanner-5f37ea5ae255c2f3", "level": "error", "message": {"text": "FastAPI PUT `put_capabilities_settings` without auth dependency \u2014 deeptutor/api/routers/capabilities_settings.py:34"}, "properties": {"repobilityId": "bfa46bbd858128a2", "scanner": "scanner-primary", "fingerprint": "5f37ea5ae255c2f3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/capabilities_settings.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-44aa2f5e93b5eb01", "level": "error", "message": {"text": "FastAPI PUT `put_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:151"}, "properties": {"repobilityId": "9b95000e44afdc24", "scanner": "scanner-primary", "fingerprint": "44aa2f5e93b5eb01", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 151}}}]}, {"ruleId": "scanner-c2d789f9b745e227", "level": "error", "message": {"text": "FastAPI DELETE `delete_entry` without auth dependency \u2014 deeptutor/api/routers/memory.py:159"}, "properties": {"repobilityId": "04aba53b04f7c3b6", "scanner": "scanner-primary", "fingerprint": "c2d789f9b745e227", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 159}}}]}, {"ruleId": "scanner-60f0387efd897161", "level": "error", "message": {"text": "FastAPI POST `reset_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:169"}, "properties": {"repobilityId": "b44aaae2182b25f3", "scanner": "scanner-primary", "fingerprint": "60f0387efd897161", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 169}}}]}, {"ruleId": "scanner-264ddc7819bcb679", "level": "error", "message": {"text": "FastAPI POST `start_run` without auth dependency \u2014 deeptutor/api/routers/memory.py:308"}, "properties": {"repobilityId": "ecec46fb0ee24599", "scanner": "scanner-primary", "fingerprint": "264ddc7819bcb679", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 308}}}]}, {"ruleId": "scanner-870607768e0a9c23", "level": "error", "message": {"text": "FastAPI POST `cancel_run` without auth dependency \u2014 deeptutor/api/routers/memory.py:363"}, "properties": {"repobilityId": "fade865d03137062", "scanner": "scanner-primary", "fingerprint": "870607768e0a9c23", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 363}}}]}, {"ruleId": "scanner-b3ab7fc622593214", "level": "error", "message": {"text": "FastAPI POST `undo_run_edit` without auth dependency \u2014 deeptutor/api/routers/memory.py:373"}, "properties": {"repobilityId": "8b4fc0a81c9ba7f6", "scanner": "scanner-primary", "fingerprint": "b3ab7fc622593214", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 373}}}]}, {"ruleId": "scanner-827cdd8b3c5694bd", "level": "error", "message": {"text": "FastAPI POST `update_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:529"}, "properties": {"repobilityId": "4709d87a983f5bdf", "scanner": "scanner-primary", "fingerprint": "827cdd8b3c5694bd", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 529}}}]}, {"ruleId": "scanner-aaef327deb4e71b5", "level": "error", "message": {"text": "FastAPI POST `audit_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:544"}, "properties": {"repobilityId": "93a5eeb83b4e08d1", "scanner": "scanner-primary", "fingerprint": "aaef327deb4e71b5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 544}}}]}, {"ruleId": "scanner-03147c680f4a15ec", "level": "error", "message": {"text": "FastAPI POST `dedup_doc` without auth dependency \u2014 deeptutor/api/routers/memory.py:559"}, "properties": {"repobilityId": "704c354aa5ec6d90", "scanner": "scanner-primary", "fingerprint": "03147c680f4a15ec", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 559}}}]}, {"ruleId": "scanner-0196713758d57ebf", "level": "error", "message": {"text": "FastAPI PUT `put_memory_settings` without auth dependency \u2014 deeptutor/api/routers/memory.py:622"}, "properties": {"repobilityId": "05b17224a6efe08b", "scanner": "scanner-primary", "fingerprint": "0196713758d57ebf", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 622}}}]}, {"ruleId": "scanner-94980d0fab5d2aba", "level": "error", "message": {"text": "FastAPI POST `apply_doc_ops` without auth dependency \u2014 deeptutor/api/routers/memory.py:649"}, "properties": {"repobilityId": "2e729444d45dc871", "scanner": "scanner-primary", "fingerprint": "94980d0fab5d2aba", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 649}}}]}, {"ruleId": "scanner-0137f360b92ceb8d", "level": "error", "message": {"text": "FastAPI DELETE `clear_trace` without auth dependency \u2014 deeptutor/api/routers/memory.py:695"}, "properties": {"repobilityId": "4d21581438c9cc43", "scanner": "scanner-primary", "fingerprint": "0137f360b92ceb8d", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 695}}}]}, {"ruleId": "scanner-ef3e170fe0325315", "level": "error", "message": {"text": "FastAPI DELETE `clear_trace_day` without auth dependency \u2014 deeptutor/api/routers/memory.py:708"}, "properties": {"repobilityId": "97e98bfb6e1acf1e", "scanner": "scanner-primary", "fingerprint": "ef3e170fe0325315", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 708}}}]}, {"ruleId": "scanner-74efd573575e82e9", "level": "error", "message": {"text": "FastAPI POST `refresh_snapshot` without auth dependency \u2014 deeptutor/api/routers/memory.py:750"}, "properties": {"repobilityId": "c6495f768cae9a98", "scanner": "scanner-primary", "fingerprint": "74efd573575e82e9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 750}}}]}, {"ruleId": "scanner-d6516cff29bfbf58", "level": "error", "message": {"text": "FastAPI DELETE `clear_snapshot_changes` without auth dependency \u2014 deeptutor/api/routers/memory.py:779"}, "properties": {"repobilityId": "7a591e5b44ce4ce6", "scanner": "scanner-primary", "fingerprint": "d6516cff29bfbf58", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/memory.py"}, "region": {"startLine": 779}}}]}, {"ruleId": "scanner-043ee9d6378baabb", "level": "error", "message": {"text": "FastAPI POST `create_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:170"}, "properties": {"repobilityId": "556145677e8ec4fa", "scanner": "scanner-primary", "fingerprint": "043ee9d6378baabb", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 170}}}]}, {"ruleId": "scanner-b3dac2289e4a6869", "level": "error", "message": {"text": "FastAPI PUT `update_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:215"}, "properties": {"repobilityId": "b99952d6bf496e18", "scanner": "scanner-primary", "fingerprint": "b3dac2289e4a6869", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 215}}}]}, {"ruleId": "scanner-532fc04a52298a06", "level": "error", "message": {"text": "FastAPI DELETE `delete_notebook` without auth dependency \u2014 deeptutor/api/routers/notebook.py:244"}, "properties": {"repobilityId": "d22019ee7a412d0a", "scanner": "scanner-primary", "fingerprint": "532fc04a52298a06", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 244}}}]}, {"ruleId": "scanner-285f4dd4169fcec2", "level": "error", "message": {"text": "FastAPI POST `add_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:266"}, "properties": {"repobilityId": "9cf4ff03871f3e72", "scanner": "scanner-primary", "fingerprint": "285f4dd4169fcec2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 266}}}]}, {"ruleId": "scanner-bb45a728c45a11f8", "level": "error", "message": {"text": "FastAPI POST `add_record_with_summary` without auth dependency \u2014 deeptutor/api/routers/notebook.py:299"}, "properties": {"repobilityId": "4fd97fc48b7c7597", "scanner": "scanner-primary", "fingerprint": "bb45a728c45a11f8", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 299}}}]}, {"ruleId": "scanner-157739536497df96", "level": "error", "message": {"text": "FastAPI DELETE `remove_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:309"}, "properties": {"repobilityId": "9b458ae6d6cdae1c", "scanner": "scanner-primary", "fingerprint": "157739536497df96", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 309}}}]}, {"ruleId": "scanner-b4d71e110b673683", "level": "error", "message": {"text": "FastAPI PUT `update_record` without auth dependency \u2014 deeptutor/api/routers/notebook.py:332"}, "properties": {"repobilityId": "b687e41cf1d246be", "scanner": "scanner-primary", "fingerprint": "b4d71e110b673683", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/notebook.py"}, "region": {"startLine": 332}}}]}, {"ruleId": "scanner-efd9639bd7ec8830", "level": "error", "message": {"text": "FastAPI POST `init_modules` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:134"}, "properties": {"repobilityId": "aead01ea32999cc7", "scanner": "scanner-primary", "fingerprint": "efd9639bd7ec8830", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/mastery_path.py"}, "region": {"startLine": 134}}}]}, {"ruleId": "scanner-cb45fa0b82495b42", "level": "error", "message": {"text": "FastAPI POST `import_from_book` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:149"}, "properties": {"repobilityId": "999917498a9e34b9", "scanner": "scanner-primary", "fingerprint": "cb45fa0b82495b42", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/mastery_path.py"}, "region": {"startLine": 149}}}]}, {"ruleId": "scanner-ef677a88e3b98dcd", "level": "error", "message": {"text": "FastAPI DELETE `delete_progress` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:183"}, "properties": {"repobilityId": "449fbda08c9de591", "scanner": "scanner-primary", "fingerprint": "ef677a88e3b98dcd", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/mastery_path.py"}, "region": {"startLine": 183}}}]}, {"ruleId": "scanner-d87593ef147a5ec9", "level": "error", "message": {"text": "FastAPI POST `redo_progress` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:193"}, "properties": {"repobilityId": "40e1230ab72a5231", "scanner": "scanner-primary", "fingerprint": "d87593ef147a5ec9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/mastery_path.py"}, "region": {"startLine": 193}}}]}, {"ruleId": "scanner-18ad691f8d13a40e", "level": "error", "message": {"text": "FastAPI POST `generate_from_notebook` without auth dependency \u2014 deeptutor/api/routers/mastery_path.py:231"}, "properties": {"repobilityId": "f2e91fff0057a4c8", "scanner": "scanner-primary", "fingerprint": "18ad691f8d13a40e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/mastery_path.py"}, "region": {"startLine": 231}}}]}, {"ruleId": "scanner-ec6d859a92db72a6", "level": "error", "message": {"text": "FastAPI POST `create_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:330"}, "properties": {"repobilityId": "b6a25960bb5aa897", "scanner": "scanner-primary", "fingerprint": "ec6d859a92db72a6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 330}}}]}, {"ruleId": "scanner-67839f80d54d2fc7", "level": "error", "message": {"text": "FastAPI PUT `update_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:350"}, "properties": {"repobilityId": "ca4273db51c5e581", "scanner": "scanner-primary", "fingerprint": "67839f80d54d2fc7", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 350}}}]}, {"ruleId": "scanner-8d40481314068ee3", "level": "error", "message": {"text": "FastAPI DELETE `delete_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:358"}, "properties": {"repobilityId": "ed8a489d03a95a8c", "scanner": "scanner-primary", "fingerprint": "8d40481314068ee3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 358}}}]}, {"ruleId": "scanner-3b9b396feb6f04f9", "level": "error", "message": {"text": "FastAPI POST `create_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:445"}, "properties": {"repobilityId": "01f820b7fa0585e2", "scanner": "scanner-primary", "fingerprint": "3b9b396feb6f04f9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 445}}}]}, {"ruleId": "scanner-19d0cb1c7e1fa703", "level": "error", "message": {"text": "FastAPI PATCH `update_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:587"}, "properties": {"repobilityId": "d877e4ad5cce412e", "scanner": "scanner-primary", "fingerprint": "19d0cb1c7e1fa703", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 587}}}]}, {"ruleId": "scanner-bfd2fe898e7571fc", "level": "error", "message": {"text": "FastAPI POST `start_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:621"}, "properties": {"repobilityId": "5f5df0a8e6c69e9a", "scanner": "scanner-primary", "fingerprint": "bfd2fe898e7571fc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 621}}}]}, {"ruleId": "scanner-30a75ced869f9a88", "level": "error", "message": {"text": "FastAPI POST `stop_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:631"}, "properties": {"repobilityId": "da247d24becee6bf", "scanner": "scanner-primary", "fingerprint": "30a75ced869f9a88", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 631}}}]}, {"ruleId": "scanner-3a5579fdd2207bcb", "level": "error", "message": {"text": "FastAPI DELETE `destroy_partner` without auth dependency \u2014 deeptutor/api/routers/partners.py:639"}, "properties": {"repobilityId": "23c02f58c6e6b877", "scanner": "scanner-primary", "fingerprint": "3a5579fdd2207bcb", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 639}}}]}, {"ruleId": "scanner-afe8695ad3f00fc8", "level": "error", "message": {"text": "FastAPI POST `reload_partner_channels` without auth dependency \u2014 deeptutor/api/routers/partners.py:647"}, "properties": {"repobilityId": "76c24c3fa67ed0eb", "scanner": "scanner-primary", "fingerprint": "afe8695ad3f00fc8", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 647}}}]}, {"ruleId": "scanner-aff66e432eca1dcc", "level": "error", "message": {"text": "FastAPI PUT `put_partner_soul` without auth dependency \u2014 deeptutor/api/routers/partners.py:674"}, "properties": {"repobilityId": "d44a59ae15b8522d", "scanner": "scanner-primary", "fingerprint": "aff66e432eca1dcc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 674}}}]}, {"ruleId": "scanner-47313f7701f82375", "level": "error", "message": {"text": "FastAPI POST `add_partner_assets` without auth dependency \u2014 deeptutor/api/routers/partners.py:694"}, "properties": {"repobilityId": "734364ae6556b295", "scanner": "scanner-primary", "fingerprint": "47313f7701f82375", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 694}}}]}, {"ruleId": "scanner-315fb9dc0b5b01f2", "level": "error", "message": {"text": "FastAPI DELETE `delete_partner_asset` without auth dependency \u2014 deeptutor/api/routers/partners.py:708"}, "properties": {"repobilityId": "fc77f4ffdbac7d63", "scanner": "scanner-primary", "fingerprint": "315fb9dc0b5b01f2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 708}}}]}, {"ruleId": "scanner-7d5920ffe21c6f2c", "level": "error", "message": {"text": "FastAPI POST `archive_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:749"}, "properties": {"repobilityId": "6d21c9fad5579cf8", "scanner": "scanner-primary", "fingerprint": "7d5920ffe21c6f2c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 749}}}]}, {"ruleId": "scanner-9d7968059e219d26", "level": "error", "message": {"text": "FastAPI POST `resume_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:759"}, "properties": {"repobilityId": "94e8bfc63128cd50", "scanner": "scanner-primary", "fingerprint": "9d7968059e219d26", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 759}}}]}, {"ruleId": "scanner-f03ea859040c2718", "level": "error", "message": {"text": "FastAPI POST `delete_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:771"}, "properties": {"repobilityId": "8b7e4ce739b76e29", "scanner": "scanner-primary", "fingerprint": "f03ea859040c2718", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 771}}}]}, {"ruleId": "scanner-079e8c8d817678c9", "level": "error", "message": {"text": "FastAPI POST `branch_partner_session` without auth dependency \u2014 deeptutor/api/routers/partners.py:782"}, "properties": {"repobilityId": "b1f9d72a0477829e", "scanner": "scanner-primary", "fingerprint": "079e8c8d817678c9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 782}}}]}, {"ruleId": "scanner-124edb3510c0ccd3", "level": "error", "message": {"text": "FastAPI POST `partner_chat_http` without auth dependency \u2014 deeptutor/api/routers/partners.py:890"}, "properties": {"repobilityId": "3d90d409f0ab34a3", "scanner": "scanner-primary", "fingerprint": "124edb3510c0ccd3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 890}}}]}, {"ruleId": "scanner-2ed7dffaed2b1f5b", "level": "error", "message": {"text": "FastAPI POST `partner_chat_http_stream` without auth dependency \u2014 deeptutor/api/routers/partners.py:981"}, "properties": {"repobilityId": "28e89df6cead5a62", "scanner": "scanner-primary", "fingerprint": "2ed7dffaed2b1f5b", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/partners.py"}, "region": {"startLine": 981}}}]}, {"ruleId": "scanner-f8fe2b08d500d2dc", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 deeptutor/api/routers/chat.py:47"}, "properties": {"repobilityId": "021a07859b9b6aa0", "scanner": "scanner-primary", "fingerprint": "f8fe2b08d500d2dc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/chat.py"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-bdcfa622782412cc", "level": "error", "message": {"text": "FastAPI PUT `update_network_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:523"}, "properties": {"repobilityId": "1cfd15073f3864d9", "scanner": "scanner-primary", "fingerprint": "bdcfa622782412cc", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 523}}}]}, {"ruleId": "scanner-184e4a6d929f040b", "level": "error", "message": {"text": "FastAPI PUT `update_chat_attachment_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:579"}, "properties": {"repobilityId": "89761f98aa91c720", "scanner": "scanner-primary", "fingerprint": "184e4a6d929f040b", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 579}}}]}, {"ruleId": "scanner-44c43524f530fce6", "level": "error", "message": {"text": "FastAPI PUT `update_mineru_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:678"}, "properties": {"repobilityId": "88e94b255ad2ed96", "scanner": "scanner-primary", "fingerprint": "44c43524f530fce6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 678}}}]}, {"ruleId": "scanner-716168a676e12b53", "level": "error", "message": {"text": "FastAPI PUT `update_document_parsing_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:712"}, "properties": {"repobilityId": "4a6a5dda17b57982", "scanner": "scanner-primary", "fingerprint": "716168a676e12b53", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 712}}}]}, {"ruleId": "scanner-142d89614de3df9b", "level": "error", "message": {"text": "FastAPI POST `test_document_parsing` without auth dependency \u2014 deeptutor/api/routers/settings.py:733"}, "properties": {"repobilityId": "eb97799b9b0a452e", "scanner": "scanner-primary", "fingerprint": "142d89614de3df9b", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 733}}}]}, {"ruleId": "scanner-5fefc7c52fde27f4", "level": "error", "message": {"text": "FastAPI POST `start_document_parsing_install` without auth dependency \u2014 deeptutor/api/routers/settings.py:760"}, "properties": {"repobilityId": "640caa513846f2f7", "scanner": "scanner-primary", "fingerprint": "5fefc7c52fde27f4", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 760}}}]}, {"ruleId": "scanner-3abc376be52b7d3a", "level": "error", "message": {"text": "FastAPI POST `start_document_parsing_model_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:780"}, "properties": {"repobilityId": "bacda098e4292678", "scanner": "scanner-primary", "fingerprint": "3abc376be52b7d3a", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 780}}}]}, {"ruleId": "scanner-8c137a1893d8ee48", "level": "error", "message": {"text": "FastAPI POST `cancel_document_parsing_job` without auth dependency \u2014 deeptutor/api/routers/settings.py:818"}, "properties": {"repobilityId": "88dccceeca6c4fda", "scanner": "scanner-primary", "fingerprint": "8c137a1893d8ee48", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 818}}}]}, {"ruleId": "scanner-23b3209302bee0d4", "level": "error", "message": {"text": "FastAPI POST `start_mineru_models_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:826"}, "properties": {"repobilityId": "6f244196006e8037", "scanner": "scanner-primary", "fingerprint": "23b3209302bee0d4", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 826}}}]}, {"ruleId": "scanner-749899e743af8599", "level": "error", "message": {"text": "FastAPI POST `cancel_mineru_models_download` without auth dependency \u2014 deeptutor/api/routers/settings.py:870"}, "properties": {"repobilityId": "61a07fa476c93fdf", "scanner": "scanner-primary", "fingerprint": "749899e743af8599", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 870}}}]}, {"ruleId": "scanner-2d0497a846739ebf", "level": "error", "message": {"text": "FastAPI POST `test_mineru_connection` without auth dependency \u2014 deeptutor/api/routers/settings.py:878"}, "properties": {"repobilityId": "8a22d4b94b4a72a2", "scanner": "scanner-primary", "fingerprint": "2d0497a846739ebf", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 878}}}]}, {"ruleId": "scanner-eb54373c65d0a5af", "level": "error", "message": {"text": "FastAPI PUT `update_catalog` without auth dependency \u2014 deeptutor/api/routers/settings.py:955"}, "properties": {"repobilityId": "45b35beb21871ff2", "scanner": "scanner-primary", "fingerprint": "eb54373c65d0a5af", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 955}}}]}, {"ruleId": "scanner-a45a8f6129d55fd9", "level": "error", "message": {"text": "FastAPI POST `apply_catalog` without auth dependency \u2014 deeptutor/api/routers/settings.py:963"}, "properties": {"repobilityId": "aa321b82838a33fb", "scanner": "scanner-primary", "fingerprint": "a45a8f6129d55fd9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 963}}}]}, {"ruleId": "scanner-953fd991f16da925", "level": "error", "message": {"text": "FastAPI POST `fetch_models_from_provider` without auth dependency \u2014 deeptutor/api/routers/settings.py:976"}, "properties": {"repobilityId": "d4494b14c6e1d4e9", "scanner": "scanner-primary", "fingerprint": "953fd991f16da925", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 976}}}]}, {"ruleId": "scanner-ee5526272284b4b9", "level": "error", "message": {"text": "FastAPI PUT `update_theme` without auth dependency \u2014 deeptutor/api/routers/settings.py:1007"}, "properties": {"repobilityId": "03284be7e094caf8", "scanner": "scanner-primary", "fingerprint": "ee5526272284b4b9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1007}}}]}, {"ruleId": "scanner-b3acd60da01ee1d5", "level": "error", "message": {"text": "FastAPI PUT `update_language` without auth dependency \u2014 deeptutor/api/routers/settings.py:1015"}, "properties": {"repobilityId": "355d4e5b7f7b733b", "scanner": "scanner-primary", "fingerprint": "b3acd60da01ee1d5", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1015}}}]}, {"ruleId": "scanner-211ffacc995533ba", "level": "error", "message": {"text": "FastAPI PUT `update_voice_autoplay` without auth dependency \u2014 deeptutor/api/routers/settings.py:1023"}, "properties": {"repobilityId": "f3068201bc1dce03", "scanner": "scanner-primary", "fingerprint": "211ffacc995533ba", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1023}}}]}, {"ruleId": "scanner-6c15d8d81381175e", "level": "error", "message": {"text": "FastAPI PUT `update_chat_response_timeout` without auth dependency \u2014 deeptutor/api/routers/settings.py:1036"}, "properties": {"repobilityId": "3204fd3fa0317e81", "scanner": "scanner-primary", "fingerprint": "6c15d8d81381175e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1036}}}]}, {"ruleId": "scanner-6b7cfd9ad32dc08b", "level": "error", "message": {"text": "FastAPI PUT `update_ui_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:1050"}, "properties": {"repobilityId": "7a40c473d36dca0d", "scanner": "scanner-primary", "fingerprint": "6b7cfd9ad32dc08b", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1050}}}]}, {"ruleId": "scanner-626fcb55238945d0", "level": "error", "message": {"text": "FastAPI POST `reset_settings` without auth dependency \u2014 deeptutor/api/routers/settings.py:1065"}, "properties": {"repobilityId": "cd4ab3434e2033b7", "scanner": "scanner-primary", "fingerprint": "626fcb55238945d0", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1065}}}]}, {"ruleId": "scanner-9aa6fedf1e8cb157", "level": "error", "message": {"text": "FastAPI PUT `update_sidebar_description` without auth dependency \u2014 deeptutor/api/routers/settings.py:1094"}, "properties": {"repobilityId": "33302aa89a9e6a7a", "scanner": "scanner-primary", "fingerprint": "9aa6fedf1e8cb157", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1094}}}]}, {"ruleId": "scanner-6c0d19375456efe0", "level": "error", "message": {"text": "FastAPI PUT `update_sidebar_nav_order` without auth dependency \u2014 deeptutor/api/routers/settings.py:1102"}, "properties": {"repobilityId": "eef631d65de50dd8", "scanner": "scanner-primary", "fingerprint": "6c0d19375456efe0", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1102}}}]}, {"ruleId": "scanner-7275711f9a52a5f9", "level": "error", "message": {"text": "FastAPI PUT `update_enabled_tools` without auth dependency \u2014 deeptutor/api/routers/settings.py:1110"}, "properties": {"repobilityId": "343c58bec254e75e", "scanner": "scanner-primary", "fingerprint": "7275711f9a52a5f9", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1110}}}]}, {"ruleId": "scanner-989c3b2e0fad2997", "level": "error", "message": {"text": "FastAPI POST `start_service_test` without auth dependency \u2014 deeptutor/api/routers/settings.py:1119"}, "properties": {"repobilityId": "df8179cc22ef88ef", "scanner": "scanner-primary", "fingerprint": "989c3b2e0fad2997", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1119}}}]}, {"ruleId": "scanner-98f4f42b5c25824a", "level": "error", "message": {"text": "FastAPI POST `cancel_service_test` without auth dependency \u2014 deeptutor/api/routers/settings.py:1151"}, "properties": {"repobilityId": "a849a8f8a61aaaa7", "scanner": "scanner-primary", "fingerprint": "98f4f42b5c25824a", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1151}}}]}, {"ruleId": "scanner-e8795302e83c5419", "level": "error", "message": {"text": "FastAPI POST `complete_tour` without auth dependency \u2014 deeptutor/api/routers/settings.py:1180"}, "properties": {"repobilityId": "2bf1d3e1b7b3e75d", "scanner": "scanner-primary", "fingerprint": "e8795302e83c5419", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1180}}}]}, {"ruleId": "scanner-f2c28c3f15247d8f", "level": "error", "message": {"text": "FastAPI POST `reopen_tour` without auth dependency \u2014 deeptutor/api/routers/settings.py:1212"}, "properties": {"repobilityId": "0c33f0ccf35274fb", "scanner": "scanner-primary", "fingerprint": "f2c28c3f15247d8f", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/settings.py"}, "region": {"startLine": 1212}}}]}, {"ruleId": "scanner-2f2758d995ff5c44", "level": "error", "message": {"text": "FastAPI POST `create_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:91"}, "properties": {"repobilityId": "59bf008d40df5009", "scanner": "scanner-primary", "fingerprint": "2f2758d995ff5c44", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/personas.py"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-1ef7f6b88c8f51e3", "level": "error", "message": {"text": "FastAPI PUT `update_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:110"}, "properties": {"repobilityId": "b6f083a7a2046a31", "scanner": "scanner-primary", "fingerprint": "1ef7f6b88c8f51e3", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/personas.py"}, "region": {"startLine": 110}}}]}, {"ruleId": "scanner-f8aec3f5c351ba1e", "level": "error", "message": {"text": "FastAPI DELETE `delete_persona` without auth dependency \u2014 deeptutor/api/routers/personas.py:129"}, "properties": {"repobilityId": "ac0f78dd5cc123ff", "scanner": "scanner-primary", "fingerprint": "f8aec3f5c351ba1e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/personas.py"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-f4291267ab551b7e", "level": "error", "message": {"text": "FastAPI POST `import_chat_history` without auth dependency \u2014 deeptutor/api/routers/imports.py:74"}, "properties": {"repobilityId": "175b94ec7c24af1d", "scanner": "scanner-primary", "fingerprint": "f4291267ab551b7e", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/imports.py"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-5ac02e3989aea9b6", "level": "error", "message": {"text": "FastAPI PATCH `rename_session` without auth dependency \u2014 deeptutor/api/routers/sessions.py:143"}, "properties": {"repobilityId": "f054caec5a957673", "scanner": "scanner-primary", "fingerprint": "5ac02e3989aea9b6", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/sessions.py"}, "region": {"startLine": 143}}}]}, {"ruleId": "scanner-d556ed33844f6412", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 deeptutor/api/routers/sessions.py:153"}, "properties": {"repobilityId": "46ee62a6255c7105", "scanner": "scanner-primary", "fingerprint": "d556ed33844f6412", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/sessions.py"}, "region": {"startLine": 153}}}]}, {"ruleId": "scanner-4e7054d258481b5f", "level": "error", "message": {"text": "FastAPI PUT `update_branch_selection` without auth dependency \u2014 deeptutor/api/routers/sessions.py:166"}, "properties": {"repobilityId": "b694593f19da24da", "scanner": "scanner-primary", "fingerprint": "4e7054d258481b5f", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/sessions.py"}, "region": {"startLine": 166}}}]}, {"ruleId": "scanner-f4c8353ffc2e2dca", "level": "error", "message": {"text": "FastAPI DELETE `delete_turn_by_message` without auth dependency \u2014 deeptutor/api/routers/sessions.py:180"}, "properties": {"repobilityId": "dfc45f2bd849efab", "scanner": "scanner-primary", "fingerprint": "f4c8353ffc2e2dca", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/sessions.py"}, "region": {"startLine": 180}}}]}, {"ruleId": "scanner-98e566273ee36cd2", "level": "error", "message": {"text": "FastAPI POST `record_quiz_results` without auth dependency \u2014 deeptutor/api/routers/sessions.py:199"}, "properties": {"repobilityId": "6170b5e0cd65339b", "scanner": "scanner-primary", "fingerprint": "98e566273ee36cd2", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/sessions.py"}, "region": {"startLine": 199}}}]}, {"ruleId": "scanner-109ea23cf85b145c", "level": "error", "message": {"text": "FastAPI POST `test_llm_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:148"}, "properties": {"repobilityId": "7112628478a94900", "scanner": "scanner-primary", "fingerprint": "109ea23cf85b145c", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/system.py"}, "region": {"startLine": 148}}}]}, {"ruleId": "scanner-c8285ad78ab3ddc4", "level": "error", "message": {"text": "FastAPI POST `test_embeddings_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:216"}, "properties": {"repobilityId": "6ab023bda323deba", "scanner": "scanner-primary", "fingerprint": "c8285ad78ab3ddc4", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/system.py"}, "region": {"startLine": 216}}}]}, {"ruleId": "scanner-95c9329e96a75a18", "level": "error", "message": {"text": "FastAPI POST `test_search_connection` without auth dependency \u2014 deeptutor/api/routers/system.py:273"}, "properties": {"repobilityId": "8bef348275e667c2", "scanner": "scanner-primary", "fingerprint": "95c9329e96a75a18", "layer": "security", "severity": "high", "confidence": 0.75, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "deeptutor/api/routers/system.py"}, "region": {"startLine": 273}}}]}, {"ruleId": "scanner-4d94ccba38a24fb3", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-6m6c-36f7-fhxh"}, "properties": {"repobilityId": "c2432a300de057ef", "scanner": "scanner-primary", "fingerprint": "4d94ccba38a24fb3", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6m6c-36f7-fhxh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b6695e7bb5b1f2f9", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-87f9-hvmw-gh4p"}, "properties": {"repobilityId": "e1b3aa347542de5e", "scanner": "scanner-primary", "fingerprint": "b6695e7bb5b1f2f9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-87f9-hvmw-gh4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7405a856a9e34e4", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-ghcm-xqfw-q4vr"}, "properties": {"repobilityId": "225d6303f90867e6", "scanner": "scanner-primary", "fingerprint": "c7405a856a9e34e4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ghcm-xqfw-q4vr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-741ab58ddebd06a0", "level": "warning", "message": {"text": "Vulnerable dependency mermaid 11.14.0: GHSA-xcj9-5m2h-648r"}, "properties": {"repobilityId": "9e863977192fcd66", "scanner": "scanner-primary", "fingerprint": "741ab58ddebd06a0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-xcj9-5m2h-648r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-43221fdfcd8c3db1", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": "5b394f3a7826e1d3", "scanner": "scanner-primary", "fingerprint": "43221fdfcd8c3db1", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-267c-6grr-h53f"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-25a996e40d29b82c", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": "f114dfb2323ce9d3", "scanner": "scanner-primary", "fingerprint": "25a996e40d29b82c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-26hh-7cqf-hhc6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-664bc51897707a0e", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": "bf85581008018e00", "scanner": "scanner-primary", "fingerprint": "664bc51897707a0e", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-36qx-fr4f-26g5"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-540cf51e05e06206", "level": "note", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": "d504c25d9c1e5df2", "scanner": "scanner-primary", "fingerprint": "540cf51e05e06206", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3g8h-86w9-wvmq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81546a7fa18a2b56", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-4633-3j49-mh5q"}, "properties": {"repobilityId": "558d999668b688f7", "scanner": "scanner-primary", "fingerprint": "81546a7fa18a2b56", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4633-3j49-mh5q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2057301faa826bfc", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": "da280ce710b786c6", "scanner": "scanner-primary", "fingerprint": "2057301faa826bfc", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-492v-c6pp-mqqv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-003757ac01fe6a09", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-4c39-4ccg-62r3"}, "properties": {"repobilityId": "89d5d3767544bbc2", "scanner": "scanner-primary", "fingerprint": "003757ac01fe6a09", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-4c39-4ccg-62r3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c51a0519d0283e37", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-68g3-v927-f742"}, "properties": {"repobilityId": "73ab4426f84ce006", "scanner": "scanner-primary", "fingerprint": "c51a0519d0283e37", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-68g3-v927-f742"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9f6a8200185089d", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-6gpp-xcg3-4w24"}, "properties": {"repobilityId": "b4b31df83ed09c6f", "scanner": "scanner-primary", "fingerprint": "b9f6a8200185089d", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6gpp-xcg3-4w24"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-678bf574096d3dd3", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-89xv-2m56-2m9x"}, "properties": {"repobilityId": "4892afae0ad9a192", "scanner": "scanner-primary", "fingerprint": "678bf574096d3dd3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-89xv-2m56-2m9x"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1066f2256483362b", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": "c7ccc1d6c5158baf", "scanner": "scanner-primary", "fingerprint": "1066f2256483362b", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-8h8q-6873-q5fj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c134ed07b4d981a0", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-955p-x3mx-jcvp"}, "properties": {"repobilityId": "0dd0762822dadf49", "scanner": "scanner-primary", "fingerprint": "c134ed07b4d981a0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-955p-x3mx-jcvp"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c20a36b4601b4799", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": "f7f1284b5f4caa30", "scanner": "scanner-primary", "fingerprint": "c20a36b4601b4799", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c4j6-fc7j-m34r"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bea136ed86c29b59", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": "2b71f27538d3759a", "scanner": "scanner-primary", "fingerprint": "bea136ed86c29b59", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-ffhc-5mcf-pf4q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-efcf7b275cc569b9", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": "595537d5a7cae3e7", "scanner": "scanner-primary", "fingerprint": "efcf7b275cc569b9", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gx5p-jg67-6x7h"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-af56e5f4d0beb3a6", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": "90497a5a5f3029a1", "scanner": "scanner-primary", "fingerprint": "af56e5f4d0beb3a6", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-h64f-5h5j-jqjh"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0076add513a89bad", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-m99w-x7hq-7vfj"}, "properties": {"repobilityId": "dba02a7ad1f34ce9", "scanner": "scanner-primary", "fingerprint": "0076add513a89bad", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-m99w-x7hq-7vfj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c7ecbac08a8bed19", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": "d252baeb0811275b", "scanner": "scanner-primary", "fingerprint": "c7ecbac08a8bed19", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-mg66-mrh9-m8jx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05ca0e7959284077", "level": "error", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-p9j2-gv94-2wf4"}, "properties": {"repobilityId": "185337dfe5585eae", "scanner": "scanner-primary", "fingerprint": "05ca0e7959284077", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-p9j2-gv94-2wf4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-331fd92b435a94da", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-q8wf-6r8g-63ch"}, "properties": {"repobilityId": "492a5fe1a707e4c3", "scanner": "scanner-primary", "fingerprint": "331fd92b435a94da", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-q8wf-6r8g-63ch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cd8c649a51c1e18", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": "3612cf0962803c11", "scanner": "scanner-primary", "fingerprint": "7cd8c649a51c1e18", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vfv6-92ff-j949"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5794ed7ed8424a51", "level": "warning", "message": {"text": "Vulnerable dependency next 16.2.3: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": "b525c916d229e705", "scanner": "scanner-primary", "fingerprint": "5794ed7ed8424a51", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-wfc6-r584-vfw7"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-401d7ee6ff3add6c", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "86c312e6e8a1e925", "scanner": "scanner-primary", "fingerprint": "401d7ee6ff3add6c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-840edaacc0bd06d7", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.4.31: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "00a7666aebb4f6a3", "scanner": "scanner-primary", "fingerprint": "840edaacc0bd06d7", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-680067153df8469f", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-6g55-p6wh-862q"}, "properties": {"repobilityId": "b8944461c8644339", "scanner": "scanner-primary", "fingerprint": "680067153df8469f", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-6g55-p6wh-862q", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b1e1c9739855def", "level": "warning", "message": {"text": "Vulnerable dependency postcss 8.5.6: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": "6c83605d3aa8fcef", "scanner": "scanner-primary", "fingerprint": "6b1e1c9739855def", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-qx2v-qp2m-jg93", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1656f062b59c2b5", "level": "note", "message": {"text": "Vulnerable dependency @babel/core 7.28.5: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": "aed0a4d7b3d82bce", "scanner": "scanner-primary", "fingerprint": "b1656f062b59c2b5", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4x5r-pxfx-6jf8", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6d645899ba265c1", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "99627bea33b3e44f", "scanner": "scanner-primary", "fingerprint": "f6d645899ba265c1", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-da436a552d441f90", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "579bbb43dc72a04b", "scanner": "scanner-primary", "fingerprint": "da436a552d441f90", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a451de39b670107", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-76mc-f452-cxcm"}, "properties": {"repobilityId": "875f3c35d0cef567", "scanner": "scanner-primary", "fingerprint": "4a451de39b670107", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-76mc-f452-cxcm", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7be4da00dffe13ed", "level": "note", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-c2j3-45gr-mqc4"}, "properties": {"repobilityId": "15299ad5f146d9b2", "scanner": "scanner-primary", "fingerprint": "7be4da00dffe13ed", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-c2j3-45gr-mqc4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-95e09fe7afecf753", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-cmwh-pvxp-8882"}, "properties": {"repobilityId": "ec23a71e7510eb6a", "scanner": "scanner-primary", "fingerprint": "95e09fe7afecf753", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-cmwh-pvxp-8882", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c5ee34cb020e7fa", "level": "note", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-gvmj-g25r-r7wr"}, "properties": {"repobilityId": "e3ce61c931d66aab", "scanner": "scanner-primary", "fingerprint": "9c5ee34cb020e7fa", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gvmj-g25r-r7wr", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-459c78f8755406e9", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-hpcv-96wg-7vj8"}, "properties": {"repobilityId": "af54c2c1573bbdc1", "scanner": "scanner-primary", "fingerprint": "459c78f8755406e9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hpcv-96wg-7vj8", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f07f6e1cb9851f49", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-r47g-fvhr-h676"}, "properties": {"repobilityId": "41375b226e6d1e6d", "scanner": "scanner-primary", "fingerprint": "f07f6e1cb9851f49", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r47g-fvhr-h676", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-db82421595ecceaa", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-rp9w-3fw7-7cwq"}, "properties": {"repobilityId": "c1d0c0010147e1f9", "scanner": "scanner-primary", "fingerprint": "db82421595ecceaa", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-rp9w-3fw7-7cwq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5bdb0bee39833393", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-vxr8-fq34-vvx9"}, "properties": {"repobilityId": "6a57c89793b078d1", "scanner": "scanner-primary", "fingerprint": "5bdb0bee39833393", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-vxr8-fq34-vvx9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e245014afe71ccb1", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.0: GHSA-x4vx-rjvf-j5p4"}, "properties": {"repobilityId": "c1d913cf1c1ad6e6", "scanner": "scanner-primary", "fingerprint": "e245014afe71ccb1", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-x4vx-rjvf-j5p4", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4dcc6a16f3851a9a", "level": "error", "message": {"text": "Vulnerable dependency uuid 8.3.2: GHSA-w5hq-g745-h8pq"}, "properties": {"repobilityId": "90ae1f5d3eb9ff69", "scanner": "scanner-primary", "fingerprint": "4dcc6a16f3851a9a", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-w5hq-g745-h8pq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b62672b5c8588c6", "level": "note", "message": {"text": "Dependency i18next is a major version behind"}, "properties": {"repobilityId": "c9721e90806bf0ae", "scanner": "scanner-primary", "fingerprint": "1b62672b5c8588c6", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df0951a6a3ddcafc", "level": "note", "message": {"text": "Dependency lucide-react is a major version behind"}, "properties": {"repobilityId": "f8c94a3a49e97e7b", "scanner": "scanner-primary", "fingerprint": "df0951a6a3ddcafc", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae833d4a886bff6d", "level": "note", "message": {"text": "Dependency react-i18next is a major version behind"}, "properties": {"repobilityId": "be7cb2cc2001eec1", "scanner": "scanner-primary", "fingerprint": "ae833d4a886bff6d", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/package.json"}, "region": {"startLine": 1}}}]}]}]}