{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-bead75b0f9233e05", "name": "No API endpoints detected", "shortDescription": {"text": "No API endpoints detected"}, "fullDescription": {"text": "The scanner did not find FastAPI/Flask/Express/NestJS/GraphQL/gRPC routes. If this repo exposes APIs, the framework may be unsupported."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b62d8d33e250991f", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 components/Faq.tsx:23", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 components/Faq.tsx:23"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b976038c5a56b847", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/layout.tsx:80", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/layout.tsx:80"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d83aa4b518483473", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/match/[slug]/page.tsx:162", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/match/[slug]/page.tsx:162"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cf2ff59312cfdcab", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/world-cup-2026/page.tsx:128", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/world-cup-2026/page.tsx:128"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-480f807ab48c573d", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/league/[name]/page.tsx:131", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/league/[name]/page.tsx:131"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b05786d22ad8c2f", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/fixtures/[slug]/page.tsx:147", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/fixtures/[slug]/page.tsx:147"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-928bb634631ebec1", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/team/[name]/page.tsx:138", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/team/[name]/page.tsx:138"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ae69ab92920ed48", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/channels/page.tsx:52", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/channels/page.tsx:52"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e5f8981d3457560", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/schedules/[date]/page.tsx:97", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/schedules/[date]/page.tsx:97"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16aa4644e368aae2", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/channel/[name]/page.tsx:213", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/channel/[name]/page.tsx:213"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06b39375cd075d86", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/country/[name]/page.tsx:130", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/country/[name]/page.tsx:130"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f959b09e13f225a", "name": "Insecure pattern 'direct_innerhtml_assignment' in components/SuperCounter.tsx:36", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in components/SuperCounter.tsx:36"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70b0faa7f22e6cab", "name": "Insecure pattern 'dangerous_innerhtml' in components/Faq.tsx:23", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in components/Faq.tsx:23"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2ccd0689db53c7d", "name": "Insecure pattern 'dangerous_innerhtml' in app/layout.tsx:80", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/layout.tsx:80"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca96d9c2425af1d4", "name": "Insecure pattern 'dangerous_innerhtml' in app/match/[slug]/page.tsx:162", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/match/[slug]/page.tsx:162"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9ba843f34ef9c2a", "name": "Insecure pattern 'dangerous_innerhtml' in app/world-cup-2026/page.tsx:128", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/world-cup-2026/page.tsx:128"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6420ac2670dab345", "name": "Insecure pattern 'dangerous_innerhtml' in app/league/[name]/page.tsx:131", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/league/[name]/page.tsx:131"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-00fd43001697f7b5", "name": "Insecure pattern 'dangerous_innerhtml' in app/team/[name]/page.tsx:138", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/team/[name]/page.tsx:138"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0441f65c2ae645d", "name": "Insecure pattern 'dangerous_innerhtml' in app/channels/page.tsx:52", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/channels/page.tsx:52"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c61704fffbc460d2", "name": "Insecure pattern 'dangerous_innerhtml' in app/schedules/[date]/page.tsx:97", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/schedules/[date]/page.tsx:97"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-129a5b876494b196", "name": "Insecure pattern 'dangerous_innerhtml' in app/channel/[name]/page.tsx:213", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/channel/[name]/page.tsx:213"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc0f57e4fb266c4c", "name": "Insecure pattern 'dangerous_innerhtml' in app/country/[name]/page.tsx:130", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/country/[name]/page.tsx:130"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16aeaabeb92d025f", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/google-ads.js:83", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/google-ads.js:83"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c4a04bd807da0c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad6701f0a8405e22", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 44 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9fe265b9991ba833", "name": "Commented-code block (6 lines) in components/LocalTime.tsx:6", "shortDescription": {"text": "Commented-code block (6 lines) in components/LocalTime.tsx:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14c8a7509a7235b5", "name": "Commented-code block (6 lines) in app/league/[name]/page.tsx:28", "shortDescription": {"text": "Commented-code block (6 lines) in app/league/[name]/page.tsx:28"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23315"}, "properties": {"repository": "yosintv2/lstv", "repoUrl": "https://github.com/yosintv2/lstv", "branch": "main"}, "results": [{"ruleId": "scanner-bead75b0f9233e05", "level": "none", "message": {"text": "No API endpoints detected"}, "properties": {"repobilityId": "0f8bb852027c38f8", "scanner": "scanner-primary", "fingerprint": "bead75b0f9233e05", "layer": "api", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-b62d8d33e250991f", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 components/Faq.tsx:23"}, "properties": {"repobilityId": "127fd7d8d2cb1465", "scanner": "scanner-primary", "fingerprint": "b62d8d33e250991f", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-b976038c5a56b847", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/layout.tsx:80"}, "properties": {"repobilityId": "6f16eb9b82a2dcd6", "scanner": "scanner-primary", "fingerprint": "b976038c5a56b847", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-d83aa4b518483473", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/match/[slug]/page.tsx:162"}, "properties": {"repobilityId": "46f0667b4d96712a", "scanner": "scanner-primary", "fingerprint": "d83aa4b518483473", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-cf2ff59312cfdcab", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/world-cup-2026/page.tsx:128"}, "properties": {"repobilityId": "c10ee64e1f29ea16", "scanner": "scanner-primary", "fingerprint": "cf2ff59312cfdcab", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-480f807ab48c573d", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/league/[name]/page.tsx:131"}, "properties": {"repobilityId": "e1275040c7d47a2d", "scanner": "scanner-primary", "fingerprint": "480f807ab48c573d", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-2b05786d22ad8c2f", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/fixtures/[slug]/page.tsx:147"}, "properties": {"repobilityId": "6434a9b12290c446", "scanner": "scanner-primary", "fingerprint": "2b05786d22ad8c2f", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-928bb634631ebec1", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/team/[name]/page.tsx:138"}, "properties": {"repobilityId": "fe853dcc3ee0f8a3", "scanner": "scanner-primary", "fingerprint": "928bb634631ebec1", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-2ae69ab92920ed48", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/channels/page.tsx:52"}, "properties": {"repobilityId": "a76337de8494f1e0", "scanner": "scanner-primary", "fingerprint": "2ae69ab92920ed48", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-0e5f8981d3457560", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/schedules/[date]/page.tsx:97"}, "properties": {"repobilityId": "8f333654f2009554", "scanner": "scanner-primary", "fingerprint": "0e5f8981d3457560", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-16aa4644e368aae2", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/channel/[name]/page.tsx:213"}, "properties": {"repobilityId": "d45e9376199e94e0", "scanner": "scanner-primary", "fingerprint": "16aa4644e368aae2", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-06b39375cd075d86", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/country/[name]/page.tsx:130"}, "properties": {"repobilityId": "7d9cf50305f1de5a", "scanner": "scanner-primary", "fingerprint": "06b39375cd075d86", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-0f959b09e13f225a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in components/SuperCounter.tsx:36"}, "properties": {"repobilityId": "22ff588e5dbbd09a", "scanner": "scanner-primary", "fingerprint": "0f959b09e13f225a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "components/SuperCounter.tsx"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-70b0faa7f22e6cab", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in components/Faq.tsx:23"}, "properties": {"repobilityId": "2d045ab45e1d0194", "scanner": "scanner-primary", "fingerprint": "70b0faa7f22e6cab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "components/Faq.tsx"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-a2ccd0689db53c7d", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/layout.tsx:80"}, "properties": {"repobilityId": "69d4743587f721a0", "scanner": "scanner-primary", "fingerprint": "a2ccd0689db53c7d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/layout.tsx"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-ca96d9c2425af1d4", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/match/[slug]/page.tsx:162"}, "properties": {"repobilityId": "8d615ec3cef2792f", "scanner": "scanner-primary", "fingerprint": "ca96d9c2425af1d4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/match/[slug]/page.tsx"}, "region": {"startLine": 162}}}]}, {"ruleId": "scanner-b9ba843f34ef9c2a", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/world-cup-2026/page.tsx:128"}, "properties": {"repobilityId": "23ce536f2cb0f99f", "scanner": "scanner-primary", "fingerprint": "b9ba843f34ef9c2a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/world-cup-2026/page.tsx"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-6420ac2670dab345", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/league/[name]/page.tsx:131"}, "properties": {"repobilityId": "1c215a525cad3c5d", "scanner": "scanner-primary", "fingerprint": "6420ac2670dab345", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/league/[name]/page.tsx"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-00fd43001697f7b5", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/team/[name]/page.tsx:138"}, "properties": {"repobilityId": "873aa18c246547ed", "scanner": "scanner-primary", "fingerprint": "00fd43001697f7b5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/team/[name]/page.tsx"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-f0441f65c2ae645d", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/channels/page.tsx:52"}, "properties": {"repobilityId": "884553b73dd6af73", "scanner": "scanner-primary", "fingerprint": "f0441f65c2ae645d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/channels/page.tsx"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-c61704fffbc460d2", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/schedules/[date]/page.tsx:97"}, "properties": {"repobilityId": "36d04305d5c800fc", "scanner": "scanner-primary", "fingerprint": "c61704fffbc460d2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/schedules/[date]/page.tsx"}, "region": {"startLine": 97}}}]}, {"ruleId": "scanner-129a5b876494b196", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/channel/[name]/page.tsx:213"}, "properties": {"repobilityId": "7e7c8a3a3a8a4c2f", "scanner": "scanner-primary", "fingerprint": "129a5b876494b196", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/channel/[name]/page.tsx"}, "region": {"startLine": 213}}}]}, {"ruleId": "scanner-bc0f57e4fb266c4c", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/country/[name]/page.tsx:130"}, "properties": {"repobilityId": "426633fdd74f5f33", "scanner": "scanner-primary", "fingerprint": "bc0f57e4fb266c4c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/country/[name]/page.tsx"}, "region": {"startLine": 130}}}]}, {"ruleId": "scanner-16aeaabeb92d025f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/google-ads.js:83"}, "properties": {"repobilityId": "229d723ae068315f", "scanner": "scanner-primary", "fingerprint": "16aeaabeb92d025f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/google-ads.js"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2aee2e2d969c7c6b", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bee6b8956e03198c", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b70dbcc8f54d72ab", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-28c4a04bd807da0c", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "419d1ec7943efec2", "scanner": "scanner-primary", "fingerprint": "28c4a04bd807da0c", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-ad6701f0a8405e22", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "8384c23520d55657", "scanner": "scanner-primary", "fingerprint": "ad6701f0a8405e22", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "2d6a93bbd823f1b6", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "53a0d8b55332fce2", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "fbfe660a0471684c", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "1a665c5993991766", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "0644098a1d153cf8", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "92b41dbed68a19d6", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "1f7eef82e840da5a", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-9fe265b9991ba833", "level": "none", "message": {"text": "Commented-code block (6 lines) in components/LocalTime.tsx:6"}, "properties": {"repobilityId": "de370d06a5e9caec", "scanner": "scanner-primary", "fingerprint": "9fe265b9991ba833", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-14c8a7509a7235b5", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/league/[name]/page.tsx:28"}, "properties": {"repobilityId": "f0ca26cbbc1e64bc", "scanner": "scanner-primary", "fingerprint": "14c8a7509a7235b5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}]}]}