{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-9eae84c1bd769515", "name": "Possibly dead Python function: set_admin_session", "shortDescription": {"text": "Possibly dead Python function: set_admin_session"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3438c15d29e89bd8", "name": "Possibly dead Python function: require_authenticated", "shortDescription": {"text": "Possibly dead Python function: require_authenticated"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d9c146b25143f42", "name": "Possibly dead Python function: require_admin_or_download_user", "shortDescription": {"text": "Possibly dead Python function: require_admin_or_download_user"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e0888941f466597", "name": "Possibly dead Python function: require_authenticated_websocket", "shortDescription": {"text": "Possibly dead Python function: require_authenticated_websocket"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce54710a21feb7a2", "name": "Possibly dead Python function: require_admin_websocket", "shortDescription": {"text": "Possibly dead Python function: require_admin_websocket"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb794059dd6694ed", "name": "Possibly dead Python function: require_admin_or_download_user_websocket", "shortDescription": {"text": "Possibly dead Python function: require_admin_or_download_user_websocket"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ef702320d0ff1b8", "name": "Possibly dead Python function: send_wrapper", "shortDescription": {"text": "Possibly dead Python function: send_wrapper"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c775a46c2ba9c8f3", "name": "Possibly dead Python function: set_ffmpeg_path", "shortDescription": {"text": "Possibly dead Python function: set_ffmpeg_path"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-946b4bf5da562d77", "name": "Possibly dead Python function: mapped_callback", "shortDescription": {"text": "Possibly dead Python function: mapped_callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92b6642ba8161afb", "name": "Possibly dead Python function: transcode_progress_callback", "shortDescription": {"text": "Possibly dead Python function: transcode_progress_callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-baae84a32e825931", "name": "Possibly dead Python function: comskip_progress_callback", "shortDescription": {"text": "Possibly dead Python function: comskip_progress_callback"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09c78276ade5492e", "name": "Privileged port 50 in use", "shortDescription": {"text": "Privileged port 50 in use"}, "fullDescription": {"text": "Port 50 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60427b03771411b6", "name": "Dockerfile runs as root: frontend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: frontend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-faa134129e5545ff", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b048d166901fd868", "name": "Docker base image is tag-pinned but not digest-pinned: nginx:alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f66ad88286ca30a", "name": "Dockerfile runs as root: backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15b7cf40a00be802", "name": "Docker base image is tag-pinned but not digest-pinned: ghcr.io/linuxserver/baseimage-ubuntu:noble", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: ghcr.io/linuxserver/baseimage-ubuntu:noble"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d2a6283f9ebab24", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e70c0bb994125bc", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5352e214808b403", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a50467f36b413ec", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a73739afeec625f", "name": "Very large file: frontend/src/pages/Settings.jsx (1797 lines)", "shortDescription": {"text": "Very large file: frontend/src/pages/Settings.jsx (1797 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b5241978a4a586b", "name": "Very large file: backend/services/post_processor.py (1753 lines)", "shortDescription": {"text": "Very large file: backend/services/post_processor.py (1753 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1221a828ecfe91f", "name": "Very large file: backend/services/download_manager.py (2238 lines)", "shortDescription": {"text": "Very large file: backend/services/download_manager.py (2238 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fc54267defb8350", "name": "Very large file: backend/services/epg_ingest_manager.py (1221 lines)", "shortDescription": {"text": "Very large file: backend/services/epg_ingest_manager.py (1221 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 5 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 21 placeholder/mock markers across 6 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0903f0cecc34e804", "name": "Commented-code block (7 lines) in frontend/src/pages/Browse.test.jsx:54", "shortDescription": {"text": "Commented-code block (7 lines) in frontend/src/pages/Browse.test.jsx:54"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5a417579040040df", "name": "Commented-code block (6 lines) in backend/tests/test_delete_account_epg_cleanup.py:59", "shortDescription": {"text": "Commented-code block (6 lines) in backend/tests/test_delete_account_epg_cleanup.py:59"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9a410a89bfde01f9", "name": "Legacy-named symbol `login_auth_legacy` in backend/tests/test_legacy_login_admin_username.py:11", "shortDescription": {"text": "Legacy-named symbol `login_auth_legacy` in backend/tests/test_legacy_login_admin_username.py:11"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f19cc55ec52fc01", "name": "Legacy-named symbol `login_auth_legacy` in backend/api/auth.py:399", "shortDescription": {"text": "Legacy-named symbol `login_auth_legacy` in backend/api/auth.py:399"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16af5735f60e7e61", "name": "Commented-code block (5 lines) in backend/api/settings.py:305", "shortDescription": {"text": "Commented-code block (5 lines) in backend/api/settings.py:305"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-121e7d952e9ea53c", "name": "Commented-code block (7 lines) in backend/api/channels.py:389", "shortDescription": {"text": "Commented-code block (7 lines) in backend/api/channels.py:389"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-45b6b7dc685aa29d", "name": "Commented-code block (5 lines) in backend/services/scheduled_manager.py:22", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/scheduled_manager.py:22"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0e5142de796fcb63", "name": "Commented-code block (5 lines) in backend/services/download_manager.py:39", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/download_manager.py:39"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-825c9afba71db592", "name": "Commented-code block (6 lines) in backend/services/hls_streamer.py:191", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/hls_streamer.py:191"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e918b12475f4d36a", "name": "Commented-code block (6 lines) in backend/services/epg_ingest_manager.py:36", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/epg_ingest_manager.py:36"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b93f5249d85fbb7b", "name": "Commented-code block (5 lines) in backend/services/download_builder.py:90", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/download_builder.py:90"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/auth.py:require_authenticated_websocket, backend/auth.py:require_admin_or_download_user_websocket\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/models/user.py:to_dict, backend/models/user.py:to_dict, backend/models/user.py:to_dict\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8cfe7c8aed20a718", "name": "Frontend route `/accounts` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/accounts` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2be4ec6e20969bbf", "name": "Frontend route `/logs` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/logs` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5ddca1ac2dc97a5e", "name": "Frontend route `/downloads/:downloadId/play` has no Link/navigate to it \u2014 frontend/src/pages/DownloadPlayer.test.jsx", "shortDescription": {"text": "Frontend route `/downloads/:downloadId/play` has no Link/navigate to it \u2014 frontend/src/pages/DownloadPlayer.test.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-62093ca58510b5b3", "name": "Dangling fetch: GET /downloads/failed-count${params} (frontend/src/api.js:137)", "shortDescription": {"text": "Dangling fetch: GET /downloads/failed-count${params} (frontend/src/api.js:137)"}, "fullDescription": {"text": "`frontend/src/api.js:137` calls `GET /downloads/failed-count${params}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/downloads/failed-count/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-da70dcbb11af892c", "name": "Dangling fetch: GET /settings (frontend/src/api.js:176)", "shortDescription": {"text": "Dangling fetch: GET /settings (frontend/src/api.js:176)"}, "fullDescription": {"text": "`frontend/src/api.js:176` calls `GET /settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1c0701e2c1ee8caf", "name": "Dangling fetch: GET /settings/public (frontend/src/api.js:177)", "shortDescription": {"text": "Dangling fetch: GET /settings/public (frontend/src/api.js:177)"}, "fullDescription": {"text": "`frontend/src/api.js:177` calls `GET /settings/public` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/public`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac293631ae7948e6", "name": "Dangling fetch: PUT /settings (frontend/src/api.js:178)", "shortDescription": {"text": "Dangling fetch: PUT /settings (frontend/src/api.js:178)"}, "fullDescription": {"text": "`frontend/src/api.js:178` calls `PUT /settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45ba699e8b7d7a2a", "name": "Dangling fetch: GET /settings/templates (frontend/src/api.js:179)", "shortDescription": {"text": "Dangling fetch: GET /settings/templates (frontend/src/api.js:179)"}, "fullDescription": {"text": "`frontend/src/api.js:179` calls `GET /settings/templates` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/templates`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5eb7ef591b07f2e7", "name": "Dangling fetch: GET /settings/tools (frontend/src/api.js:180)", "shortDescription": {"text": "Dangling fetch: GET /settings/tools (frontend/src/api.js:180)"}, "fullDescription": {"text": "`frontend/src/api.js:180` calls `GET /settings/tools` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/tools`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0271a2108c5eaf92", "name": "Dangling fetch: GET /settings/folders/status (frontend/src/api.js:181)", "shortDescription": {"text": "Dangling fetch: GET /settings/folders/status (frontend/src/api.js:181)"}, "fullDescription": {"text": "`frontend/src/api.js:181` calls `GET /settings/folders/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/folders/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ddbb964388fdea85", "name": "Dangling fetch: GET /auth/status (frontend/src/api.js:186)", "shortDescription": {"text": "Dangling fetch: GET /auth/status (frontend/src/api.js:186)"}, "fullDescription": {"text": "`frontend/src/api.js:186` calls `GET /auth/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dfe2051d5ed65c32", "name": "Dangling fetch: GET /auth/admin-bootstrap/status (frontend/src/api.js:187)", "shortDescription": {"text": "Dangling fetch: GET /auth/admin-bootstrap/status (frontend/src/api.js:187)"}, "fullDescription": {"text": "`frontend/src/api.js:187` calls `GET /auth/admin-bootstrap/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/admin-bootstrap/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8b53926a6200a23c", "name": "Dangling fetch: POST /auth/admin-bootstrap/complete (frontend/src/api.js:189)", "shortDescription": {"text": "Dangling fetch: POST /auth/admin-bootstrap/complete (frontend/src/api.js:189)"}, "fullDescription": {"text": "`frontend/src/api.js:189` calls `POST /auth/admin-bootstrap/complete` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/admin-bootstrap/complete`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5614475e429654b0", "name": "Dangling fetch: POST /auth/setup (frontend/src/api.js:194)", "shortDescription": {"text": "Dangling fetch: POST /auth/setup (frontend/src/api.js:194)"}, "fullDescription": {"text": "`frontend/src/api.js:194` calls `POST /auth/setup` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/setup`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a13164f09d5cbddf", "name": "Dangling fetch: POST /auth/login-credentials (frontend/src/api.js:196)", "shortDescription": {"text": "Dangling fetch: POST /auth/login-credentials (frontend/src/api.js:196)"}, "fullDescription": {"text": "`frontend/src/api.js:196` calls `POST /auth/login-credentials` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login-credentials`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d6a2e389c6819d01", "name": "Dangling fetch: POST /auth/login (frontend/src/api.js:197)", "shortDescription": {"text": "Dangling fetch: POST /auth/login (frontend/src/api.js:197)"}, "fullDescription": {"text": "`frontend/src/api.js:197` calls `POST /auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-705dcb3ec554a43c", "name": "Dangling fetch: POST /auth/user/login (frontend/src/api.js:199)", "shortDescription": {"text": "Dangling fetch: POST /auth/user/login (frontend/src/api.js:199)"}, "fullDescription": {"text": "`frontend/src/api.js:199` calls `POST /auth/user/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/user/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8780de408bbd7cf3", "name": "Dangling fetch: POST /auth/plex/login/start (frontend/src/api.js:200)", "shortDescription": {"text": "Dangling fetch: POST /auth/plex/login/start (frontend/src/api.js:200)"}, "fullDescription": {"text": "`frontend/src/api.js:200` calls `POST /auth/plex/login/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/plex/login/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7def4e3d802c3a12", "name": "Dangling fetch: POST /auth/plex/login/complete (frontend/src/api.js:202)", "shortDescription": {"text": "Dangling fetch: POST /auth/plex/login/complete (frontend/src/api.js:202)"}, "fullDescription": {"text": "`frontend/src/api.js:202` calls `POST /auth/plex/login/complete` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/plex/login/complete`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35337c40978fda1a", "name": "Dangling fetch: POST /auth/logout (frontend/src/api.js:203)", "shortDescription": {"text": "Dangling fetch: POST /auth/logout (frontend/src/api.js:203)"}, "fullDescription": {"text": "`frontend/src/api.js:203` calls `POST /auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dd0820b78bc907e2", "name": "Dangling fetch: POST /auth/change-password (frontend/src/api.js:205)", "shortDescription": {"text": "Dangling fetch: POST /auth/change-password (frontend/src/api.js:205)"}, "fullDescription": {"text": "`frontend/src/api.js:205` calls `POST /auth/change-password` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/change-password`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-69347e04cc81b975", "name": "Dangling fetch: GET /auth/preferences (frontend/src/api.js:209)", "shortDescription": {"text": "Dangling fetch: GET /auth/preferences (frontend/src/api.js:209)"}, "fullDescription": {"text": "`frontend/src/api.js:209` calls `GET /auth/preferences` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/preferences`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-14cfc81e50fdeb21", "name": "Dangling fetch: PUT /auth/preferences (frontend/src/api.js:211)", "shortDescription": {"text": "Dangling fetch: PUT /auth/preferences (frontend/src/api.js:211)"}, "fullDescription": {"text": "`frontend/src/api.js:211` calls `PUT /auth/preferences` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/preferences`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c9ce3af9baafd95", "name": "Dangling fetch: GET /auth/user/setup/${encodeURIComponent(token)} (frontend/src/api.js:212)", "shortDescription": {"text": "Dangling fetch: GET /auth/user/setup/${encodeURIComponent(token)} (frontend/src/api.js:212)"}, "fullDescription": {"text": "`frontend/src/api.js:212` calls `GET /auth/user/setup/${encodeURIComponent(token)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/user/setup/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4e473faefc5f0e5e", "name": "Dangling fetch: POST /auth/user/setup/${encodeURIComponent(token)} (frontend/src/api.js:214)", "shortDescription": {"text": "Dangling fetch: POST /auth/user/setup/${encodeURIComponent(token)} (frontend/src/api.js:214)"}, "fullDescription": {"text": "`frontend/src/api.js:214` calls `POST /auth/user/setup/${encodeURIComponent(token)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/user/setup/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9d579e7344bfa7e5", "name": "Dangling fetch: POST /admin/plex/server/test (frontend/src/api.js:237)", "shortDescription": {"text": "Dangling fetch: POST /admin/plex/server/test (frontend/src/api.js:237)"}, "fullDescription": {"text": "`frontend/src/api.js:237` calls `POST /admin/plex/server/test` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/plex/server/test`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4b1b5b539bb9da7", "name": "Dangling fetch: GET /admin/plex/server/users (frontend/src/api.js:238)", "shortDescription": {"text": "Dangling fetch: GET /admin/plex/server/users (frontend/src/api.js:238)"}, "fullDescription": {"text": "`frontend/src/api.js:238` calls `GET /admin/plex/server/users` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/admin/plex/server/users`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`backend/main.py` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a6d91f2236825bf", "name": "Unused endpoint: ANY /", "shortDescription": {"text": "Unused endpoint: ANY /"}, "fullDescription": {"text": "`backend/main.py` declares `ANY /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7704fa4b33201b51", "name": "Unused endpoint: ANY /{full_path:path}", "shortDescription": {"text": "Unused endpoint: ANY /{full_path:path}"}, "fullDescription": {"text": "`backend/main.py` declares `ANY /{full_path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12590588bd560e15", "name": "Unused endpoint: GET /api/epg/search", "shortDescription": {"text": "Unused endpoint: GET /api/epg/search"}, "fullDescription": {"text": "`backend/api/epg.py` declares `GET /api/epg/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5949e36a46ad5d07", "name": "Unused endpoint: GET /csrf", "shortDescription": {"text": "Unused endpoint: GET /csrf"}, "fullDescription": {"text": "`backend/api/auth.py` declares `GET /csrf` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d18fe59c0e04d455", "name": "Unused endpoint: GET /admin-bootstrap/status", "shortDescription": {"text": "Unused endpoint: GET /admin-bootstrap/status"}, "fullDescription": {"text": "`backend/api/auth.py` declares `GET /admin-bootstrap/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05548e3a807cb1f1", "name": "Unused endpoint: POST /admin-bootstrap/complete", "shortDescription": {"text": "Unused endpoint: POST /admin-bootstrap/complete"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /admin-bootstrap/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb757797f6bd3444", "name": "Unused endpoint: POST /setup", "shortDescription": {"text": "Unused endpoint: POST /setup"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /setup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60a24ef6e57ba89b", "name": "Unused endpoint: POST /login-credentials", "shortDescription": {"text": "Unused endpoint: POST /login-credentials"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /login-credentials` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06eb5909449c5de7", "name": "Unused endpoint: POST /user/login", "shortDescription": {"text": "Unused endpoint: POST /user/login"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /user/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac6b4917fce952cc", "name": "Unused endpoint: POST /plex/login/start", "shortDescription": {"text": "Unused endpoint: POST /plex/login/start"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /plex/login/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cab4434ba6a1682a", "name": "Unused endpoint: POST /plex/login/complete", "shortDescription": {"text": "Unused endpoint: POST /plex/login/complete"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /plex/login/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fe9bb486644f008", "name": "Unused endpoint: POST /change-password", "shortDescription": {"text": "Unused endpoint: POST /change-password"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /change-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8764484f2d99e7b", "name": "Unused endpoint: GET /preferences", "shortDescription": {"text": "Unused endpoint: GET /preferences"}, "fullDescription": {"text": "`backend/api/auth.py` declares `GET /preferences` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b6f3e56a23ece9a", "name": "Unused endpoint: PUT /preferences", "shortDescription": {"text": "Unused endpoint: PUT /preferences"}, "fullDescription": {"text": "`backend/api/auth.py` declares `PUT /preferences` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c09dfb98247b83a", "name": "Unused endpoint: GET /user/setup/{token}", "shortDescription": {"text": "Unused endpoint: GET /user/setup/{token}"}, "fullDescription": {"text": "`backend/api/auth.py` declares `GET /user/setup/{token}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-036db92d819ac034", "name": "Unused endpoint: POST /user/setup/{token}", "shortDescription": {"text": "Unused endpoint: POST /user/setup/{token}"}, "fullDescription": {"text": "`backend/api/auth.py` declares `POST /user/setup/{token}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce46577ac036074b", "name": "Unused endpoint: GET /api/downloads/failed-count", "shortDescription": {"text": "Unused endpoint: GET /api/downloads/failed-count"}, "fullDescription": {"text": "`backend/api/downloads.py` declares `GET /api/downloads/failed-count` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2d0d8595a2282b8", "name": "Unused endpoint: GET /api/downloads/{download_id}/file", "shortDescription": {"text": "Unused endpoint: GET /api/downloads/{download_id}/file"}, "fullDescription": {"text": "`backend/api/downloads.py` declares `GET /api/downloads/{download_id}/file` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33840861cd8a64e8", "name": "Unused endpoint: GET /api/downloads/{download_id}/hls/{asset}", "shortDescription": {"text": "Unused endpoint: GET /api/downloads/{download_id}/hls/{asset}"}, "fullDescription": {"text": "`backend/api/downloads.py` declares `GET /api/downloads/{download_id}/hls/{asset}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/api/settings.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67d28fa8cd6bb12f", "name": "Unused endpoint: PUT /", "shortDescription": {"text": "Unused endpoint: PUT /"}, "fullDescription": {"text": "`backend/api/settings.py` declares `PUT /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66d6e05669a99666", "name": "Unused endpoint: GET /folders/status", "shortDescription": {"text": "Unused endpoint: GET /folders/status"}, "fullDescription": {"text": "`backend/api/settings.py` declares `GET /folders/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-017394171548a2b2", "name": "Unused endpoint: GET /templates", "shortDescription": {"text": "Unused endpoint: GET /templates"}, "fullDescription": {"text": "`backend/api/settings.py` declares `GET /templates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-582b00fca2796501", "name": "Unused endpoint: GET /tools", "shortDescription": {"text": "Unused endpoint: GET /tools"}, "fullDescription": {"text": "`backend/api/settings.py` declares `GET /tools` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a42c52fea3345b5", "name": "Unused endpoint: GET /public", "shortDescription": {"text": "Unused endpoint: GET /public"}, "fullDescription": {"text": "`backend/api/settings.py` declares `GET /public` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4cc144b53db879ad", "name": "Unused endpoint: GET /api/logos", "shortDescription": {"text": "Unused endpoint: GET /api/logos"}, "fullDescription": {"text": "`backend/api/channels.py` declares `GET /api/logos` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f03eb286a2475f92", "name": "Unused endpoint: GET /api/accounts/{account_id}/channels/{channel_id}/epg", "shortDescription": {"text": "Unused endpoint: GET /api/accounts/{account_id}/channels/{channel_id}/epg"}, "fullDescription": {"text": "`backend/api/channels.py` declares `GET /api/accounts/{account_id}/channels/{channel_id}/epg` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d1a30bee69c148c", "name": "Unused endpoint: GET /api/accounts/{account_id}/channels/{channel_id}/preview", "shortDescription": {"text": "Unused endpoint: GET /api/accounts/{account_id}/channels/{channel_id}/preview"}, "fullDescription": {"text": "`backend/api/channels.py` declares `GET /api/accounts/{account_id}/channels/{channel_id}/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/17919"}, "properties": {"repository": "razzamatazm/mustarrd", "repoUrl": "https://github.com/razzamatazm/mustarrd", "branch": "main"}, "results": [{"ruleId": "scanner-9eae84c1bd769515", "level": "note", "message": {"text": "Possibly dead Python function: set_admin_session"}, "properties": {"repobilityId": "54df534adcaef2cc", "scanner": "scanner-primary", "fingerprint": "9eae84c1bd769515", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/auth.py:39"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3438c15d29e89bd8", "level": "note", "message": {"text": "Possibly dead Python function: require_authenticated"}, "properties": {"repobilityId": "8e1dba0b4d1dc932", "scanner": "scanner-primary", "fingerprint": "3438c15d29e89bd8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/auth.py:155"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1d9c146b25143f42", "level": "note", "message": {"text": "Possibly dead Python function: require_admin_or_download_user"}, "properties": {"repobilityId": "e01b5cad816e13f3", "scanner": "scanner-primary", "fingerprint": "1d9c146b25143f42", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/auth.py:171"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e0888941f466597", "level": "note", "message": {"text": "Possibly dead Python function: require_authenticated_websocket"}, "properties": {"repobilityId": "bdafd4510e82cd43", "scanner": "scanner-primary", "fingerprint": "2e0888941f466597", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/auth.py:177"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ce54710a21feb7a2", "level": "note", "message": {"text": "Possibly dead Python function: require_admin_websocket"}, "properties": {"repobilityId": "179de44c607aa480", "scanner": "scanner-primary", "fingerprint": "ce54710a21feb7a2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/auth.py:187"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bb794059dd6694ed", "level": "note", "message": {"text": "Possibly dead Python function: require_admin_or_download_user_websocket"}, "properties": {"repobilityId": "4d340e630ae6c6b9", "scanner": "scanner-primary", "fingerprint": "bb794059dd6694ed", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/auth.py:197"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ef702320d0ff1b8", "level": "note", "message": {"text": "Possibly dead Python function: send_wrapper"}, "properties": {"repobilityId": "f34ba48c1fd7571b", "scanner": "scanner-primary", "fingerprint": "0ef702320d0ff1b8", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/main.py:197"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c775a46c2ba9c8f3", "level": "note", "message": {"text": "Possibly dead Python function: set_ffmpeg_path"}, "properties": {"repobilityId": "18061e5b07eeb44f", "scanner": "scanner-primary", "fingerprint": "c775a46c2ba9c8f3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/post_processor.py:217"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-946b4bf5da562d77", "level": "note", "message": {"text": "Possibly dead Python function: mapped_callback"}, "properties": {"repobilityId": "a0f78d93c1361fdf", "scanner": "scanner-primary", "fingerprint": "946b4bf5da562d77", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/post_processor.py:1410"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92b6642ba8161afb", "level": "note", "message": {"text": "Possibly dead Python function: transcode_progress_callback"}, "properties": {"repobilityId": "c4879f589187ef46", "scanner": "scanner-primary", "fingerprint": "92b6642ba8161afb", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/download_manager.py:2004"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-baae84a32e825931", "level": "note", "message": {"text": "Possibly dead Python function: comskip_progress_callback"}, "properties": {"repobilityId": "ab33cfc54ade4afe", "scanner": "scanner-primary", "fingerprint": "baae84a32e825931", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/download_manager.py:2032"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-09c78276ade5492e", "level": "warning", "message": {"text": "Privileged port 50 in use"}, "properties": {"repobilityId": "da61f654c07ea7a9", "scanner": "scanner-primary", "fingerprint": "09c78276ade5492e", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker-compose.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-60427b03771411b6", "level": "warning", "message": {"text": "Dockerfile runs as root: frontend/Dockerfile"}, "properties": {"repobilityId": "735c01d8531dfd2c", "scanner": "scanner-primary", "fingerprint": "60427b03771411b6", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-faa134129e5545ff", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "3e90d440e1f9ece1", "scanner": "scanner-primary", "fingerprint": "faa134129e5545ff", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b048d166901fd868", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:alpine"}, "properties": {"repobilityId": "48ad78acd60e6948", "scanner": "scanner-primary", "fingerprint": "b048d166901fd868", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/Dockerfile"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-1f66ad88286ca30a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "properties": {"repobilityId": "7afd2b0e8a8c9eeb", "scanner": "scanner-primary", "fingerprint": "1f66ad88286ca30a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-15b7cf40a00be802", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: ghcr.io/linuxserver/baseimage-ubuntu:noble"}, "properties": {"repobilityId": "75e02e735209dbbf", "scanner": "scanner-primary", "fingerprint": "15b7cf40a00be802", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3d2a6283f9ebab24", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "9d67ecdd7ca3938a", "scanner": "scanner-primary", "fingerprint": "3d2a6283f9ebab24", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-15b7cf40a00be802", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: ghcr.io/linuxserver/baseimage-ubuntu:noble"}, "properties": {"repobilityId": "01b3e4008efaa675", "scanner": "scanner-primary", "fingerprint": "15b7cf40a00be802", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-5e70c0bb994125bc", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "04d52176a45c72f7", "scanner": "scanner-primary", "fingerprint": "5e70c0bb994125bc", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-5e70c0bb994125bc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cf211fadd51f8e36", "scanner": "scanner-primary", "fingerprint": "5e70c0bb994125bc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-5e70c0bb994125bc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "95c73134f058f573", "scanner": "scanner-primary", "fingerprint": "5e70c0bb994125bc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-5e70c0bb994125bc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "fe505d9000759172", "scanner": "scanner-primary", "fingerprint": "5e70c0bb994125bc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-5e70c0bb994125bc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a4ec6eb2a7071f6b", "scanner": "scanner-primary", "fingerprint": "5e70c0bb994125bc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-5e70c0bb994125bc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e1fe34935d8da462", "scanner": "scanner-primary", "fingerprint": "5e70c0bb994125bc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-b5352e214808b403", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "86e617e86a0b4248", "scanner": "scanner-primary", "fingerprint": "b5352e214808b403", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish-images.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1a50467f36b413ec", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8be1c656ca78b295", "scanner": "scanner-primary", "fingerprint": "1a50467f36b413ec", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/tests.yml"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-1a50467f36b413ec", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "83768f0016883fc6", "scanner": "scanner-primary", "fingerprint": "1a50467f36b413ec", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/tests.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-2a73739afeec625f", "level": "note", "message": {"text": "Very large file: frontend/src/pages/Settings.jsx (1797 lines)"}, "properties": {"repobilityId": "33b5e78ff0864984", "scanner": "scanner-primary", "fingerprint": "2a73739afeec625f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6b5241978a4a586b", "level": "note", "message": {"text": "Very large file: backend/services/post_processor.py (1753 lines)"}, "properties": {"repobilityId": "2a92ceb9cf4ac638", "scanner": "scanner-primary", "fingerprint": "6b5241978a4a586b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d1221a828ecfe91f", "level": "note", "message": {"text": "Very large file: backend/services/download_manager.py (2238 lines)"}, "properties": {"repobilityId": "f0264a89d9ab55e9", "scanner": "scanner-primary", "fingerprint": "d1221a828ecfe91f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9fc54267defb8350", "level": "note", "message": {"text": "Very large file: backend/services/epg_ingest_manager.py (1221 lines)"}, "properties": {"repobilityId": "ecf4bb3605ccb230", "scanner": "scanner-primary", "fingerprint": "9fc54267defb8350", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "bd10a8927dab76b0", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "e735edd970352712", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "414a25db7c1bd546", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "aa7b8e4620f9c2a2", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "1ab35f782a4a9872", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-0903f0cecc34e804", "level": "none", "message": {"text": "Commented-code block (7 lines) in frontend/src/pages/Browse.test.jsx:54"}, "properties": {"repobilityId": "aa44da8e1ae1b3c6", "scanner": "scanner-primary", "fingerprint": "0903f0cecc34e804", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5a417579040040df", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/tests/test_delete_account_epg_cleanup.py:59"}, "properties": {"repobilityId": "b1e8441447021136", "scanner": "scanner-primary", "fingerprint": "5a417579040040df", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9a410a89bfde01f9", "level": "note", "message": {"text": "Legacy-named symbol `login_auth_legacy` in backend/tests/test_legacy_login_admin_username.py:11"}, "properties": {"repobilityId": "3d70a18fbbad34b7", "scanner": "scanner-primary", "fingerprint": "9a410a89bfde01f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8f19cc55ec52fc01", "level": "note", "message": {"text": "Legacy-named symbol `login_auth_legacy` in backend/api/auth.py:399"}, "properties": {"repobilityId": "7eeb8ee557796b83", "scanner": "scanner-primary", "fingerprint": "8f19cc55ec52fc01", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-16af5735f60e7e61", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/api/settings.py:305"}, "properties": {"repobilityId": "ffd82c064ffbf52e", "scanner": "scanner-primary", "fingerprint": "16af5735f60e7e61", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-121e7d952e9ea53c", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/api/channels.py:389"}, "properties": {"repobilityId": "24544fd4c91acb86", "scanner": "scanner-primary", "fingerprint": "121e7d952e9ea53c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-45b6b7dc685aa29d", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/scheduled_manager.py:22"}, "properties": {"repobilityId": "b157b1c1687b68c9", "scanner": "scanner-primary", "fingerprint": "45b6b7dc685aa29d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0e5142de796fcb63", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/download_manager.py:39"}, "properties": {"repobilityId": "b645e2379142475b", "scanner": "scanner-primary", "fingerprint": "0e5142de796fcb63", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-825c9afba71db592", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/hls_streamer.py:191"}, "properties": {"repobilityId": "8cfa14383286fae9", "scanner": "scanner-primary", "fingerprint": "825c9afba71db592", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e918b12475f4d36a", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/epg_ingest_manager.py:36"}, "properties": {"repobilityId": "fd5613a2493baada", "scanner": "scanner-primary", "fingerprint": "e918b12475f4d36a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b93f5249d85fbb7b", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/download_builder.py:90"}, "properties": {"repobilityId": "12c2aa75261732dc", "scanner": "scanner-primary", "fingerprint": "b93f5249d85fbb7b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "82e6f598c8abd2ad", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "4bb7b606cfa721ad", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "4af6d54722999b96", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "e985a0af1b099f5c", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "c2f9ff4bec5e649b", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "b28dd21979be6fbe", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "a3c80155c937ae5d", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "a1c7c88ebc40474f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "2563a3d6e8c1c75d", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-8cfe7c8aed20a718", "level": "warning", "message": {"text": "Frontend route `/accounts` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "d401f2323d41a957", "scanner": "scanner-primary", "fingerprint": "8cfe7c8aed20a718", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-2be4ec6e20969bbf", "level": "warning", "message": {"text": "Frontend route `/logs` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "92f31dfbc3e90138", "scanner": "scanner-primary", "fingerprint": "2be4ec6e20969bbf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-5ddca1ac2dc97a5e", "level": "warning", "message": {"text": "Frontend route `/downloads/:downloadId/play` has no Link/navigate to it \u2014 frontend/src/pages/DownloadPlayer.test.jsx"}, "properties": {"repobilityId": "e1e3cd8674a76a5e", "scanner": "scanner-primary", "fingerprint": "5ddca1ac2dc97a5e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-62093ca58510b5b3", "level": "error", "message": {"text": "Dangling fetch: GET /downloads/failed-count${params} (frontend/src/api.js:137)"}, "properties": {"repobilityId": "1fcf0046122b1020", "scanner": "scanner-primary", "fingerprint": "62093ca58510b5b3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-da70dcbb11af892c", "level": "error", "message": {"text": "Dangling fetch: GET /settings (frontend/src/api.js:176)"}, "properties": {"repobilityId": "4b661c8531974e05", "scanner": "scanner-primary", "fingerprint": "da70dcbb11af892c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1c0701e2c1ee8caf", "level": "error", "message": {"text": "Dangling fetch: GET /settings/public (frontend/src/api.js:177)"}, "properties": {"repobilityId": "82dc53a822e1a3e1", "scanner": "scanner-primary", "fingerprint": "1c0701e2c1ee8caf", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ac293631ae7948e6", "level": "error", "message": {"text": "Dangling fetch: PUT /settings (frontend/src/api.js:178)"}, "properties": {"repobilityId": "8557a1025e7561d2", "scanner": "scanner-primary", "fingerprint": "ac293631ae7948e6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-45ba699e8b7d7a2a", "level": "error", "message": {"text": "Dangling fetch: GET /settings/templates (frontend/src/api.js:179)"}, "properties": {"repobilityId": "54520ff8615a3ff3", "scanner": "scanner-primary", "fingerprint": "45ba699e8b7d7a2a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5eb7ef591b07f2e7", "level": "error", "message": {"text": "Dangling fetch: GET /settings/tools (frontend/src/api.js:180)"}, "properties": {"repobilityId": "5726fb1b2883af3a", "scanner": "scanner-primary", "fingerprint": "5eb7ef591b07f2e7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0271a2108c5eaf92", "level": "error", "message": {"text": "Dangling fetch: GET /settings/folders/status (frontend/src/api.js:181)"}, "properties": {"repobilityId": "25858812a5101388", "scanner": "scanner-primary", "fingerprint": "0271a2108c5eaf92", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ddbb964388fdea85", "level": "error", "message": {"text": "Dangling fetch: GET /auth/status (frontend/src/api.js:186)"}, "properties": {"repobilityId": "245460302830ee90", "scanner": "scanner-primary", "fingerprint": "ddbb964388fdea85", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-dfe2051d5ed65c32", "level": "error", "message": {"text": "Dangling fetch: GET /auth/admin-bootstrap/status (frontend/src/api.js:187)"}, "properties": {"repobilityId": "d09389afd8aacd21", "scanner": "scanner-primary", "fingerprint": "dfe2051d5ed65c32", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8b53926a6200a23c", "level": "error", "message": {"text": "Dangling fetch: POST /auth/admin-bootstrap/complete (frontend/src/api.js:189)"}, "properties": {"repobilityId": "b1bf697c796b7bf9", "scanner": "scanner-primary", "fingerprint": "8b53926a6200a23c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5614475e429654b0", "level": "error", "message": {"text": "Dangling fetch: POST /auth/setup (frontend/src/api.js:194)"}, "properties": {"repobilityId": "350c981579a55ef8", "scanner": "scanner-primary", "fingerprint": "5614475e429654b0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a13164f09d5cbddf", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login-credentials (frontend/src/api.js:196)"}, "properties": {"repobilityId": "a75e9d40ba3f2fde", "scanner": "scanner-primary", "fingerprint": "a13164f09d5cbddf", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d6a2e389c6819d01", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login (frontend/src/api.js:197)"}, "properties": {"repobilityId": "fc47c2a78598de44", "scanner": "scanner-primary", "fingerprint": "d6a2e389c6819d01", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-705dcb3ec554a43c", "level": "error", "message": {"text": "Dangling fetch: POST /auth/user/login (frontend/src/api.js:199)"}, "properties": {"repobilityId": "0698c51317ad04ab", "scanner": "scanner-primary", "fingerprint": "705dcb3ec554a43c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8780de408bbd7cf3", "level": "error", "message": {"text": "Dangling fetch: POST /auth/plex/login/start (frontend/src/api.js:200)"}, "properties": {"repobilityId": "a9bf4cfbbf3e9a43", "scanner": "scanner-primary", "fingerprint": "8780de408bbd7cf3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7def4e3d802c3a12", "level": "error", "message": {"text": "Dangling fetch: POST /auth/plex/login/complete (frontend/src/api.js:202)"}, "properties": {"repobilityId": "4d0aec78ff88ce18", "scanner": "scanner-primary", "fingerprint": "7def4e3d802c3a12", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-35337c40978fda1a", "level": "error", "message": {"text": "Dangling fetch: POST /auth/logout (frontend/src/api.js:203)"}, "properties": {"repobilityId": "abd140ae974efb8e", "scanner": "scanner-primary", "fingerprint": "35337c40978fda1a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-dd0820b78bc907e2", "level": "error", "message": {"text": "Dangling fetch: POST /auth/change-password (frontend/src/api.js:205)"}, "properties": {"repobilityId": "833557f6ac010599", "scanner": "scanner-primary", "fingerprint": "dd0820b78bc907e2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-69347e04cc81b975", "level": "error", "message": {"text": "Dangling fetch: GET /auth/preferences (frontend/src/api.js:209)"}, "properties": {"repobilityId": "ee1109b041d6cbe1", "scanner": "scanner-primary", "fingerprint": "69347e04cc81b975", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-14cfc81e50fdeb21", "level": "error", "message": {"text": "Dangling fetch: PUT /auth/preferences (frontend/src/api.js:211)"}, "properties": {"repobilityId": "1815c0564b14dc65", "scanner": "scanner-primary", "fingerprint": "14cfc81e50fdeb21", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4c9ce3af9baafd95", "level": "error", "message": {"text": "Dangling fetch: GET /auth/user/setup/${encodeURIComponent(token)} (frontend/src/api.js:212)"}, "properties": {"repobilityId": "ea1535df4f459b9f", "scanner": "scanner-primary", "fingerprint": "4c9ce3af9baafd95", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4e473faefc5f0e5e", "level": "error", "message": {"text": "Dangling fetch: POST /auth/user/setup/${encodeURIComponent(token)} (frontend/src/api.js:214)"}, "properties": {"repobilityId": "8ffc55886660db4f", "scanner": "scanner-primary", "fingerprint": "4e473faefc5f0e5e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9d579e7344bfa7e5", "level": "error", "message": {"text": "Dangling fetch: POST /admin/plex/server/test (frontend/src/api.js:237)"}, "properties": {"repobilityId": "46aa2b252b5390bd", "scanner": "scanner-primary", "fingerprint": "9d579e7344bfa7e5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f4b1b5b539bb9da7", "level": "error", "message": {"text": "Dangling fetch: GET /admin/plex/server/users (frontend/src/api.js:238)"}, "properties": {"repobilityId": "bf27b8ba6057d053", "scanner": "scanner-primary", "fingerprint": "f4b1b5b539bb9da7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "3c95aa69206af894", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1a6d91f2236825bf", "level": "note", "message": {"text": "Unused endpoint: ANY /"}, "properties": {"repobilityId": "9d7f3bdddbdb5896", "scanner": "scanner-primary", "fingerprint": "1a6d91f2236825bf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7704fa4b33201b51", "level": "note", "message": {"text": "Unused endpoint: ANY /{full_path:path}"}, "properties": {"repobilityId": "fd02cd8484c6a892", "scanner": "scanner-primary", "fingerprint": "7704fa4b33201b51", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-12590588bd560e15", "level": "note", "message": {"text": "Unused endpoint: GET /api/epg/search"}, "properties": {"repobilityId": "0bfbac43000a0a4f", "scanner": "scanner-primary", "fingerprint": "12590588bd560e15", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5949e36a46ad5d07", "level": "note", "message": {"text": "Unused endpoint: GET /csrf"}, "properties": {"repobilityId": "98a15aec17eb8f55", "scanner": "scanner-primary", "fingerprint": "5949e36a46ad5d07", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d18fe59c0e04d455", "level": "note", "message": {"text": "Unused endpoint: GET /admin-bootstrap/status"}, "properties": {"repobilityId": "e543749964a699b4", "scanner": "scanner-primary", "fingerprint": "d18fe59c0e04d455", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-05548e3a807cb1f1", "level": "note", "message": {"text": "Unused endpoint: POST /admin-bootstrap/complete"}, "properties": {"repobilityId": "739dc863b95b991c", "scanner": "scanner-primary", "fingerprint": "05548e3a807cb1f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb757797f6bd3444", "level": "note", "message": {"text": "Unused endpoint: POST /setup"}, "properties": {"repobilityId": "f88e063e4b80295e", "scanner": "scanner-primary", "fingerprint": "eb757797f6bd3444", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60a24ef6e57ba89b", "level": "note", "message": {"text": "Unused endpoint: POST /login-credentials"}, "properties": {"repobilityId": "7f7ca702485cbe99", "scanner": "scanner-primary", "fingerprint": "60a24ef6e57ba89b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "d8ae83a298978baf", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-06eb5909449c5de7", "level": "note", "message": {"text": "Unused endpoint: POST /user/login"}, "properties": {"repobilityId": "3ac5c4568bebcc08", "scanner": "scanner-primary", "fingerprint": "06eb5909449c5de7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac6b4917fce952cc", "level": "note", "message": {"text": "Unused endpoint: POST /plex/login/start"}, "properties": {"repobilityId": "f33b1c3b71c0b348", "scanner": "scanner-primary", "fingerprint": "ac6b4917fce952cc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cab4434ba6a1682a", "level": "note", "message": {"text": "Unused endpoint: POST /plex/login/complete"}, "properties": {"repobilityId": "f61dae340883199f", "scanner": "scanner-primary", "fingerprint": "cab4434ba6a1682a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "3974f6336d4d82ea", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4fe9bb486644f008", "level": "note", "message": {"text": "Unused endpoint: POST /change-password"}, "properties": {"repobilityId": "25ed65fb92eebe7d", "scanner": "scanner-primary", "fingerprint": "4fe9bb486644f008", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8764484f2d99e7b", "level": "note", "message": {"text": "Unused endpoint: GET /preferences"}, "properties": {"repobilityId": "6614399c25e56de7", "scanner": "scanner-primary", "fingerprint": "b8764484f2d99e7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b6f3e56a23ece9a", "level": "note", "message": {"text": "Unused endpoint: PUT /preferences"}, "properties": {"repobilityId": "6007b564a5e39581", "scanner": "scanner-primary", "fingerprint": "0b6f3e56a23ece9a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4c09dfb98247b83a", "level": "note", "message": {"text": "Unused endpoint: GET /user/setup/{token}"}, "properties": {"repobilityId": "a2b1ad72d818800b", "scanner": "scanner-primary", "fingerprint": "4c09dfb98247b83a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-036db92d819ac034", "level": "note", "message": {"text": "Unused endpoint: POST /user/setup/{token}"}, "properties": {"repobilityId": "a9eab570506656d3", "scanner": "scanner-primary", "fingerprint": "036db92d819ac034", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ce46577ac036074b", "level": "note", "message": {"text": "Unused endpoint: GET /api/downloads/failed-count"}, "properties": {"repobilityId": "306f255b6c9e5f4a", "scanner": "scanner-primary", "fingerprint": "ce46577ac036074b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2d0d8595a2282b8", "level": "note", "message": {"text": "Unused endpoint: GET /api/downloads/{download_id}/file"}, "properties": {"repobilityId": "9248827d308ba4fc", "scanner": "scanner-primary", "fingerprint": "b2d0d8595a2282b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-33840861cd8a64e8", "level": "note", "message": {"text": "Unused endpoint: GET /api/downloads/{download_id}/hls/{asset}"}, "properties": {"repobilityId": "83e74c55b548dc71", "scanner": "scanner-primary", "fingerprint": "33840861cd8a64e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "7a0602ef4db4e2d2", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-67d28fa8cd6bb12f", "level": "note", "message": {"text": "Unused endpoint: PUT /"}, "properties": {"repobilityId": "7238248543a9d29f", "scanner": "scanner-primary", "fingerprint": "67d28fa8cd6bb12f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-66d6e05669a99666", "level": "note", "message": {"text": "Unused endpoint: GET /folders/status"}, "properties": {"repobilityId": "65f01de83bbd7f1c", "scanner": "scanner-primary", "fingerprint": "66d6e05669a99666", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-017394171548a2b2", "level": "note", "message": {"text": "Unused endpoint: GET /templates"}, "properties": {"repobilityId": "5e9e4e79f4ede550", "scanner": "scanner-primary", "fingerprint": "017394171548a2b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-582b00fca2796501", "level": "note", "message": {"text": "Unused endpoint: GET /tools"}, "properties": {"repobilityId": "5937a24d3986b5a6", "scanner": "scanner-primary", "fingerprint": "582b00fca2796501", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6a42c52fea3345b5", "level": "note", "message": {"text": "Unused endpoint: GET /public"}, "properties": {"repobilityId": "72ecf0fcae93c7fe", "scanner": "scanner-primary", "fingerprint": "6a42c52fea3345b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4cc144b53db879ad", "level": "note", "message": {"text": "Unused endpoint: GET /api/logos"}, "properties": {"repobilityId": "f4e994b37943c2c1", "scanner": "scanner-primary", "fingerprint": "4cc144b53db879ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f03eb286a2475f92", "level": "note", "message": {"text": "Unused endpoint: GET /api/accounts/{account_id}/channels/{channel_id}/epg"}, "properties": {"repobilityId": "65328a320500b88e", "scanner": "scanner-primary", "fingerprint": "f03eb286a2475f92", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d1a30bee69c148c", "level": "note", "message": {"text": "Unused endpoint: GET /api/accounts/{account_id}/channels/{channel_id}/preview"}, "properties": {"repobilityId": "b4554ab2cb8e8d60", "scanner": "scanner-primary", "fingerprint": "8d1a30bee69c148c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}