{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-b1445ac4b7d3431a", "name": "Possibly dead Python function: extract_markdown", "shortDescription": {"text": "Possibly dead Python function: extract_markdown"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a411d965b418960a", "name": "Possibly dead Python function: safe_fetch", "shortDescription": {"text": "Possibly dead Python function: safe_fetch"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f60804b208eb36f", "name": "Possibly dead Python function: image_to_pdf", "shortDescription": {"text": "Possibly dead Python function: image_to_pdf"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-885d313a56d18235", "name": "Possibly dead Python function: entities_pdf", "shortDescription": {"text": "Possibly dead Python function: entities_pdf"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7cf3d17260b2665", "name": "Possibly dead Python function: redact_pdf", "shortDescription": {"text": "Possibly dead Python function: redact_pdf"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7098d2059574b00", "name": "Possibly dead Python function: analyze", "shortDescription": {"text": "Possibly dead Python function: analyze"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51540e8483ff46f3", "name": "Possibly dead Python function: youtube_transcript_md", "shortDescription": {"text": "Possibly dead Python function: youtube_transcript_md"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91e396ebef8c2556", "name": "Possibly dead Python function: restore", "shortDescription": {"text": "Possibly dead Python function: restore"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7e9a41d2d6034af", "name": "Possibly dead Python function: anonymize", "shortDescription": {"text": "Possibly dead Python function: anonymize"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abb50705a18a5879", "name": "Possibly dead Python function: probe_duration", "shortDescription": {"text": "Possibly dead Python function: probe_duration"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3488a163c0e1a9d", "name": "Possibly dead Python function: transcribe_media", "shortDescription": {"text": "Possibly dead Python function: transcribe_media"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd65a94a9741f320", "name": "Possibly dead Python function: youtube_markdown", "shortDescription": {"text": "Possibly dead Python function: youtube_markdown"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-461587ad0ecea196", "name": "Possibly dead Python function: ocr_pdf", "shortDescription": {"text": "Possibly dead Python function: ocr_pdf"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-017c56dd002560d0", "name": "Possibly dead Python function: ocr_image", "shortDescription": {"text": "Possibly dead Python function: ocr_image"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de3c1f217d72a063", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6557e3bc2c9ef8a", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-353d82d5033e942c", "name": "Possible secret in entrypoint.sh", "shortDescription": {"text": "Possible secret in entrypoint.sh"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-61a838abc3838600", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/i18n.js:674", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/i18n.js:674"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fcf57cf5efbe9f7c", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/app.js:23", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/app.js:23"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72f22a8515e5d438", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9f8563726e2c42e", "name": "GitHub Action tracks a moving branch", "shortDescription": {"text": "GitHub Action tracks a moving branch"}, "fullDescription": {"text": "jlumbroso/free-disk-space@main can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce72207f6d6ea840", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b841c61fdfcff569", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-076b03a16e76601d", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b143871fd2a4d170", "name": "Very large file: app/static/app.js (1093 lines)", "shortDescription": {"text": "Very large file: app/static/app.js (1093 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-74e89b8d9b095c32", "name": "Very large file: docs/make_manual.py (833 lines)", "shortDescription": {"text": "Very large file: docs/make_manual.py (833 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 19 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 37 placeholder/mock markers across 8 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6525ecfbceac4efb", "name": "Commented-code block (5 lines) in app/ocr.py:52", "shortDescription": {"text": "Commented-code block (5 lines) in app/ocr.py:52"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-af022f937dd5b7fd", "name": "9 env vars used in code but missing from .env.example", "shortDescription": {"text": "9 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ANONIMAL_MAX_CHARS`, `ANON_HASH_KEY`, `APP_VERSION`, `EXTRACT_TIMEOUT`, `GEMINI_API_KEY`, `OPF_CHECKPOINT`, `OPF_DEVICE`, `REDIS_URL` + 1 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f9ea70a038fee79c", "name": "FastAPI POST `list_models` without auth dependency \u2014 app/main.py:385", "shortDescription": {"text": "FastAPI POST `list_models` without auth dependency \u2014 app/main.py:385"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d4b3f95258e1eb3", "name": "FastAPI POST `convert` without auth dependency \u2014 app/main.py:428", "shortDescription": {"text": "FastAPI POST `convert` without auth dependency \u2014 app/main.py:428"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5db14e90e6b8235a", "name": "FastAPI POST `validate_anon_rules` without auth dependency \u2014 app/main.py:671", "shortDescription": {"text": "FastAPI POST `validate_anon_rules` without auth dependency \u2014 app/main.py:671"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d9b2ea5bdd85ec3", "name": "FastAPI POST `redact_endpoint` without auth dependency \u2014 app/main.py:684", "shortDescription": {"text": "FastAPI POST `redact_endpoint` without auth dependency \u2014 app/main.py:684"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7d67b1e08236fe9", "name": "FastAPI POST `export_endpoint` without auth dependency \u2014 app/main.py:793", "shortDescription": {"text": "FastAPI POST `export_endpoint` without auth dependency \u2014 app/main.py:793"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3609937c8ab941d", "name": "FastAPI POST `compact_endpoint` without auth dependency \u2014 app/main.py:814", "shortDescription": {"text": "FastAPI POST `compact_endpoint` without auth dependency \u2014 app/main.py:814"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9e3045f1d76422d", "name": "FastAPI POST `chunk_endpoint` without auth dependency \u2014 app/main.py:824", "shortDescription": {"text": "FastAPI POST `chunk_endpoint` without auth dependency \u2014 app/main.py:824"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-afe75e14254e7ce7", "name": "FastAPI POST `anonymize` without auth dependency \u2014 anonimal/app.py:89", "shortDescription": {"text": "FastAPI POST `anonymize` without auth dependency \u2014 anonimal/app.py:89"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`app/main.py` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b03bc47738186741", "name": "Unused endpoint: POST /api/convert", "shortDescription": {"text": "Unused endpoint: POST /api/convert"}, "fullDescription": {"text": "`app/main.py` declares `POST /api/convert` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43be21c240d30a09", "name": "Unused endpoint: POST /api/compact", "shortDescription": {"text": "Unused endpoint: POST /api/compact"}, "fullDescription": {"text": "`app/main.py` declares `POST /api/compact` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1acc39fb884c9469", "name": "Unused endpoint: POST /api/chunk", "shortDescription": {"text": "Unused endpoint: POST /api/chunk"}, "fullDescription": {"text": "`app/main.py` declares `POST /api/chunk` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`app/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b87548f1fd08efb6", "name": "Unused endpoint: POST /anonymize", "shortDescription": {"text": "Unused endpoint: POST /anonymize"}, "fullDescription": {"text": "`anonimal/app.py` declares `POST /anonymize` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/25392"}, "properties": {"repository": "diegoparras/escriba", "repoUrl": "https://github.com/diegoparras/escriba", "branch": "main"}, "results": [{"ruleId": "scanner-b1445ac4b7d3431a", "level": "note", "message": {"text": "Possibly dead Python function: extract_markdown"}, "properties": {"repobilityId": "fdadb5a633aa888b", "scanner": "scanner-primary", "fingerprint": "b1445ac4b7d3431a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/odl.py:31"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a411d965b418960a", "level": "note", "message": {"text": "Possibly dead Python function: safe_fetch"}, "properties": {"repobilityId": "ccd42f7403c3ae8f", "scanner": "scanner-primary", "fingerprint": "a411d965b418960a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/security.py:72"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f60804b208eb36f", "level": "note", "message": {"text": "Possibly dead Python function: image_to_pdf"}, "properties": {"repobilityId": "b5bfbe2bf466505c", "scanner": "scanner-primary", "fingerprint": "1f60804b208eb36f", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/redact.py:31"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-885d313a56d18235", "level": "note", "message": {"text": "Possibly dead Python function: entities_pdf"}, "properties": {"repobilityId": "64d66d4134aaed98", "scanner": "scanner-primary", "fingerprint": "885d313a56d18235", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/redact.py:74"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7cf3d17260b2665", "level": "note", "message": {"text": "Possibly dead Python function: redact_pdf"}, "properties": {"repobilityId": "bbbfc7d0ffc05756", "scanner": "scanner-primary", "fingerprint": "d7cf3d17260b2665", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/redact.py:98"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7098d2059574b00", "level": "note", "message": {"text": "Possibly dead Python function: analyze"}, "properties": {"repobilityId": "5b48f818dd8bf4d5", "scanner": "scanner-primary", "fingerprint": "f7098d2059574b00", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/llmprep.py:145"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-51540e8483ff46f3", "level": "note", "message": {"text": "Possibly dead Python function: youtube_transcript_md"}, "properties": {"repobilityId": "de141fef062ff9ce", "scanner": "scanner-primary", "fingerprint": "51540e8483ff46f3", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py:245"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-91e396ebef8c2556", "level": "note", "message": {"text": "Possibly dead Python function: restore"}, "properties": {"repobilityId": "2a32744c5b0f8fd0", "scanner": "scanner-primary", "fingerprint": "91e396ebef8c2556", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/anonimal.py:182"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7e9a41d2d6034af", "level": "note", "message": {"text": "Possibly dead Python function: anonymize"}, "properties": {"repobilityId": "4e262424f720df86", "scanner": "scanner-primary", "fingerprint": "d7e9a41d2d6034af", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/anonimal.py:288"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-abb50705a18a5879", "level": "note", "message": {"text": "Possibly dead Python function: probe_duration"}, "properties": {"repobilityId": "e9ee4a103059f9d5", "scanner": "scanner-primary", "fingerprint": "abb50705a18a5879", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/transcribe.py:35"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3488a163c0e1a9d", "level": "note", "message": {"text": "Possibly dead Python function: transcribe_media"}, "properties": {"repobilityId": "5ce5313bd3aeb8bb", "scanner": "scanner-primary", "fingerprint": "b3488a163c0e1a9d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/transcribe.py:65"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dd65a94a9741f320", "level": "note", "message": {"text": "Possibly dead Python function: youtube_markdown"}, "properties": {"repobilityId": "b28ef90a2d452642", "scanner": "scanner-primary", "fingerprint": "dd65a94a9741f320", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/yt_transcript.py:214"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-461587ad0ecea196", "level": "note", "message": {"text": "Possibly dead Python function: ocr_pdf"}, "properties": {"repobilityId": "f87032a9302197a7", "scanner": "scanner-primary", "fingerprint": "461587ad0ecea196", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/ocr.py:46"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-017c56dd002560d0", "level": "note", "message": {"text": "Possibly dead Python function: ocr_image"}, "properties": {"repobilityId": "93d0ee2faf03f418", "scanner": "scanner-primary", "fingerprint": "017c56dd002560d0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/ocr.py:86"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-de3c1f217d72a063", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "1de0ecd007803dbd", "scanner": "scanner-primary", "fingerprint": "de3c1f217d72a063", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e6557e3bc2c9ef8a", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "d01c7516315da985", "scanner": "scanner-primary", "fingerprint": "e6557e3bc2c9ef8a", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "anonimal/Dockerfile"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-353d82d5033e942c", "level": "error", "message": {"text": "Possible secret in entrypoint.sh"}, "properties": {"repobilityId": "51f196d426871098", "scanner": "scanner-primary", "fingerprint": "353d82d5033e942c", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "entrypoint.sh"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-61a838abc3838600", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/i18n.js:674"}, "properties": {"repobilityId": "f4275221f41a16a1", "scanner": "scanner-primary", "fingerprint": "61a838abc3838600", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/i18n.js"}, "region": {"startLine": 674}}}]}, {"ruleId": "scanner-fcf57cf5efbe9f7c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/app.js:23"}, "properties": {"repobilityId": "69c0843502513d0e", "scanner": "scanner-primary", "fingerprint": "fcf57cf5efbe9f7c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/app.js"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-72f22a8515e5d438", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5200663acdf45d17", "scanner": "scanner-primary", "fingerprint": "72f22a8515e5d438", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-e9f8563726e2c42e", "level": "error", "message": {"text": "GitHub Action tracks a moving branch"}, "properties": {"repobilityId": "bfe2f3a263832534", "scanner": "scanner-primary", "fingerprint": "e9f8563726e2c42e", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-72f22a8515e5d438", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cd4a0ba13f654201", "scanner": "scanner-primary", "fingerprint": "72f22a8515e5d438", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-72f22a8515e5d438", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b02ff2f0cde3f3c1", "scanner": "scanner-primary", "fingerprint": "72f22a8515e5d438", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-72f22a8515e5d438", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "147d251465a6a350", "scanner": "scanner-primary", "fingerprint": "72f22a8515e5d438", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-72f22a8515e5d438", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "df4cd2ea16df1ac7", "scanner": "scanner-primary", "fingerprint": "72f22a8515e5d438", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-ce72207f6d6ea840", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "e219df20432f4cd8", "scanner": "scanner-primary", "fingerprint": "ce72207f6d6ea840", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/anonimal-publish.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b841c61fdfcff569", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "83a185deafa37ffa", "scanner": "scanner-primary", "fingerprint": "b841c61fdfcff569", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-publish.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-b841c61fdfcff569", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "92a252f237fefd54", "scanner": "scanner-primary", "fingerprint": "b841c61fdfcff569", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-publish.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-b841c61fdfcff569", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9865da7d2b2ff924", "scanner": "scanner-primary", "fingerprint": "b841c61fdfcff569", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-publish.yml"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-b841c61fdfcff569", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "3ced3a497e6628d3", "scanner": "scanner-primary", "fingerprint": "b841c61fdfcff569", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-publish.yml"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-b841c61fdfcff569", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "81e5f06397892af9", "scanner": "scanner-primary", "fingerprint": "b841c61fdfcff569", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-publish.yml"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-076b03a16e76601d", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "a42462ccbe3d06f2", "scanner": "scanner-primary", "fingerprint": "076b03a16e76601d", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker-publish.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b143871fd2a4d170", "level": "note", "message": {"text": "Very large file: app/static/app.js (1093 lines)"}, "properties": {"repobilityId": "857e0a34a0bf0a91", "scanner": "scanner-primary", "fingerprint": "b143871fd2a4d170", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-74e89b8d9b095c32", "level": "note", "message": {"text": "Very large file: docs/make_manual.py (833 lines)"}, "properties": {"repobilityId": "9f3f8cb84e2d1cc7", "scanner": "scanner-primary", "fingerprint": "74e89b8d9b095c32", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "3ed59df086c20248", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "29ecc919bf33db75", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "a93a0bfd98246531", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-6525ecfbceac4efb", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/ocr.py:52"}, "properties": {"repobilityId": "60b1551f001bd1cd", "scanner": "scanner-primary", "fingerprint": "6525ecfbceac4efb", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-af022f937dd5b7fd", "level": "note", "message": {"text": "9 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "5597384795dea7a4", "scanner": "scanner-primary", "fingerprint": "af022f937dd5b7fd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-f9ea70a038fee79c", "level": "error", "message": {"text": "FastAPI POST `list_models` without auth dependency \u2014 app/main.py:385"}, "properties": {"repobilityId": "a5905dd8404749bf", "scanner": "scanner-primary", "fingerprint": "f9ea70a038fee79c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 385}}}]}, {"ruleId": "scanner-7d4b3f95258e1eb3", "level": "error", "message": {"text": "FastAPI POST `convert` without auth dependency \u2014 app/main.py:428"}, "properties": {"repobilityId": "8709f5e7f35bc2c1", "scanner": "scanner-primary", "fingerprint": "7d4b3f95258e1eb3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 428}}}]}, {"ruleId": "scanner-5db14e90e6b8235a", "level": "error", "message": {"text": "FastAPI POST `validate_anon_rules` without auth dependency \u2014 app/main.py:671"}, "properties": {"repobilityId": "d788252f05aa0780", "scanner": "scanner-primary", "fingerprint": "5db14e90e6b8235a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 671}}}]}, {"ruleId": "scanner-7d9b2ea5bdd85ec3", "level": "error", "message": {"text": "FastAPI POST `redact_endpoint` without auth dependency \u2014 app/main.py:684"}, "properties": {"repobilityId": "d9b50b580235ea21", "scanner": "scanner-primary", "fingerprint": "7d9b2ea5bdd85ec3", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 684}}}]}, {"ruleId": "scanner-d7d67b1e08236fe9", "level": "error", "message": {"text": "FastAPI POST `export_endpoint` without auth dependency \u2014 app/main.py:793"}, "properties": {"repobilityId": "de4f4c04491b303e", "scanner": "scanner-primary", "fingerprint": "d7d67b1e08236fe9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 793}}}]}, {"ruleId": "scanner-b3609937c8ab941d", "level": "error", "message": {"text": "FastAPI POST `compact_endpoint` without auth dependency \u2014 app/main.py:814"}, "properties": {"repobilityId": "36b27eefebfb6400", "scanner": "scanner-primary", "fingerprint": "b3609937c8ab941d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 814}}}]}, {"ruleId": "scanner-f9e3045f1d76422d", "level": "error", "message": {"text": "FastAPI POST `chunk_endpoint` without auth dependency \u2014 app/main.py:824"}, "properties": {"repobilityId": "84a3cb58d04978ed", "scanner": "scanner-primary", "fingerprint": "f9e3045f1d76422d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 824}}}]}, {"ruleId": "scanner-afe75e14254e7ce7", "level": "error", "message": {"text": "FastAPI POST `anonymize` without auth dependency \u2014 anonimal/app.py:89"}, "properties": {"repobilityId": "c0de8a0e4bee2f26", "scanner": "scanner-primary", "fingerprint": "afe75e14254e7ce7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "anonimal/app.py"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "8c4331603b2f737d", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b03bc47738186741", "level": "note", "message": {"text": "Unused endpoint: POST /api/convert"}, "properties": {"repobilityId": "6195e82486283085", "scanner": "scanner-primary", "fingerprint": "b03bc47738186741", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43be21c240d30a09", "level": "note", "message": {"text": "Unused endpoint: POST /api/compact"}, "properties": {"repobilityId": "faf1f8fae155b422", "scanner": "scanner-primary", "fingerprint": "43be21c240d30a09", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1acc39fb884c9469", "level": "note", "message": {"text": "Unused endpoint: POST /api/chunk"}, "properties": {"repobilityId": "4699c5589e18d588", "scanner": "scanner-primary", "fingerprint": "1acc39fb884c9469", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "d8721f71fae1e2af", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b87548f1fd08efb6", "level": "note", "message": {"text": "Unused endpoint: POST /anonymize"}, "properties": {"repobilityId": "b692c58aab1207c0", "scanner": "scanner-primary", "fingerprint": "b87548f1fd08efb6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}