{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-45fcf06a758fde14", "name": "Insecure pattern 'direct_innerhtml_assignment' in business.html:516", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in business.html:516"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aee3d7481bbae871", "name": "Insecure pattern 'direct_innerhtml_assignment' in admin.html:446", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in admin.html:446"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1072e08a6c8a1cf7", "name": "Possible secret in demo.html", "shortDescription": {"text": "Possible secret in demo.html"}, "fullDescription": {"text": "Detected pattern matching generic_api_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-dbaa79c576f001e7", "name": "Insecure pattern 'direct_innerhtml_assignment' in demo.html:878", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in demo.html:878"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9ba82e4312d817b", "name": "Possible secret in auth.js", "shortDescription": {"text": "Possible secret in auth.js"}, "fullDescription": {"text": "Detected pattern matching generic_api_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-560c9d13bc17adfd", "name": "Insecure pattern 'direct_innerhtml_assignment' in auth.js:72", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in auth.js:72"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/29598"}, "properties": {"repository": "sokainc/onecampus", "repoUrl": "https://github.com/sokainc/onecampus", "branch": "main"}, "results": [{"ruleId": "scanner-45fcf06a758fde14", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in business.html:516"}, "properties": {"repobilityId": "cb3416dd229ce85c", "scanner": "scanner-primary", "fingerprint": "45fcf06a758fde14", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "business.html"}, "region": {"startLine": 516}}}]}, {"ruleId": "scanner-aee3d7481bbae871", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in admin.html:446"}, "properties": {"repobilityId": "6ce12d2fb0d90b99", "scanner": "scanner-primary", "fingerprint": "aee3d7481bbae871", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "admin.html"}, "region": {"startLine": 446}}}]}, {"ruleId": "scanner-1072e08a6c8a1cf7", "level": "error", "message": {"text": "Possible secret in demo.html"}, "properties": {"repobilityId": "40ff9b906b812fd9", "scanner": "scanner-primary", "fingerprint": "1072e08a6c8a1cf7", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "demo.html"}, "region": {"startLine": 1925}}}]}, {"ruleId": "scanner-dbaa79c576f001e7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in demo.html:878"}, "properties": {"repobilityId": "6b68320339549820", "scanner": "scanner-primary", "fingerprint": "dbaa79c576f001e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "demo.html"}, "region": {"startLine": 878}}}]}, {"ruleId": "scanner-d9ba82e4312d817b", "level": "error", "message": {"text": "Possible secret in auth.js"}, "properties": {"repobilityId": "be55a9c5fef5019f", "scanner": "scanner-primary", "fingerprint": "d9ba82e4312d817b", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "auth.js"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-560c9d13bc17adfd", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in auth.js:72"}, "properties": {"repobilityId": "9550ca2f43615973", "scanner": "scanner-primary", "fingerprint": "560c9d13bc17adfd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "auth.js"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "b78c3f97a64bed9d", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "8758d4363915214e", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}]}]}