{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-5f6803475d083186", "name": "Stray `console.log` in TS/JS \u2014 client/App.js:863", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 client/App.js:863"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-614de364854e40ec", "name": "Stray `console.log` in TS/JS \u2014 client/scripts/patch-web-html.js:133", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 client/scripts/patch-web-html.js:133"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec80c14568dc77d8", "name": "Stray `console.log` in TS/JS \u2014 shared/ai/bot-api.js:270", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 shared/ai/bot-api.js:270"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a3e33ec5493a6d2", "name": "Stray `console.log` in TS/JS \u2014 shared/ai/bots/loader.js:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 shared/ai/bots/loader.js:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7fadca1bdb12b289", "name": "Stray `console.log` in TS/JS \u2014 backend/test-game.js:5", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/test-game.js:5"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-08a96b78af61264a", "name": "Stray `console.log` in TS/JS \u2014 backend/src/server.js:120", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/server.js:120"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-164b5439cbd2c873", "name": "Stray `console.log` in TS/JS \u2014 backend/src/socket/gameManager.js:399", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/socket/gameManager.js:399"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25793675869c22a7", "name": "Insecure pattern 'cors_wildcard' in backend/src/server.js:105", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in backend/src/server.js:105"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89ef0ad8ae3fb66b", "name": "Very large file: client/App.js (5658 lines)", "shortDescription": {"text": "Very large file: client/App.js (5658 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-73ff42a7e14a3b64", "name": "Very large file: shared/ai/ai-engine.js (2254 lines)", "shortDescription": {"text": "Very large file: shared/ai/ai-engine.js (2254 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4db9284267c1aacd", "name": "Very large file: shared/ai/ai-expert.js (1314 lines)", "shortDescription": {"text": "Very large file: shared/ai/ai-expert.js (1314 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb4acb9b955794af", "name": "Very large file: shared/ai/bots/opus_4_8_high/bot.js (1544 lines)", "shortDescription": {"text": "Very large file: shared/ai/bots/opus_4_8_high/bot.js (1544 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fdd3b4b01fd708d2", "name": "Very large file: shared/ai/bots/sonnet_4_6_medium/bot.js (1519 lines)", "shortDescription": {"text": "Very large file: shared/ai/bots/sonnet_4_6_medium/bot.js (1519 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a1b95138ba793fb", "name": "Very large file: shared/ai/bots/rabbit/bot.js (1390 lines)", "shortDescription": {"text": "Very large file: shared/ai/bots/rabbit/bot.js (1390 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "1 test file(s) for 45 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 50 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: ci, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing ci, tests, operator-readme. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8a61701adacc12df", "name": "`fetch()` without try/.catch or AbortSignal \u2014 client/App.js:634", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 client/App.js:634"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a9f31fa16a294db0", "name": "Commented-code block (6 lines) in shared/ai/ai-engine.js:375", "shortDescription": {"text": "Commented-code block (6 lines) in shared/ai/ai-engine.js:375"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4310569d1570224f", "name": "Commented-code block (6 lines) in shared/ai/ai-tactical-core.js:110", "shortDescription": {"text": "Commented-code block (6 lines) in shared/ai/ai-tactical-core.js:110"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-09ef2c0fd1585ca7", "name": "Commented-code block (5 lines) in shared/ai/ai-expert.js:720", "shortDescription": {"text": "Commented-code block (5 lines) in shared/ai/ai-expert.js:720"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1bef94b0299dc6ee", "name": "Legacy-named symbol `distOld` in shared/ai/ai-beliefs.js:284", "shortDescription": {"text": "Legacy-named symbol `distOld` in shared/ai/ai-beliefs.js:284"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4025c9f39d827436", "name": "Commented-code block (8 lines) in shared/ai/ai-beliefs.js:24", "shortDescription": {"text": "Commented-code block (8 lines) in shared/ai/ai-beliefs.js:24"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-64c373402a280fb7", "name": "Commented-code block (5 lines) in shared/ai/bots/gemini_3_1_pro/bot.js:521", "shortDescription": {"text": "Commented-code block (5 lines) in shared/ai/bots/gemini_3_1_pro/bot.js:521"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e269343378186ab1", "name": "Commented-code block (6 lines) in shared/ai/bots/opus_4_8_high/bot.js:74", "shortDescription": {"text": "Commented-code block (6 lines) in shared/ai/bots/opus_4_8_high/bot.js:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7c42236375abc29f", "name": "Legacy-named symbol `dOld` in shared/ai/bots/grok_apex/bot.js:286", "shortDescription": {"text": "Legacy-named symbol `dOld` in shared/ai/bots/grok_apex/bot.js:286"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39aa3f5efceee725", "name": "Commented-code block (6 lines) in shared/ai/bots/grok_apex/bot.js:108", "shortDescription": {"text": "Commented-code block (6 lines) in shared/ai/bots/grok_apex/bot.js:108"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b1fecf3ae4bf49e8", "name": "Legacy-named symbol `dOld` in shared/ai/bots/sonnet_4_6_medium/bot.js:302", "shortDescription": {"text": "Legacy-named symbol `dOld` in shared/ai/bots/sonnet_4_6_medium/bot.js:302"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18181feb22dfee79", "name": "Commented-code block (6 lines) in shared/ai/bots/opus_4_7_flash/bot.js:147", "shortDescription": {"text": "Commented-code block (6 lines) in shared/ai/bots/opus_4_7_flash/bot.js:147"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0939d208cbb83a67", "name": "Commented-code block (6 lines) in shared/ai/bots/composer_2_5/bot.js:141", "shortDescription": {"text": "Commented-code block (6 lines) in shared/ai/bots/composer_2_5/bot.js:141"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-552ac1450893a231", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/controllers/auth.js:126", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/controllers/auth.js:126"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-319e66a630e14977", "name": "2 env vars used in code but missing from .env.example", "shortDescription": {"text": "2 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `API_URL`, `PLATFORM`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1af52515513e0276", "name": "Unused endpoint: GET /api/v2/health", "shortDescription": {"text": "Unused endpoint: GET /api/v2/health"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api/v2/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0eaee304fc9c7507", "name": "Unused endpoint: GET /api/v2/auth/google", "shortDescription": {"text": "Unused endpoint: GET /api/v2/auth/google"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api/v2/auth/google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccdfe8e9920b4879", "name": "Unused endpoint: GET /api/v2/auth/google/callback", "shortDescription": {"text": "Unused endpoint: GET /api/v2/auth/google/callback"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api/v2/auth/google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-392dcbd9c0e4ed85", "name": "Unused endpoint: GET /auth/google/callback", "shortDescription": {"text": "Unused endpoint: GET /auth/google/callback"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /auth/google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb0e1f155831d18b", "name": "Unused endpoint: GET /api/v2/auth/dev", "shortDescription": {"text": "Unused endpoint: GET /api/v2/auth/dev"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api/v2/auth/dev` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7fc3df8ad769e6a6", "name": "Unused endpoint: POST /api/v2/auth/refresh", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/refresh"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd8adbad6ca236da", "name": "Unused endpoint: GET /api/v2/auth/status", "shortDescription": {"text": "Unused endpoint: GET /api/v2/auth/status"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api/v2/auth/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab1ce03c153413e8", "name": "Unused endpoint: POST /api/v2/auth/mint-token", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/mint-token"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/mint-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b92a155ea1b65c4", "name": "Unused endpoint: GET /api/v2/profile", "shortDescription": {"text": "Unused endpoint: GET /api/v2/profile"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /api/v2/profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55f7ed87156f8384", "name": "Unused endpoint: POST /api/v2/stats/update", "shortDescription": {"text": "Unused endpoint: POST /api/v2/stats/update"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/stats/update` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d551604b0107396", "name": "Unused endpoint: POST /api/v2/stats/reset-tournament", "shortDescription": {"text": "Unused endpoint: POST /api/v2/stats/reset-tournament"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/stats/reset-tournament` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c24db6186ea119fb", "name": "Unused endpoint: POST /api/v2/auth/google-native", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/google-native"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/google-native` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9bca773ea36f91d9", "name": "Unused endpoint: POST /api/v2/auth/vk", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/vk"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/vk` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d429697078814769", "name": "Unused endpoint: POST /api/v2/auth/facebook", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/facebook"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/facebook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cbef220ad3c773b", "name": "Unused endpoint: POST /api/v2/auth/yandex", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/yandex"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/yandex` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c05db8fa5f9fe552", "name": "Unused endpoint: POST /api/v2/auth/guest", "shortDescription": {"text": "Unused endpoint: POST /api/v2/auth/guest"}, "fullDescription": {"text": "`backend/src/server.js` declares `POST /api/v2/auth/guest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9a65f1dde230ca2", "name": "Unused endpoint: USE /js/bots", "shortDescription": {"text": "Unused endpoint: USE /js/bots"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /js/bots` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b76bd843cc8a2ce", "name": "Unused endpoint: USE /v2/js/bots", "shortDescription": {"text": "Unused endpoint: USE /v2/js/bots"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /v2/js/bots` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b82f2c3c8954bf1c", "name": "Unused endpoint: USE /docs", "shortDescription": {"text": "Unused endpoint: USE /docs"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f02a079c69b52f2d", "name": "Unused endpoint: USE /", "shortDescription": {"text": "Unused endpoint: USE /"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-013d6bbad52219f0", "name": "Unused endpoint: USE /v2", "shortDescription": {"text": "Unused endpoint: USE /v2"}, "fullDescription": {"text": "`backend/src/server.js` declares `USE /v2` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a51d843623ed11f", "name": "Unused endpoint: GET /v2/*", "shortDescription": {"text": "Unused endpoint: GET /v2/*"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /v2/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a7da4485ffd5140", "name": "Unused endpoint: GET /*", "shortDescription": {"text": "Unused endpoint: GET /*"}, "fullDescription": {"text": "`backend/src/server.js` declares `GET /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/20032"}, "properties": {"repository": "soufee/rps-battle", "repoUrl": "https://github.com/soufee/rps-battle", "branch": "main"}, "results": [{"ruleId": "scanner-5f6803475d083186", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 client/App.js:863"}, "properties": {"repobilityId": "349cfff72930ca36", "scanner": "scanner-primary", "fingerprint": "5f6803475d083186", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-614de364854e40ec", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 client/scripts/patch-web-html.js:133"}, "properties": {"repobilityId": "e572e0dfc1c01902", "scanner": "scanner-primary", "fingerprint": "614de364854e40ec", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ec80c14568dc77d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 shared/ai/bot-api.js:270"}, "properties": {"repobilityId": "6174a4645bc823fc", "scanner": "scanner-primary", "fingerprint": "ec80c14568dc77d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5a3e33ec5493a6d2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 shared/ai/bots/loader.js:48"}, "properties": {"repobilityId": "2ac7909a79c05090", "scanner": "scanner-primary", "fingerprint": "5a3e33ec5493a6d2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7fadca1bdb12b289", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/test-game.js:5"}, "properties": {"repobilityId": "c6b11c7ee94212da", "scanner": "scanner-primary", "fingerprint": "7fadca1bdb12b289", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-08a96b78af61264a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/server.js:120"}, "properties": {"repobilityId": "d7f22f465aadd584", "scanner": "scanner-primary", "fingerprint": "08a96b78af61264a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-164b5439cbd2c873", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/socket/gameManager.js:399"}, "properties": {"repobilityId": "2027da18e9000b0b", "scanner": "scanner-primary", "fingerprint": "164b5439cbd2c873", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-25793675869c22a7", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in backend/src/server.js:105"}, "properties": {"repobilityId": "228d2a37764ba7ad", "scanner": "scanner-primary", "fingerprint": "25793675869c22a7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/src/server.js"}, "region": {"startLine": 105}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-89ef0ad8ae3fb66b", "level": "note", "message": {"text": "Very large file: client/App.js (5658 lines)"}, "properties": {"repobilityId": "284fa6cc18de50de", "scanner": "scanner-primary", "fingerprint": "89ef0ad8ae3fb66b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-73ff42a7e14a3b64", "level": "note", "message": {"text": "Very large file: shared/ai/ai-engine.js (2254 lines)"}, "properties": {"repobilityId": "3f790662f57576ee", "scanner": "scanner-primary", "fingerprint": "73ff42a7e14a3b64", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4db9284267c1aacd", "level": "note", "message": {"text": "Very large file: shared/ai/ai-expert.js (1314 lines)"}, "properties": {"repobilityId": "e9dad161c03ed9de", "scanner": "scanner-primary", "fingerprint": "4db9284267c1aacd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-bb4acb9b955794af", "level": "note", "message": {"text": "Very large file: shared/ai/bots/opus_4_8_high/bot.js (1544 lines)"}, "properties": {"repobilityId": "180d435ccfae7c66", "scanner": "scanner-primary", "fingerprint": "bb4acb9b955794af", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-fdd3b4b01fd708d2", "level": "note", "message": {"text": "Very large file: shared/ai/bots/sonnet_4_6_medium/bot.js (1519 lines)"}, "properties": {"repobilityId": "9bf207b98d472b35", "scanner": "scanner-primary", "fingerprint": "fdd3b4b01fd708d2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6a1b95138ba793fb", "level": "note", "message": {"text": "Very large file: shared/ai/bots/rabbit/bot.js (1390 lines)"}, "properties": {"repobilityId": "28627f2bd6482d02", "scanner": "scanner-primary", "fingerprint": "6a1b95138ba793fb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "de984486340c2461", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "08ef7e8543797f16", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "8b5bbfaf107a79d7", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "0444e0f691c2e73b", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "4ac5b985d101e9c3", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "257771ebd9d32a00", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "98a472ee194cf2a4", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8a61701adacc12df", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 client/App.js:634"}, "properties": {"repobilityId": "2fa947553069960f", "scanner": "scanner-primary", "fingerprint": "8a61701adacc12df", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a9f31fa16a294db0", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/ai/ai-engine.js:375"}, "properties": {"repobilityId": "70d8479b465d15cf", "scanner": "scanner-primary", "fingerprint": "a9f31fa16a294db0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4310569d1570224f", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/ai/ai-tactical-core.js:110"}, "properties": {"repobilityId": "5405457e681d9f89", "scanner": "scanner-primary", "fingerprint": "4310569d1570224f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-09ef2c0fd1585ca7", "level": "none", "message": {"text": "Commented-code block (5 lines) in shared/ai/ai-expert.js:720"}, "properties": {"repobilityId": "9b90ccee40ebf9f6", "scanner": "scanner-primary", "fingerprint": "09ef2c0fd1585ca7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1bef94b0299dc6ee", "level": "note", "message": {"text": "Legacy-named symbol `distOld` in shared/ai/ai-beliefs.js:284"}, "properties": {"repobilityId": "225cb975f6c31e3a", "scanner": "scanner-primary", "fingerprint": "1bef94b0299dc6ee", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4025c9f39d827436", "level": "none", "message": {"text": "Commented-code block (8 lines) in shared/ai/ai-beliefs.js:24"}, "properties": {"repobilityId": "e8bfb9891d723c73", "scanner": "scanner-primary", "fingerprint": "4025c9f39d827436", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-64c373402a280fb7", "level": "none", "message": {"text": "Commented-code block (5 lines) in shared/ai/bots/gemini_3_1_pro/bot.js:521"}, "properties": {"repobilityId": "feb69596d0d10332", "scanner": "scanner-primary", "fingerprint": "64c373402a280fb7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e269343378186ab1", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/ai/bots/opus_4_8_high/bot.js:74"}, "properties": {"repobilityId": "87ec854821d90129", "scanner": "scanner-primary", "fingerprint": "e269343378186ab1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7c42236375abc29f", "level": "note", "message": {"text": "Legacy-named symbol `dOld` in shared/ai/bots/grok_apex/bot.js:286"}, "properties": {"repobilityId": "6fd95621edc07d35", "scanner": "scanner-primary", "fingerprint": "7c42236375abc29f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-39aa3f5efceee725", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/ai/bots/grok_apex/bot.js:108"}, "properties": {"repobilityId": "5a9ce875b5080ac6", "scanner": "scanner-primary", "fingerprint": "39aa3f5efceee725", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b1fecf3ae4bf49e8", "level": "note", "message": {"text": "Legacy-named symbol `dOld` in shared/ai/bots/sonnet_4_6_medium/bot.js:302"}, "properties": {"repobilityId": "528392e92e214864", "scanner": "scanner-primary", "fingerprint": "b1fecf3ae4bf49e8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-18181feb22dfee79", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/ai/bots/opus_4_7_flash/bot.js:147"}, "properties": {"repobilityId": "b9f953eb88b040cd", "scanner": "scanner-primary", "fingerprint": "18181feb22dfee79", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0939d208cbb83a67", "level": "none", "message": {"text": "Commented-code block (6 lines) in shared/ai/bots/composer_2_5/bot.js:141"}, "properties": {"repobilityId": "4e4eb97bc063971b", "scanner": "scanner-primary", "fingerprint": "0939d208cbb83a67", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-552ac1450893a231", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/src/controllers/auth.js:126"}, "properties": {"repobilityId": "99f85da3a49a3006", "scanner": "scanner-primary", "fingerprint": "552ac1450893a231", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-319e66a630e14977", "level": "none", "message": {"text": "2 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d838d1fc5d8231c9", "scanner": "scanner-primary", "fingerprint": "319e66a630e14977", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-1af52515513e0276", "level": "note", "message": {"text": "Unused endpoint: GET /api/v2/health"}, "properties": {"repobilityId": "2d595f7e1e3b0545", "scanner": "scanner-primary", "fingerprint": "1af52515513e0276", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0eaee304fc9c7507", "level": "note", "message": {"text": "Unused endpoint: GET /api/v2/auth/google"}, "properties": {"repobilityId": "2f02178a3a3bd768", "scanner": "scanner-primary", "fingerprint": "0eaee304fc9c7507", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ccdfe8e9920b4879", "level": "note", "message": {"text": "Unused endpoint: GET /api/v2/auth/google/callback"}, "properties": {"repobilityId": "bdddffb69136ad35", "scanner": "scanner-primary", "fingerprint": "ccdfe8e9920b4879", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-392dcbd9c0e4ed85", "level": "note", "message": {"text": "Unused endpoint: GET /auth/google/callback"}, "properties": {"repobilityId": "75a3a7ea76d344c3", "scanner": "scanner-primary", "fingerprint": "392dcbd9c0e4ed85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb0e1f155831d18b", "level": "note", "message": {"text": "Unused endpoint: GET /api/v2/auth/dev"}, "properties": {"repobilityId": "2266d409f0de2f80", "scanner": "scanner-primary", "fingerprint": "eb0e1f155831d18b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7fc3df8ad769e6a6", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/refresh"}, "properties": {"repobilityId": "5ae1b562548f6b8b", "scanner": "scanner-primary", "fingerprint": "7fc3df8ad769e6a6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd8adbad6ca236da", "level": "note", "message": {"text": "Unused endpoint: GET /api/v2/auth/status"}, "properties": {"repobilityId": "5fa116f780ed79a8", "scanner": "scanner-primary", "fingerprint": "dd8adbad6ca236da", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab1ce03c153413e8", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/mint-token"}, "properties": {"repobilityId": "4bda04e48438eb07", "scanner": "scanner-primary", "fingerprint": "ab1ce03c153413e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4b92a155ea1b65c4", "level": "note", "message": {"text": "Unused endpoint: GET /api/v2/profile"}, "properties": {"repobilityId": "4a6e78fda3076fdd", "scanner": "scanner-primary", "fingerprint": "4b92a155ea1b65c4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55f7ed87156f8384", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/stats/update"}, "properties": {"repobilityId": "2669bb9a47393b40", "scanner": "scanner-primary", "fingerprint": "55f7ed87156f8384", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1d551604b0107396", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/stats/reset-tournament"}, "properties": {"repobilityId": "813c3bb3ba2983a0", "scanner": "scanner-primary", "fingerprint": "1d551604b0107396", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c24db6186ea119fb", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/google-native"}, "properties": {"repobilityId": "e2e3f11c8af8a69c", "scanner": "scanner-primary", "fingerprint": "c24db6186ea119fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9bca773ea36f91d9", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/vk"}, "properties": {"repobilityId": "a62ff9411fa0dff4", "scanner": "scanner-primary", "fingerprint": "9bca773ea36f91d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d429697078814769", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/facebook"}, "properties": {"repobilityId": "cc4a1829c2a8e34f", "scanner": "scanner-primary", "fingerprint": "d429697078814769", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0cbef220ad3c773b", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/yandex"}, "properties": {"repobilityId": "ffea558c555b7491", "scanner": "scanner-primary", "fingerprint": "0cbef220ad3c773b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c05db8fa5f9fe552", "level": "note", "message": {"text": "Unused endpoint: POST /api/v2/auth/guest"}, "properties": {"repobilityId": "bad4b006de78f3fc", "scanner": "scanner-primary", "fingerprint": "c05db8fa5f9fe552", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e9a65f1dde230ca2", "level": "note", "message": {"text": "Unused endpoint: USE /js/bots"}, "properties": {"repobilityId": "8427a75a927d8687", "scanner": "scanner-primary", "fingerprint": "e9a65f1dde230ca2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b76bd843cc8a2ce", "level": "note", "message": {"text": "Unused endpoint: USE /v2/js/bots"}, "properties": {"repobilityId": "69d05f2bbbd910da", "scanner": "scanner-primary", "fingerprint": "7b76bd843cc8a2ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b82f2c3c8954bf1c", "level": "note", "message": {"text": "Unused endpoint: USE /docs"}, "properties": {"repobilityId": "3ecdec8b637d59d0", "scanner": "scanner-primary", "fingerprint": "b82f2c3c8954bf1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f02a079c69b52f2d", "level": "note", "message": {"text": "Unused endpoint: USE /"}, "properties": {"repobilityId": "22d1f0fb36181ff6", "scanner": "scanner-primary", "fingerprint": "f02a079c69b52f2d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-013d6bbad52219f0", "level": "note", "message": {"text": "Unused endpoint: USE /v2"}, "properties": {"repobilityId": "2d78ac0445c23283", "scanner": "scanner-primary", "fingerprint": "013d6bbad52219f0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a51d843623ed11f", "level": "note", "message": {"text": "Unused endpoint: GET /v2/*"}, "properties": {"repobilityId": "3362e42058268034", "scanner": "scanner-primary", "fingerprint": "9a51d843623ed11f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a7da4485ffd5140", "level": "note", "message": {"text": "Unused endpoint: GET /*"}, "properties": {"repobilityId": "cd99ac8ca66bb54b", "scanner": "scanner-primary", "fingerprint": "7a7da4485ffd5140", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}