{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_blueprint_gap", "name": "Foundry mined blueprint gap alignment: statyk/compendium", "shortDescription": {"text": "Foundry mined blueprint gap alignment: statyk/compendium"}, "fullDescription": {"text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#5\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: statyk/compendium\nThread: statyk/compendium#5\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#5\nRepo: statyk/compendium\nIssue/PR number: 5\nGraph consistency label: supported_by_verification_signal\nNodes: 46\nEdges: 75\nNode types: {'pr_file': 23, 'link_quality': 6, 'commit': 5, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'com"}, "properties": {"scanner": "foundry_dataset", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: statyk/compendium", "shortDescription": {"text": "Foundry mined assumption checks: statyk/compendium"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: statyk/compendium\nThread: statyk/compendium#3\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: statyk/compendium#3\nRepo: statyk/compendium\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 3\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 1\nLabels: {'data_schema_persistence': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'schema_or_data': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-55cd9648fe80fb7d\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"data_schema_persistence\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://g"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_test_ci_gap", "name": "Foundry mined test ci gap after feedback: statyk/compendium", "shortDescription": {"text": "Foundry mined test ci gap after feedback: statyk/compendium"}, "fullDescription": {"text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#4\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: statyk/compendium\nThread: statyk/compendium#4\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#4\nRepo: statyk/compendium\nIssue/PR number: 4\nGraph consistency label: supported_by_verification_signal\nNodes: 22\nEdges: 29\nNode types: {'link_quality': 6, 'commit': 3, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain'"}, "properties": {"scanner": "foundry_dataset", "category": "testing", "severity": "high", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "foundry_schema_ui_api_gap", "name": "Foundry mined schema ui api mismatch: statyk/compendium", "shortDescription": {"text": "Foundry mined schema ui api mismatch: statyk/compendium"}, "fullDescription": {"text": "Graph query export: Schema, UI, and API mismatch\nQuery id: schema_ui_api_mismatch\nQuery type: motif_query\nIntent: Assumption-check examples for data-path consistency across layers.\nMotif: schema_ui_api_mismatch\nTraining usage: assumption_check\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#5\nEvidence:\nGraph motif: Schema, UI, and API evidence do not line up\nMotif id: schema_ui_api_mismatch\nPolarity: bad\nTraining usage: assumption_check\nSeverity: high\nRepo: statyk/compendium\nThread: statyk/compendium#5\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#5\nRepo: statyk/compendium\nIssue/PR number: 5\nGraph consistency label: supported_by_verification_signal\nNodes: 46\nEdges: 75\nNode types: {'pr_file': 23, 'link_quality': 6, 'commit': 5, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_o"}, "properties": {"scanner": "foundry_dataset", "category": "quality", "severity": "high", "confidence": 0.76, "cwe": "", "owasp": ""}}, {"id": "scanner-4f7646511c281596", "name": "Possibly dead Python function: backup_command", "shortDescription": {"text": "Possibly dead Python function: backup_command"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f816a2ed4b70a04", "name": "Possibly dead Python function: restore_command", "shortDescription": {"text": "Possibly dead Python function: restore_command"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a3ae4b7cbebe199", "name": "Possibly dead Python function: init_command", "shortDescription": {"text": "Possibly dead Python function: init_command"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e13ff909c373c6d5", "name": "Possibly dead Python function: require_web_user", "shortDescription": {"text": "Possibly dead Python function: require_web_user"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0feee973f18913ad", "name": "Possibly dead Python function: require_scan_pairing", "shortDescription": {"text": "Possibly dead Python function: require_scan_pairing"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c583827fb1f85cd4", "name": "Possibly dead Python function: validate_google_books_key", "shortDescription": {"text": "Possibly dead Python function: validate_google_books_key"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b612662ceff78a5", "name": "Possibly dead Python function: list_users", "shortDescription": {"text": "Possibly dead Python function: list_users"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff9424fc7fb63063", "name": "Possibly dead Python function: render_patron_label_svg", "shortDescription": {"text": "Possibly dead Python function: render_patron_label_svg"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8def6db8dc5ff563", "name": "Stray `console.log` in TS/JS \u2014 src/compendium/web/static/htmx.min.js:1", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/compendium/web/static/htmx.min.js:1"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-254676044941d860", "name": "Stray `console.log` in TS/JS \u2014 src/compendium/web/static/zxing/zxing-browser.min.js:1", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/compendium/web/static/zxing/zxing-browser.min.js:1"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1224efb32b541d5f", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1fded96e36390b1e", "name": "Insecure pattern 'new_function_used' in src/compendium/web/static/htmx.min.js:1", "shortDescription": {"text": "Insecure pattern 'new_function_used' in src/compendium/web/static/htmx.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b5d7735b11cacb3", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/compendium/web/static/htmx.min.js:1", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/compendium/web/static/htmx.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15bc79657d4a5252", "name": "Insecure pattern 'insert_adjacent_html' in src/compendium/web/static/htmx.min.js:1", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in src/compendium/web/static/htmx.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-852106ed33dd3377", "name": "Insecure pattern 'domparser_html_parse' in src/compendium/web/static/htmx.min.js:1", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in src/compendium/web/static/htmx.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46c644c6227e4d4a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ee75beca21f4375", "name": "Very large file: tests/integration/test_web_ui.py (2001 lines)", "shortDescription": {"text": "Very large file: tests/integration/test_web_ui.py (2001 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9735d582720d9472", "name": "Very large file: tests/integration/test_cli_commands.py (1804 lines)", "shortDescription": {"text": "Very large file: tests/integration/test_cli_commands.py (1804 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e1d027f330f3df3", "name": "Very large file: tests/unit/test_labels_service.py (1758 lines)", "shortDescription": {"text": "Very large file: tests/unit/test_labels_service.py (1758 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-588d3dc8c99a2113", "name": "Very large file: src/compendium/services/catalog.py (1300 lines)", "shortDescription": {"text": "Very large file: src/compendium/services/catalog.py (1300 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8d6cba13bdeb51e", "name": "Very large file: src/compendium/services/import_export.py (1621 lines)", "shortDescription": {"text": "Very large file: src/compendium/services/import_export.py (1621 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 16 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3aec0d54b2c2ceb9", "name": "Commented-code block (6 lines) in tests/conftest.py:7", "shortDescription": {"text": "Commented-code block (6 lines) in tests/conftest.py:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3d7cc161c0fcbad7", "name": "Commented-code block (7 lines) in tests/integration/test_csp_inline_handlers.py:9", "shortDescription": {"text": "Commented-code block (7 lines) in tests/integration/test_csp_inline_handlers.py:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3467c9f64d7fc325", "name": "Legacy-named symbol `test_role_clone_creates_editable_copy` in tests/integration/test_web_ui.py:1558", "shortDescription": {"text": "Legacy-named symbol `test_role_clone_creates_editable_copy` in tests/integration/test_web_ui.py:1558"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e26414718aef706", "name": "Legacy-named symbol `test_no_stale_code128_default_copy` in tests/integration/test_labels_web.py:383", "shortDescription": {"text": "Legacy-named symbol `test_no_stale_code128_default_copy` in tests/integration/test_labels_web.py:383"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a9a737dc40eb52cd", "name": "Commented-code block (14 lines) in tests/integration/test_scan_web.py:387", "shortDescription": {"text": "Commented-code block (14 lines) in tests/integration/test_scan_web.py:387"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bb9a68bae151d72a", "name": "Legacy-named symbol `test_delete_older_than_noop_when_nothing_old` in tests/integration/test_audit_prune.py:75", "shortDescription": {"text": "Legacy-named symbol `test_delete_older_than_noop_when_nothing_old` in tests/integration/test_audit_prune.py:75"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8dade48f89f78a72", "name": "Legacy-named symbol `test_checkout_by_isbn_skips_checked_out_copy` in tests/integration/test_isbn_circulation.py:109", "shortDescription": {"text": "Legacy-named symbol `test_checkout_by_isbn_skips_checked_out_copy` in tests/integration/test_isbn_circulation.py:109"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a6f42618812c605", "name": "Legacy-named symbol `t_old` in tests/integration/test_item_note_model.py:82", "shortDescription": {"text": "Legacy-named symbol `t_old` in tests/integration/test_item_note_model.py:82"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f66d9e887ef3ba2f", "name": "Legacy-named symbol `test_add_item_to_work_adds_copy` in tests/integration/test_catalog.py:92", "shortDescription": {"text": "Legacy-named symbol `test_add_item_to_work_adds_copy` in tests/integration/test_catalog.py:92"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-74f8a2efb23264a5", "name": "Legacy-named symbol `added_copy` in tests/integration/test_import_export_api.py:217", "shortDescription": {"text": "Legacy-named symbol `added_copy` in tests/integration/test_import_export_api.py:217"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1466429ab0df23b0", "name": "Commented-code block (8 lines) in tests/integration/test_backup.py:382", "shortDescription": {"text": "Commented-code block (8 lines) in tests/integration/test_backup.py:382"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-52d0111c5bc077b5", "name": "Legacy-named symbol `test_place_hold_succeeds_with_one_loanable_copy` in tests/integration/test_holds.py:143", "shortDescription": {"text": "Legacy-named symbol `test_place_hold_succeeds_with_one_loanable_copy` in tests/integration/test_holds.py:143"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68a33c1a14a81b31", "name": "Legacy-named symbol `added_copy` in tests/integration/test_import_export_lt.py:146", "shortDescription": {"text": "Legacy-named symbol `added_copy` in tests/integration/test_import_export_lt.py:146"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-173b8c6f92e98807", "name": "Legacy-named symbol `ReturnOld` in tests/integration/test_discovery.py:209", "shortDescription": {"text": "Legacy-named symbol `ReturnOld` in tests/integration/test_discovery.py:209"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3c887bcfa83011b", "name": "Commented-code block (7 lines) in tests/unit/test_calendar_service.py:259", "shortDescription": {"text": "Commented-code block (7 lines) in tests/unit/test_calendar_service.py:259"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8eb013ba86cac20f", "name": "Legacy-named symbol `t_old` in tests/unit/test_item_note_repository.py:107", "shortDescription": {"text": "Legacy-named symbol `t_old` in tests/unit/test_item_note_repository.py:107"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-223bc8ea1d2d4042", "name": "Commented-code block (5 lines) in tests/unit/test_settings_registry.py:312", "shortDescription": {"text": "Commented-code block (5 lines) in tests/unit/test_settings_registry.py:312"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-62cf475cbf050d4e", "name": "Legacy-named symbol `available_copy` in tests/unit/test_hold_service.py:34", "shortDescription": {"text": "Legacy-named symbol `available_copy` in tests/unit/test_hold_service.py:34"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b69474471166866", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/render_label_matrix.py:71", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/render_label_matrix.py:71"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c5c74858fdfdb9bd", "name": "Commented-code block (5 lines) in src/compendium/api/app.py:212", "shortDescription": {"text": "Commented-code block (5 lines) in src/compendium/api/app.py:212"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4f581dc8b752619e", "name": "Stub function `_main` (body is just `pass`/`return`) \u2014 src/compendium/cli/main.py:51", "shortDescription": {"text": "Stub function `_main` (body is just `pass`/`return`) \u2014 src/compendium/cli/main.py:51"}, "fullDescription": {"text": "Likely an AI scaffold that was never filled in. Remove or implement."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27822964cb928051", "name": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/services/holds.py:125", "shortDescription": {"text": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/services/holds.py:125"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ed0e7386801c7ef", "name": "Legacy-named symbol `added_copy` in src/compendium/services/catalog.py:1063", "shortDescription": {"text": "Legacy-named symbol `added_copy` in src/compendium/services/catalog.py:1063"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5648d0a7bb58b17", "name": "Commented-code block (5 lines) in src/compendium/services/settings_registry.py:603", "shortDescription": {"text": "Commented-code block (5 lines) in src/compendium/services/settings_registry.py:603"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-40b8f72c0855bda1", "name": "Commented-code block (6 lines) in src/compendium/services/labels.py:35", "shortDescription": {"text": "Commented-code block (6 lines) in src/compendium/services/labels.py:35"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4e558c7d4539ff6e", "name": "Legacy-named symbol `added_copy` in src/compendium/services/import_export.py:509", "shortDescription": {"text": "Legacy-named symbol `added_copy` in src/compendium/services/import_export.py:509"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7e7d380b0eb9f07", "name": "Commented-code block (7 lines) in src/compendium/services/import_export.py:933", "shortDescription": {"text": "Commented-code block (7 lines) in src/compendium/services/import_export.py:933"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-615d0d920b7c4555", "name": "Commented-code block (6 lines) in src/compendium/db/engine.py:73", "shortDescription": {"text": "Commented-code block (6 lines) in src/compendium/db/engine.py:73"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5c503d19e29d264f", "name": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/repositories/base.py:99", "shortDescription": {"text": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/repositories/base.py:99"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e359b6430628a21", "name": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/repositories/sql/work_repository.py:97", "shortDescription": {"text": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/repositories/sql/work_repository.py:97"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af022f937dd5b7fd", "name": "9 env vars used in code but missing from .env.example", "shortDescription": {"text": "9 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `COMPENDIUM_ACTOR_USERNAME`, `COMPENDIUM_ALLOW_INSECURE_JWT`, `COMPENDIUM_COVER_CACHE_DIR`, `COMPENDIUM_DATABASE_URL`, `COMPENDIUM_MATRIX_ADMIN_PASS`, `COMPENDIUM_MATRIX_ADMIN_USER`, `COMPENDIUM_SCAFFOLD_DIR`, `COMPENDIUM_SECRET_KEY` + 1 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/compendium/api/deps.py:get_calendar_svc, src/compendium/web/deps.py:get_calendar_svc\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-02525d39071dd2c7", "name": "Near-duplicate function bodies in 5 places", "shortDescription": {"text": "Near-duplicate function bodies in 5 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/compendium/cli/commands/labels.py:spine_labels, src/compendium/cli/commands/labels.py:pocket_labels, src/compendium/cli/commands/labels.py:barcode_labels, src/compendium/cli/commands/labels.py:patron_card\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/compendium/web/routes/fines.py:verify_returned_confirm_form, src/compendium/web/routes/fines.py:verify_returned, src/compendium/web/routes/fines.py:write_off_claim_form, src/compendium/web/routes/fines.py:write_off_claim\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nsrc/compendium/web/routes/admin_settings.py:general_get, src/compendium/web/routes/admin_settings.py:circulation_get, src/compendium/web/routes/admin_settings.py:kiosk_get\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3dfabf5f2f85528", "name": "FastAPI POST `item_create_manual` without auth dependency \u2014 src/compendium/web/routes/items.py:288", "shortDescription": {"text": "FastAPI POST `item_create_manual` without auth dependency \u2014 src/compendium/web/routes/items.py:288"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-43be01f8ae79a04f", "name": "FastAPI POST `edit_pending_save` without auth dependency \u2014 src/compendium/web/routes/scan.py:890", "shortDescription": {"text": "FastAPI POST `edit_pending_save` without auth dependency \u2014 src/compendium/web/routes/scan.py:890"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e0603fba69ece6ab", "name": "FastAPI POST `work_edit_submit` without auth dependency \u2014 src/compendium/web/routes/catalog.py:380", "shortDescription": {"text": "FastAPI POST `work_edit_submit` without auth dependency \u2014 src/compendium/web/routes/catalog.py:380"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1766cc75c216eb78", "name": "FastAPI POST `import_submit` without auth dependency \u2014 src/compendium/web/routes/bulk.py:268", "shortDescription": {"text": "FastAPI POST `import_submit` without auth dependency \u2014 src/compendium/web/routes/bulk.py:268"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b74540c51150b206", "name": "FastAPI POST `user_create` without auth dependency \u2014 src/compendium/web/routes/users.py:129", "shortDescription": {"text": "FastAPI POST `user_create` without auth dependency \u2014 src/compendium/web/routes/users.py:129"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87c9737578d1c768", "name": "FastAPI POST `policy_update` without auth dependency \u2014 src/compendium/web/routes/policies.py:138", "shortDescription": {"text": "FastAPI POST `policy_update` without auth dependency \u2014 src/compendium/web/routes/policies.py:138"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a3b4e88e97505a34", "name": "FastAPI POST `patron_create` without auth dependency \u2014 src/compendium/web/routes/patrons.py:144", "shortDescription": {"text": "FastAPI POST `patron_create` without auth dependency \u2014 src/compendium/web/routes/patrons.py:144"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`src/compendium/api/routes/notifications.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da2ce8c5b380ae8b", "name": "Unused endpoint: POST /{notification_id}/retry", "shortDescription": {"text": "Unused endpoint: POST /{notification_id}/retry"}, "fullDescription": {"text": "`src/compendium/api/routes/notifications.py` declares `POST /{notification_id}/retry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b83ad31b50d48ece", "name": "Unused endpoint: GET /library-hours/", "shortDescription": {"text": "Unused endpoint: GET /library-hours/"}, "fullDescription": {"text": "`src/compendium/api/routes/calendar.py` declares `GET /library-hours/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd2d35e48e6019b8", "name": "Unused endpoint: PATCH /library-hours/{weekday}", "shortDescription": {"text": "Unused endpoint: PATCH /library-hours/{weekday}"}, "fullDescription": {"text": "`src/compendium/api/routes/calendar.py` declares `PATCH /library-hours/{weekday}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed47dca4e8069659", "name": "Unused endpoint: GET /closed-dates/", "shortDescription": {"text": "Unused endpoint: GET /closed-dates/"}, "fullDescription": {"text": "`src/compendium/api/routes/calendar.py` declares `GET /closed-dates/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47a30b46c4821bd6", "name": "Unused endpoint: POST /closed-dates/", "shortDescription": {"text": "Unused endpoint: POST /closed-dates/"}, "fullDescription": {"text": "`src/compendium/api/routes/calendar.py` declares `POST /closed-dates/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f4c319a9e792679", "name": "Unused endpoint: PATCH /closed-dates/{closed_date_id}", "shortDescription": {"text": "Unused endpoint: PATCH /closed-dates/{closed_date_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/calendar.py` declares `PATCH /closed-dates/{closed_date_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69956a1d8bedbe45", "name": "Unused endpoint: DELETE /closed-dates/{closed_date_id}", "shortDescription": {"text": "Unused endpoint: DELETE /closed-dates/{closed_date_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/calendar.py` declares `DELETE /closed-dates/{closed_date_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa699835e925105d", "name": "Unused endpoint: POST /loans/checkout", "shortDescription": {"text": "Unused endpoint: POST /loans/checkout"}, "fullDescription": {"text": "`src/compendium/api/routes/loans.py` declares `POST /loans/checkout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff03d30994b9cd31", "name": "Unused endpoint: POST /loans/{loan_id}/checkin", "shortDescription": {"text": "Unused endpoint: POST /loans/{loan_id}/checkin"}, "fullDescription": {"text": "`src/compendium/api/routes/loans.py` declares `POST /loans/{loan_id}/checkin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1966383c5747d526", "name": "Unused endpoint: POST /loans/{loan_id}/renew", "shortDescription": {"text": "Unused endpoint: POST /loans/{loan_id}/renew"}, "fullDescription": {"text": "`src/compendium/api/routes/loans.py` declares `POST /loans/{loan_id}/renew` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a94e3c5b6607e329", "name": "Unused endpoint: GET /loans", "shortDescription": {"text": "Unused endpoint: GET /loans"}, "fullDescription": {"text": "`src/compendium/api/routes/loans.py` declares `GET /loans` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65388cf31e8ecdc8", "name": "Unused endpoint: GET /loans/patron/{card_number}", "shortDescription": {"text": "Unused endpoint: GET /loans/patron/{card_number}"}, "fullDescription": {"text": "`src/compendium/api/routes/loans.py` declares `GET /loans/patron/{card_number}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55203b3fb1c0f67f", "name": "Unused endpoint: GET /loans/item/{barcode}", "shortDescription": {"text": "Unused endpoint: GET /loans/item/{barcode}"}, "fullDescription": {"text": "`src/compendium/api/routes/loans.py` declares `GET /loans/item/{barcode}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-276e148687d4f73e", "name": "Unused endpoint: GET /reports/checkouts", "shortDescription": {"text": "Unused endpoint: GET /reports/checkouts"}, "fullDescription": {"text": "`src/compendium/api/routes/reports.py` declares `GET /reports/checkouts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-965bb299a9b4dd6c", "name": "Unused endpoint: GET /reports/popular", "shortDescription": {"text": "Unused endpoint: GET /reports/popular"}, "fullDescription": {"text": "`src/compendium/api/routes/reports.py` declares `GET /reports/popular` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d339dda0eb394971", "name": "Unused endpoint: GET /reports/dormant", "shortDescription": {"text": "Unused endpoint: GET /reports/dormant"}, "fullDescription": {"text": "`src/compendium/api/routes/reports.py` declares `GET /reports/dormant` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3280a38285630dfa", "name": "Unused endpoint: GET /reports/overdues", "shortDescription": {"text": "Unused endpoint: GET /reports/overdues"}, "fullDescription": {"text": "`src/compendium/api/routes/reports.py` declares `GET /reports/overdues` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fce1f96dd8860f0", "name": "Unused endpoint: GET /branches/", "shortDescription": {"text": "Unused endpoint: GET /branches/"}, "fullDescription": {"text": "`src/compendium/api/routes/branches.py` declares `GET /branches/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5316f9f6e60d082c", "name": "Unused endpoint: PATCH /branches/{branch_id}", "shortDescription": {"text": "Unused endpoint: PATCH /branches/{branch_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/branches.py` declares `PATCH /branches/{branch_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82572b7132f3d730", "name": "Unused endpoint: GET /{card_number}/fines", "shortDescription": {"text": "Unused endpoint: GET /{card_number}/fines"}, "fullDescription": {"text": "`src/compendium/api/routes/fines.py` declares `GET /{card_number}/fines` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0e765a95850f2f8", "name": "Unused endpoint: POST /{card_number}/fines/assess-overdue", "shortDescription": {"text": "Unused endpoint: POST /{card_number}/fines/assess-overdue"}, "fullDescription": {"text": "`src/compendium/api/routes/fines.py` declares `POST /{card_number}/fines/assess-overdue` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`src/compendium/api/routes/fines.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab101fcde60b507a", "name": "Unused endpoint: POST /{fine_id}/pay", "shortDescription": {"text": "Unused endpoint: POST /{fine_id}/pay"}, "fullDescription": {"text": "`src/compendium/api/routes/fines.py` declares `POST /{fine_id}/pay` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-844b0025e620fb6b", "name": "Unused endpoint: POST /{fine_id}/waive", "shortDescription": {"text": "Unused endpoint: POST /{fine_id}/waive"}, "fullDescription": {"text": "`src/compendium/api/routes/fines.py` declares `POST /{fine_id}/waive` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8de438f5fe08ea4e", "name": "Unused endpoint: GET /fines", "shortDescription": {"text": "Unused endpoint: GET /fines"}, "fullDescription": {"text": "`src/compendium/api/routes/fines.py` declares `GET /fines` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8cab827ff79810c3", "name": "Unused endpoint: PATCH /creators/{creator_id}", "shortDescription": {"text": "Unused endpoint: PATCH /creators/{creator_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/creators.py` declares `PATCH /creators/{creator_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdbacfe9430a6ed", "name": "Unused endpoint: POST /auth/login", "shortDescription": {"text": "Unused endpoint: POST /auth/login"}, "fullDescription": {"text": "`src/compendium/api/routes/auth.py` declares `POST /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93315e2a5fd371d4", "name": "Unused endpoint: POST /households", "shortDescription": {"text": "Unused endpoint: POST /households"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `POST /households` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb4896467dce6096", "name": "Unused endpoint: GET /households", "shortDescription": {"text": "Unused endpoint: GET /households"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `GET /households` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00ebe6fedc4c80e5", "name": "Unused endpoint: GET /households/{household_id}", "shortDescription": {"text": "Unused endpoint: GET /households/{household_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `GET /households/{household_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d53f4e2e944adda8", "name": "Unused endpoint: PATCH /households/{household_id}", "shortDescription": {"text": "Unused endpoint: PATCH /households/{household_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `PATCH /households/{household_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-107b59a6100c61a1", "name": "Unused endpoint: DELETE /households/{household_id}", "shortDescription": {"text": "Unused endpoint: DELETE /households/{household_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `DELETE /households/{household_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d152462fa925131", "name": "Unused endpoint: POST /households/{household_id}/members", "shortDescription": {"text": "Unused endpoint: POST /households/{household_id}/members"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `POST /households/{household_id}/members` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b94c0882cfbc759", "name": "Unused endpoint: DELETE /households/{household_id}/members/{card_number}", "shortDescription": {"text": "Unused endpoint: DELETE /households/{household_id}/members/{card_number}"}, "fullDescription": {"text": "`src/compendium/api/routes/households.py` declares `DELETE /households/{household_id}/members/{card_number}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18f08ca36ea113c1", "name": "Unused endpoint: GET /items/{barcode}", "shortDescription": {"text": "Unused endpoint: GET /items/{barcode}"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `GET /items/{barcode}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4398ba9ef555ab55", "name": "Unused endpoint: POST /items/{barcode}/withdraw", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/withdraw"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/withdraw` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba53bd75cdaf87b7", "name": "Unused endpoint: PATCH /items/{barcode}", "shortDescription": {"text": "Unused endpoint: PATCH /items/{barcode}"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `PATCH /items/{barcode}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3fb3b115603d26ac", "name": "Unused endpoint: POST /items/{barcode}/loanable", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/loanable"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/loanable` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-62aa5af7266432a0", "name": "Unused endpoint: GET /items/{barcode}/notes", "shortDescription": {"text": "Unused endpoint: GET /items/{barcode}/notes"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `GET /items/{barcode}/notes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8ac919a6058f1e1", "name": "Unused endpoint: POST /items/{barcode}/notes", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/notes"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/notes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-924e7fedede00d81", "name": "Unused endpoint: DELETE /items/{barcode}/notes/{note_id}", "shortDescription": {"text": "Unused endpoint: DELETE /items/{barcode}/notes/{note_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `DELETE /items/{barcode}/notes/{note_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c305e4c7b1be169", "name": "Unused endpoint: POST /items/{barcode}/lost", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/lost"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/lost` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a21bb873dd9d6e84", "name": "Unused endpoint: POST /items/{barcode}/damaged", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/damaged"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/damaged` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d6f29ef9908ecac5", "name": "Unused endpoint: POST /items/{barcode}/clear-damage", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/clear-damage"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/clear-damage` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eec7959930332735", "name": "Unused endpoint: POST /items/{barcode}/clear-lost", "shortDescription": {"text": "Unused endpoint: POST /items/{barcode}/clear-lost"}, "fullDescription": {"text": "`src/compendium/api/routes/items.py` declares `POST /items/{barcode}/clear-lost` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cea2e3b1566c12be", "name": "Unused endpoint: GET /patron-categories/", "shortDescription": {"text": "Unused endpoint: GET /patron-categories/"}, "fullDescription": {"text": "`src/compendium/api/routes/patron_categories.py` declares `GET /patron-categories/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28eb91b5fb3eec35", "name": "Unused endpoint: POST /patron-categories/", "shortDescription": {"text": "Unused endpoint: POST /patron-categories/"}, "fullDescription": {"text": "`src/compendium/api/routes/patron_categories.py` declares `POST /patron-categories/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83e85e9154c1aa9f", "name": "Unused endpoint: PATCH /patron-categories/{category_id}", "shortDescription": {"text": "Unused endpoint: PATCH /patron-categories/{category_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/patron_categories.py` declares `PATCH /patron-categories/{category_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2592f78c9e8344d", "name": "Unused endpoint: DELETE /patron-categories/{category_id}", "shortDescription": {"text": "Unused endpoint: DELETE /patron-categories/{category_id}"}, "fullDescription": {"text": "`src/compendium/api/routes/patron_categories.py` declares `DELETE /patron-categories/{category_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/20264"}, "properties": {"repository": "statyk/compendium", "repoUrl": "https://github.com/statyk/compendium", "branch": "main"}, "results": [{"ruleId": "foundry_blueprint_gap", "level": "warning", "message": {"text": "Foundry mined blueprint gap alignment: statyk/compendium"}, "properties": {"repobilityId": 356300, "scanner": "foundry_dataset", "fingerprint": "5859e8258e469ac56a497533c533146631aaa9016416e6fb5d2884f4b5aec326", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback aligned with blueprint or architecture gaps", "intent": "Curriculum-gap examples connecting issue threads to helicopter-view gaps.", "labels": {"bug_fix": 3, "feature": 1, "test_or_ci": 8, "api_or_backend": 5, "docs_or_claims": 3, "ui_or_frontend": 7, "partial blueprint fit": 1, "verification_or_tests": 1, "data_schema_persistence": 1, "mostly follows blueprint": 2, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 1, "blueprint_human_gap_disagreement": 2, "thread_has_human_issue_and_fix_context": 2, "claimed_resolved_with_verification_signal": 3, "human_reported_issue_then_verified_fix_attempt": 1}, "source": "graph_query_export", "motif_id": "blueprint_gap_alignment", "outcomes": {"claimed_resolved_with_verification_signal": 6}, "polarity": "mixed", "query_id": "blueprint_gap_alignment", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 75, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 23, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_links_commit": 5, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 46, "node_types": {"repo": 1, "commit": 5, "thread": 1, "comment": 1, "pr_file": 23, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "statyk/compendium#5", "issue_number": "5", "quality_tiers": {"assumption_check": 3, "weak_supervision": 3}, "repo_full_name": "statyk/compendium", "training_usage": "curriculum_gap", "source_motif_id": "graph-pattern-motif-thread-6f9112326c299f80", "graph_gold_label": "supported_by_verification_signal", "changed_file_labels": {"test_or_ci": 32, "api_or_backend": 20, "docs_or_claims": 12, "ui_or_frontend": 28}}, "text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#5\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: statyk/compendium\nThread: statyk/compendium#5\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#5\nRepo: statyk/compendium\nIssue/PR number: 5\nGraph consistency label: supported_by_verification_signal\nNodes: 46\nEdges: 75\nNode types: {'pr_file': 23, 'link_quality': 6, 'commit': 5, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 23, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 6, 'comment_chain_links_commit': 5, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'test_or_ci': 8, 'ui_or_frontend': 7, 'api_or_backend': 5, 'docs_or_claims': 3, 'bug_fix': 3, 'claimed_resolved_with_verification_signal': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_disagreement': 2, 'mostly follows blueprint': 2, 'issue_or_pull_request_thread': 1, 'data_schema_persistence': 1, 'human_reported_issue_then_verified_fix_attempt': 1, 'feature': 1, 'verification_or_tests': 1, 'blueprint_human_gap_alignment': 1, 'partial blueprint fit': 1}\nOutcomes: {'claimed_resolved_with_verification_signal': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Use helicopter-view architecture/schema/design evidence beside issue threads.\n- Teach models to compare requested product class against implementation layers.\nAssumption checks:\n- Which blueprint layer is absent: frontend, API, data, auth, tests, or deployment?\n- Does human feedback confirm the same architectural gap?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "graph-query-motif_query-f82b17b79a6c969e", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/blueprint_gap_alignment/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "graph_queries/blueprint_gap_alignment", "training_usage": "curriculum_gap"}}}, {"ruleId": "foundry_blueprint_gap", "level": "warning", "message": {"text": "Foundry mined blueprint gap alignment: statyk/compendium"}, "properties": {"repobilityId": 356299, "scanner": "foundry_dataset", "fingerprint": "317dec15eeabc06650b653f323a68fdf5adfde28009fdddd7e7a663155910287", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback aligned with blueprint or architecture gaps", "intent": "Curriculum-gap examples connecting issue threads to helicopter-view gaps.", "labels": {"bug_fix": 1, "test_or_ci": 1, "test_ci_gap": 1, "dependency_or_build": 1, "partial blueprint fit": 1, "verification_or_tests": 1, "mostly follows blueprint": 2, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 1, "blueprint_human_gap_disagreement": 2, "thread_has_human_issue_and_fix_context": 2, "claimed_resolved_with_verification_signal": 3, "human_reported_issue_then_verified_fix_attempt": 1}, "source": "graph_query_export", "motif_id": "blueprint_gap_alignment", "outcomes": {"claimed_resolved_with_verification_signal": 6}, "polarity": "mixed", "query_id": "blueprint_gap_alignment", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 29, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 3, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 22, "node_types": {"repo": 1, "commit": 3, "thread": 1, "comment": 1, "pr_file": 1, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "statyk/compendium#4", "issue_number": "4", "quality_tiers": {"high_confidence": 3, "assumption_check": 3}, "repo_full_name": "statyk/compendium", "training_usage": "curriculum_gap", "source_motif_id": "graph-pattern-motif-thread-91b5c2c74b64e2bd", "graph_gold_label": "supported_by_verification_signal", "changed_file_labels": {"test_or_ci": 4}}, "text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#4\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: statyk/compendium\nThread: statyk/compendium#4\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#4\nRepo: statyk/compendium\nIssue/PR number: 4\nGraph consistency label: supported_by_verification_signal\nNodes: 22\nEdges: 29\nNode types: {'link_quality': 6, 'commit': 3, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'comment_chain_links_commit': 3, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'claimed_resolved_with_verification_signal': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_disagreement': 2, 'mostly follows blueprint': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'test_or_ci': 1, 'human_reported_issue_then_verified_fix_attempt': 1, 'verification_or_tests': 1, 'bug_fix': 1, 'dependency_or_build': 1, 'blueprint_human_gap_alignment': 1, 'partial blueprint fit': 1}\nOutcomes: {'claimed_resolved_with_verification_signal': 6}\nQuality tiers: {'high_confidence': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Use helicopter-view architecture/schema/design evidence beside issue threads.\n- Teach models to compare requested product class against implementation layers.\nAssumption checks:\n- Which blueprint layer is absent: frontend, API, data, auth, tests, or deployment?\n- Does human feedback confirm the same architectural gap?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "graph-query-motif_query-2aa3634e82a5ace6", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/blueprint_gap_alignment/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "graph_queries/blueprint_gap_alignment", "training_usage": "curriculum_gap"}}}, {"ruleId": "foundry_blueprint_gap", "level": "warning", "message": {"text": "Foundry mined blueprint gap alignment: statyk/compendium"}, "properties": {"repobilityId": 356298, "scanner": "foundry_dataset", "fingerprint": "31c39c3d369fc090a8d5f33bb8ab880bb04f69a6a1065a44dca63db6389bc032", "category": "tech_debt", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback aligned with blueprint or architecture gaps", "intent": "Curriculum-gap examples connecting issue threads to helicopter-view gaps.", "labels": {"bug_fix": 3, "schema_or_data": 1, "partial blueprint fit": 1, "data_schema_persistence": 1, "mostly follows blueprint": 2, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 1, "blueprint_human_gap_disagreement": 2, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "blueprint_gap_alignment", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "mixed", "query_id": "blueprint_gap_alignment", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 29, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 3, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 22, "node_types": {"repo": 1, "commit": 3, "thread": 1, "comment": 1, "pr_file": 1, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "statyk/compendium#3", "issue_number": "3", "quality_tiers": {"high_confidence": 3, "assumption_check": 3}, "repo_full_name": "statyk/compendium", "training_usage": "curriculum_gap", "source_motif_id": "graph-pattern-motif-thread-893cc1a45704a737", "graph_gold_label": "supported_by_high_confidence_link", "changed_file_labels": {"schema_or_data": 4}}, "text": "Graph query export: Human feedback aligned with blueprint or architecture gaps\nQuery id: blueprint_gap_alignment\nQuery type: motif_query\nIntent: Curriculum-gap examples connecting issue threads to helicopter-view gaps.\nMotif: blueprint_gap_alignment\nTraining usage: curriculum_gap\nGraph gold label: supported_by_high_confidence_link\nRepo: statyk/compendium\nThread: statyk/compendium#3\nEvidence:\nGraph motif: Human feedback aligns with blueprint or architecture gaps\nMotif id: blueprint_gap_alignment\nPolarity: mixed\nTraining usage: curriculum_gap\nSeverity: medium\nRepo: statyk/compendium\nThread: statyk/compendium#3\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#3\nRepo: statyk/compendium\nIssue/PR number: 3\nGraph consistency label: supported_by_high_confidence_link\nNodes: 22\nEdges: 29\nNode types: {'link_quality': 6, 'commit': 3, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'comment_chain_links_commit': 3, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'bug_fix': 3, 'claimed_resolved_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_disagreement': 2, 'mostly follows blueprint': 2, 'issue_or_pull_request_thread': 1, 'data_schema_persistence': 1, 'schema_or_data': 1, 'human_reported_issue_then_fix_attempt': 1, 'blueprint_human_gap_alignment': 1, 'partial blueprint fit': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'high_confidence': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Use helicopter-view architecture/schema/design evidence beside issue threads.\n- Teach models to compare requested product class against implementation layers.\nAssumption checks:\n- Which blueprint layer is absent: frontend, API, data, auth, tests, or deployment?\n- Does human feedback confirm the same architectural gap?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "graph-query-motif_query-b69f4c8a9216a0c7", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/blueprint_gap_alignment/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "graph_queries/blueprint_gap_alignment", "training_usage": "curriculum_gap"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: statyk/compendium"}, "properties": {"repobilityId": 312603, "scanner": "foundry_dataset", "fingerprint": "d2eb1582fd9cb10df8e98378d3d51cdaab32c28c357e43bbb4d4865ed7e9a2fd", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "statyk/compendium#3", "human_labels": ["data_schema_persistence", "schema_or_data"], "issue_number": "3", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.92, "repo_full_name": "statyk/compendium", "training_usage": "gold_candidate", "confidence_tier": "high_confidence", "source_chain_id": "evidence-chain-issue_chain-f46d099fb0cd3c6a", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 1, "docs": 5, "schemas": 1, "architecture": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 1, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"schema_or_data": 1}, "linked_commit_count": 3, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_high_confidence", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 2, "design_schema_api_artifact_count": 2}, "text": "Comment chain pattern product: assumption_checks\nRepo: statyk/compendium\nThread: statyk/compendium#3\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_high_confidence, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: statyk/compendium#3\nRepo: statyk/compendium\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 3\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 1\nLabels: {'data_schema_persistence': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'schema_or_data': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-55cd9648fe80fb7d\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"data_schema_persistence\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/statyk/compendium/pull/3\",\n    \"text\": \"GitHub feedback: data_schema_persistence\\nPolarity: bad\\nKind: pull_request_body\\nRepo: statyk/compendium\\nAuthor: statyk (User)\\nURL: https://github.com/statyk/compendium/pull/3\\nTitle: docs(schema): add 6 missing rows to the migration-history table\\nBody:\\n## What\\n\\nThe hand-maintained `## Migration history` table in `docs/schema.md` was missing **6 migration rows**. This adds them in base\u2192head order so the table matches `uv run alembic history` (now 30 rows, head `d3e4f5a6b7c8`).\\n\\nAdded rows (descriptions written from each migration file's actual `upgrade()` body, not just its slug):\\n\\n| Revision | Description |\\n|---|---|\\n| `e9f0a1b2c3d4` | Fix `failed_login.id` column type (Integer, not BigInteger, for SQLite autoincrement) |\\n| `fab1c2d3e4f5` | `patron.account.manage` permission on Librarian + partial unique index on `patron.user_id` |\\n| `611abe9ea6e5` | `metadata_cache` table (persistent external-lookup cache) |\\n| `a1b2c3d4e5f6` | `app_user.password_changed_at` (backfilled; pwd_iat JWT-invalidation claim) |\\n| `1b17e2ba445c` | Consolidate barcode settings \u2192 `barcode_format` |\\n| `5b9e539aca65` | `household` table + `patron.household_id`; `household.manage` permission on Librarian |\\n\\nNo ex\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-54e3538f17126829\",\n    \"filename\": \"docs/schema.md\",\n    \"label\": \"schema_or_data\",\n    \"status\": \"modified\",\n    \"additions\": 6,\n    \"deletions\": 0,\n    \"changes\": 6,\n    \"blob_url\": \"https://github.com/statyk/compendium/blob/886e45e6144a8b735fdfacef73a3e4e000a1e759/docs%2Fschema.md\"\n  }\n]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-d4ca1f2f569234a9\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: statyk/compendium\nGraph label: source_backed_multi_signal_graph\nNodes: 14\nEdges: 22\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"helicopter_repo_view\": 2, \"repo\": 1, \"source_artifact\":\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "comment-chain-pattern-assumption_checks-0f4c4ec6f44ef884", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "gold_candidate"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: statyk/compendium"}, "properties": {"repobilityId": 312602, "scanner": "foundry_dataset", "fingerprint": "e4563c702a0ccb46911d44c9122d426124cbf76821870e83efbb0b2516a25fae", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "statyk/compendium#2", "human_labels": ["api_or_backend", "docs_or_claims", "schema_or_data", "security_auth_secret", "source_or_other", "test_or_ci", "ui_or_frontend"], "issue_number": "2", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.662, "repo_full_name": "statyk/compendium", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-6d478b9169947744", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 1, "docs": 5, "schemas": 1, "architecture": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 51, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 13, "api_or_backend": 3, "docs_or_claims": 7, "schema_or_data": 2, "ui_or_frontend": 22, "source_or_other": 4}, "linked_commit_count": 5, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 2, "design_schema_api_artifact_count": 2}, "text": "Comment chain pattern product: assumption_checks\nRepo: statyk/compendium\nThread: statyk/compendium#2\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: statyk/compendium#2\nRepo: statyk/compendium\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 5\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 51\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'source_or_other': 4, 'docs_or_claims': 7, 'ui_or_frontend': 22, 'schema_or_data': 2, 'api_or_backend': 3, 'test_or_ci': 13}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-711c0f8dfc416ee2\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/statyk/compendium/pull/2\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: statyk/compendium\\nAuthor: statyk (User)\\nURL: https://github.com/statyk/compendium/pull/2\\nTitle: Remote phone scanner + UX revamp\\nBody:\\n## Summary\\n\\nAdds an opt-in **remote phone-scanner terminal** and a full UX revamp on top of it. Staff generate a pairing QR at the desk (or the Add-Item page); a phone claims it over HTTPS and becomes a continuous multi-mode (Checkout / Checkin / Catalog-add) wireless scanner that POSTs each barcode back to the server. No video stream leaves the phone.\\n\\nThis branch contains two stages:\\n\\n**Base scanner (prior work):** QR pairing with a single-use claim secret rotated to an HttpOnly session cookie, a per-mode state machine, the shared `runContinuous(video, backend, {onCode, onMiss})` decoder seam in `web/static/scanner.js` (a pinned public API shared with downstream LitCat), and the `prune-scan-pairings` maintenance command. Includes earlier fixes for QR sizing and high-res camera capture.\\n\\n**UX revamp (this work \u2014 16 commits):**\\n- **Desk live activity feed + catalog review queue** (approve / edit / discard), rendered by the existing 1500ms HTMX poll.\\n- **Per-pairing \\\"re\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-bb7f67d7ae59214b\",\n    \"filename\": \".gitignore\",\n    \"label\": \"source_or_other\",\n    \"status\": \"modified\",\n    \"additions\": 3,\n    \"deletions\": 0,\n    \"changes\": 3,\n    \"blob_url\": \"https://github.com/statyk/compendium/blob/2f688c3a57b039a0d119c606a31454b4e44f9ec7/.gitignore\"\n  },\n  {\n    \"id\": \"github-pr-file-file-994af878531f52dc\",\n    \"filename\": \"CHANGELOG.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 47,\n    \"deletions\": 0,\n    \"changes\": 47,\n    \"blob_url\": \"https://github.com/statyk/compendium/\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "comment-chain-pattern-assumption_checks-efccba54667d4f24", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: statyk/compendium"}, "properties": {"repobilityId": 312601, "scanner": "foundry_dataset", "fingerprint": "a26a576cfad363412af7e033bbdd1e00cfbd100badcec47ee3bf96f3d56e5d7a", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "statyk/compendium#1", "human_labels": ["security_auth_secret", "test_or_ci", "ui_or_frontend"], "issue_number": "1", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.59, "repo_full_name": "statyk/compendium", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-74f68d6e0b8b68ef", "helicopter_views": {"schemas": 2}, "artifact_families": {"ci": 1, "docs": 5, "schemas": 1, "architecture": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 3, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"test_or_ci": 1, "ui_or_frontend": 2}, "linked_commit_count": 2, "helicopter_view_count": 2, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 2, "design_schema_api_artifact_count": 2}, "text": "Comment chain pattern product: assumption_checks\nRepo: statyk/compendium\nThread: statyk/compendium#1\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: statyk/compendium#1\nRepo: statyk/compendium\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 3\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'ui_or_frontend': 2, 'test_or_ci': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-ed21955085befd08\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/statyk/compendium/pull/1\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: statyk/compendium\\nAuthor: statyk (User)\\nURL: https://github.com/statyk/compendium/pull/1\\nTitle: feat(metadata): track actual adapter source + fall back from GB HTTP \u2026\\nBody:\\n\u2026errors\\r\\n\\r\\nAdd lookup_metadata_with_source() returning (result, source_name) so callers can report which adapter produced the data. lookup_metadata() stays as a thin back-compat wrapper delegating to the new function.\\r\\n\\r\\nWhen Google Books is the primary book adapter and raises ExternalLookupError (e.g. HTTP 400 from a malformed/invalid API key), the error is now caught and the lookup falls back to Open Library \u2014 matching the existing None-result fallback behaviour. Other adapters still propagate their errors normally.\\r\\n\\r\\nCatalogService.refresh_metadata now uses lookup_metadata_with_source and sets RefreshReport.source from the actual adapter that returned data rather than from the hard-coded _SOURCE_FOR_MEDIA_TYPE table, so the \\\"Looked up via \u2026\\\" label in client UIs reflects which source was actually used.\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-a08f850716d6fec9\",\n    \"filename\": \"src/compendium/services/catalog.py\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"modified\",\n    \"additions\": 5,\n    \"deletions\": 3,\n    \"changes\": 8,\n    \"blob_url\": \"https://github.com/statyk/compendium/blob/173038ca7424b905a2e6f7fbb940390eceafcb20/src%2Fcompendium%2Fservices%2Fcatalog.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-0176f4124e88ee10\",\n    \"filename\": \"src/compendium/services/metadata.py\",\n    \"label\": \"ui_or_frontend\",\n    \"status\": \"modified\",\n    \"additions\": 94,\n    \"deletions\": 21,\n    \"changes\": 115,\n    \"blob_url\": \"https://github.com/statyk/compendium/blob/173038ca7424b905a2e6f7fbb940390eceafcb20/src%2Fcompendium%2Fservices%2Fmetadata.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-a8f7307\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "comment-chain-pattern-assumption_checks-4286d8ddb232161c", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_test_ci_gap", "level": "error", "message": {"text": "Foundry mined test ci gap after feedback: statyk/compendium"}, "properties": {"repobilityId": 341077, "scanner": "foundry_dataset", "fingerprint": "4e5f73bc4620ef4c9ff0c4909123704b248dfdb9bd875aa8fc0b862e02a674eb", "category": "testing", "severity": "high", "confidence": 0.78, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Feedback exposes missing tests or CI", "intent": "Hard negatives for feedback/fix chains without adequate guardrails.", "labels": {"bug_fix": 1, "test_or_ci": 1, "test_ci_gap": 1, "dependency_or_build": 1, "partial blueprint fit": 1, "verification_or_tests": 1, "mostly follows blueprint": 2, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 1, "blueprint_human_gap_disagreement": 2, "thread_has_human_issue_and_fix_context": 2, "claimed_resolved_with_verification_signal": 3, "human_reported_issue_then_verified_fix_attempt": 1}, "source": "graph_query_export", "motif_id": "test_ci_gap_after_feedback", "outcomes": {"claimed_resolved_with_verification_signal": 6}, "polarity": "bad", "query_id": "test_ci_gap_after_feedback", "severity": "high", "ci_labels": {}, "synthetic": false, "edge_count": 29, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 3, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 22, "node_types": {"repo": 1, "commit": 3, "thread": 1, "comment": 1, "pr_file": 1, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "statyk/compendium#4", "issue_number": "4", "quality_tiers": {"high_confidence": 3, "assumption_check": 3}, "repo_full_name": "statyk/compendium", "training_usage": "hard_negative", "source_motif_id": "graph-pattern-motif-thread-b92eb1b308754ae3", "graph_gold_label": "supported_by_verification_signal", "changed_file_labels": {"test_or_ci": 4}}, "text": "Graph query export: Feedback exposes missing tests or CI\nQuery id: test_ci_gap_after_feedback\nQuery type: motif_query\nIntent: Hard negatives for feedback/fix chains without adequate guardrails.\nMotif: test_ci_gap_after_feedback\nTraining usage: hard_negative\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#4\nEvidence:\nGraph motif: Feedback or fix context exposes missing test/CI guardrails\nMotif id: test_ci_gap_after_feedback\nPolarity: bad\nTraining usage: hard_negative\nSeverity: high\nRepo: statyk/compendium\nThread: statyk/compendium#4\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#4\nRepo: statyk/compendium\nIssue/PR number: 4\nGraph consistency label: supported_by_verification_signal\nNodes: 22\nEdges: 29\nNode types: {'link_quality': 6, 'commit': 3, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'comment_chain_links_commit': 3, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'claimed_resolved_with_verification_signal': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_disagreement': 2, 'mostly follows blueprint': 2, 'issue_or_pull_request_thread': 1, 'test_ci_gap': 1, 'test_or_ci': 1, 'human_reported_issue_then_verified_fix_attempt': 1, 'verification_or_tests': 1, 'bug_fix': 1, 'dependency_or_build': 1, 'blueprint_human_gap_alignment': 1, 'partial blueprint fit': 1}\nOutcomes: {'claimed_resolved_with_verification_signal': 6}\nQuality tiers: {'high_confidence': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Turn human feedback into regression tests and CI gates.\n- Penalize fixes that do not add or exercise verification for affected workflows.\nAssumption checks:\n- Did the fix add tests for the exact complaint?\n- Does CI run those tests, or is verification only implied?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "graph-query-motif_query-0efd4d8dd91e612b", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/test_ci_gap_after_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "graph_queries/test_ci_gap_after_feedback", "training_usage": "hard_negative"}}}, {"ruleId": "foundry_schema_ui_api_gap", "level": "error", "message": {"text": "Foundry mined schema ui api mismatch: statyk/compendium"}, "properties": {"repobilityId": 330992, "scanner": "foundry_dataset", "fingerprint": "0ef7cb1d8bab768a3a2e3b6200f2a5da323ea21fc18e5d66e113e5b7a35ae34a", "category": "quality", "severity": "high", "confidence": 0.76, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Schema, UI, and API mismatch", "intent": "Assumption-check examples for data-path consistency across layers.", "labels": {"bug_fix": 3, "feature": 1, "test_or_ci": 8, "api_or_backend": 5, "docs_or_claims": 3, "ui_or_frontend": 7, "partial blueprint fit": 1, "verification_or_tests": 1, "data_schema_persistence": 1, "mostly follows blueprint": 2, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 1, "blueprint_human_gap_disagreement": 2, "thread_has_human_issue_and_fix_context": 2, "claimed_resolved_with_verification_signal": 3, "human_reported_issue_then_verified_fix_attempt": 1}, "source": "graph_query_export", "motif_id": "schema_ui_api_mismatch", "outcomes": {"claimed_resolved_with_verification_signal": 6}, "polarity": "bad", "query_id": "schema_ui_api_mismatch", "severity": "high", "ci_labels": {}, "synthetic": false, "edge_count": 75, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 23, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 12, "thread_has_comment_chain": 1, "comment_chain_links_commit": 5, "comment_chain_touches_file": 12, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 46, "node_types": {"repo": 1, "commit": 5, "thread": 1, "comment": 1, "pr_file": 23, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "statyk/compendium#5", "issue_number": "5", "quality_tiers": {"assumption_check": 3, "weak_supervision": 3}, "repo_full_name": "statyk/compendium", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-759c44385fd4954b", "graph_gold_label": "supported_by_verification_signal", "changed_file_labels": {"test_or_ci": 32, "api_or_backend": 20, "docs_or_claims": 12, "ui_or_frontend": 28}}, "text": "Graph query export: Schema, UI, and API mismatch\nQuery id: schema_ui_api_mismatch\nQuery type: motif_query\nIntent: Assumption-check examples for data-path consistency across layers.\nMotif: schema_ui_api_mismatch\nTraining usage: assumption_check\nGraph gold label: supported_by_verification_signal\nRepo: statyk/compendium\nThread: statyk/compendium#5\nEvidence:\nGraph motif: Schema, UI, and API evidence do not line up\nMotif id: schema_ui_api_mismatch\nPolarity: bad\nTraining usage: assumption_check\nSeverity: high\nRepo: statyk/compendium\nThread: statyk/compendium#5\nGraph gold label: supported_by_verification_signal\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#5\nRepo: statyk/compendium\nIssue/PR number: 5\nGraph consistency label: supported_by_verification_signal\nNodes: 46\nEdges: 75\nNode types: {'pr_file': 23, 'link_quality': 6, 'commit': 5, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'thread_touches_file': 23, 'comment_chain_touches_file': 12, 'issue_chain_touches_file': 12, 'chain_has_link_quality': 6, 'comment_chain_links_commit': 5, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'test_or_ci': 8, 'ui_or_frontend': 7, 'api_or_backend': 5, 'docs_or_claims': 3, 'bug_fix': 3, 'claimed_resolved_with_verification_signal': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_disagreement': 2, 'mostly follows blueprint': 2, 'issue_or_pull_request_thread': 1, 'data_schema_persistence': 1, 'human_reported_issue_then_verified_fix_attempt': 1, 'feature': 1, 'verification_or_tests': 1, 'blueprint_human_gap_alignment': 1, 'partial blueprint fit': 1}\nOutcomes: {'claimed_resolved_with_verification_signal': 6}\nQuality tiers: {'weak_supervision': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Create schema-to-API-to-UI consistency tasks with migrations and tests.\n- Teach models to verify persistence, route contracts, and UI state together.\nAssumption checks:\n- Do schema changes have matching API and UI handling?\n- Are migrations and tests present for the data path?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "graph-query-motif_query-636d96e13ee2fac0", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/schema_ui_api_mismatch/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "graph_queries/schema_ui_api_mismatch", "training_usage": "assumption_check"}}}, {"ruleId": "foundry_schema_ui_api_gap", "level": "error", "message": {"text": "Foundry mined schema ui api mismatch: statyk/compendium"}, "properties": {"repobilityId": 330991, "scanner": "foundry_dataset", "fingerprint": "25722bdf093ff0f5fa700875dbda7af1b893f3785dc3f95b73caf187237b3018", "category": "quality", "severity": "high", "confidence": 0.76, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Schema, UI, and API mismatch", "intent": "Assumption-check examples for data-path consistency across layers.", "labels": {"bug_fix": 3, "schema_or_data": 1, "partial blueprint fit": 1, "data_schema_persistence": 1, "mostly follows blueprint": 2, "claimed_resolved_unverified": 3, "issue_or_pull_request_thread": 1, "blueprint_human_gap_alignment": 1, "blueprint_human_gap_disagreement": 2, "human_reported_issue_then_fix_attempt": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "schema_ui_api_mismatch", "outcomes": {"claimed_resolved_unverified": 6}, "polarity": "bad", "query_id": "schema_ui_api_mismatch", "severity": "high", "ci_labels": {}, "synthetic": false, "edge_count": 29, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "alignment_uses_comment": 3, "alignment_uses_finding": 3, "chain_has_link_quality": 6, "comment_aligns_finding": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 3, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 22, "node_types": {"repo": 1, "commit": 3, "thread": 1, "comment": 1, "pr_file": 1, "alignment": 3, "fix_outcome": 1, "issue_chain": 1, "link_quality": 6, "comment_chain": 1, "blueprint_finding": 3}, "query_type": "motif_query", "thread_key": "statyk/compendium#3", "issue_number": "3", "quality_tiers": {"high_confidence": 3, "assumption_check": 3}, "repo_full_name": "statyk/compendium", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-2a3ee21a07018e64", "graph_gold_label": "supported_by_high_confidence_link", "changed_file_labels": {"schema_or_data": 4}}, "text": "Graph query export: Schema, UI, and API mismatch\nQuery id: schema_ui_api_mismatch\nQuery type: motif_query\nIntent: Assumption-check examples for data-path consistency across layers.\nMotif: schema_ui_api_mismatch\nTraining usage: assumption_check\nGraph gold label: supported_by_high_confidence_link\nRepo: statyk/compendium\nThread: statyk/compendium#3\nEvidence:\nGraph motif: Schema, UI, and API evidence do not line up\nMotif id: schema_ui_api_mismatch\nPolarity: bad\nTraining usage: assumption_check\nSeverity: high\nRepo: statyk/compendium\nThread: statyk/compendium#3\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: statyk/compendium#3\nRepo: statyk/compendium\nIssue/PR number: 3\nGraph consistency label: supported_by_high_confidence_link\nNodes: 22\nEdges: 29\nNode types: {'link_quality': 6, 'commit': 3, 'alignment': 3, 'blueprint_finding': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 6, 'comment_chain_links_commit': 3, 'alignment_uses_comment': 3, 'alignment_uses_finding': 3, 'comment_aligns_finding': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'bug_fix': 3, 'claimed_resolved_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'blueprint_human_gap_disagreement': 2, 'mostly follows blueprint': 2, 'issue_or_pull_request_thread': 1, 'data_schema_persistence': 1, 'schema_or_data': 1, 'human_reported_issue_then_fix_attempt': 1, 'blueprint_human_gap_alignment': 1, 'partial blueprint fit': 1}\nOutcomes: {'claimed_resolved_unverified': 6}\nQuality tiers: {'high_confidence': 3, 'assumption_check': 3}\nCI labels: {}\nCurriculum targets:\n- Create schema-to-API-to-UI consistency tasks with migrations and tests.\n- Teach models to verify persistence, route contracts, and UI state together.\nAssumption checks:\n- Do schema changes have matching API and UI handling?\n- Are migrations and tests present for the data path?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/statyk/compendium", "source_id": "graph-query-motif_query-e968dd3fbb313671", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/schema_ui_api_mismatch/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "statyk/compendium", "source_dataset": "graph_queries/schema_ui_api_mismatch", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-4f7646511c281596", "level": "note", "message": {"text": "Possibly dead Python function: backup_command"}, "properties": {"repobilityId": "55023cd0d597d8a1", "scanner": "scanner-primary", "fingerprint": "4f7646511c281596", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/cli/commands/backup.py:12"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f816a2ed4b70a04", "level": "note", "message": {"text": "Possibly dead Python function: restore_command"}, "properties": {"repobilityId": "32373756d216e2ec", "scanner": "scanner-primary", "fingerprint": "5f816a2ed4b70a04", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/cli/commands/backup.py:76"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7a3ae4b7cbebe199", "level": "note", "message": {"text": "Possibly dead Python function: init_command"}, "properties": {"repobilityId": "f32b10e81691f1fe", "scanner": "scanner-primary", "fingerprint": "7a3ae4b7cbebe199", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/cli/commands/init.py:12"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e13ff909c373c6d5", "level": "note", "message": {"text": "Possibly dead Python function: require_web_user"}, "properties": {"repobilityId": "ffc1e5534e9e3922", "scanner": "scanner-primary", "fingerprint": "e13ff909c373c6d5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/deps.py:94"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0feee973f18913ad", "level": "note", "message": {"text": "Possibly dead Python function: require_scan_pairing"}, "properties": {"repobilityId": "144d2a9ab2df12dc", "scanner": "scanner-primary", "fingerprint": "0feee973f18913ad", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/deps.py:128"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c583827fb1f85cd4", "level": "note", "message": {"text": "Possibly dead Python function: validate_google_books_key"}, "properties": {"repobilityId": "d3eaa01cbf7dbefb", "scanner": "scanner-primary", "fingerprint": "c583827fb1f85cd4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/services/metadata.py:1083"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b612662ceff78a5", "level": "note", "message": {"text": "Possibly dead Python function: list_users"}, "properties": {"repobilityId": "120fbef697ff417f", "scanner": "scanner-primary", "fingerprint": "3b612662ceff78a5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/services/auth.py:168"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff9424fc7fb63063", "level": "note", "message": {"text": "Possibly dead Python function: render_patron_label_svg"}, "properties": {"repobilityId": "e7214e9b281f2da3", "scanner": "scanner-primary", "fingerprint": "ff9424fc7fb63063", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/services/labels.py:1124"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8def6db8dc5ff563", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/compendium/web/static/htmx.min.js:1"}, "properties": {"repobilityId": "2345b663761ad470", "scanner": "scanner-primary", "fingerprint": "8def6db8dc5ff563", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-254676044941d860", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/compendium/web/static/zxing/zxing-browser.min.js:1"}, "properties": {"repobilityId": "bf1ae58561cff46f", "scanner": "scanner-primary", "fingerprint": "254676044941d860", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1224efb32b541d5f", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "b0782d05d423cf3f", "scanner": "scanner-primary", "fingerprint": "1224efb32b541d5f", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-1224efb32b541d5f", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.11-slim"}, "properties": {"repobilityId": "dc24780cf1a2f732", "scanner": "scanner-primary", "fingerprint": "1224efb32b541d5f", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/Dockerfile"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-1fded96e36390b1e", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in src/compendium/web/static/htmx.min.js:1"}, "properties": {"repobilityId": "25a9840084dc6b7c", "scanner": "scanner-primary", "fingerprint": "1fded96e36390b1e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/static/htmx.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b5d7735b11cacb3", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/compendium/web/static/htmx.min.js:1"}, "properties": {"repobilityId": "b17e40e4cbdedf7d", "scanner": "scanner-primary", "fingerprint": "7b5d7735b11cacb3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/static/htmx.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-15bc79657d4a5252", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in src/compendium/web/static/htmx.min.js:1"}, "properties": {"repobilityId": "8ba002f05826b7b4", "scanner": "scanner-primary", "fingerprint": "15bc79657d4a5252", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/static/htmx.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-852106ed33dd3377", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in src/compendium/web/static/htmx.min.js:1"}, "properties": {"repobilityId": "0fa204d1c3ea2442", "scanner": "scanner-primary", "fingerprint": "852106ed33dd3377", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/static/htmx.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "111ded8435b78771", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "81d7235fa81ec078", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8eb96fb1706184f3", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "d23ec816d11b45e5", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "242206db1caa02bb", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2f410469668d834b", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "325eb799a895e23c", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9a38b98594265645", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9a38b98594265645", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 101}}}]}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0ee75beca21f4375", "level": "note", "message": {"text": "Very large file: tests/integration/test_web_ui.py (2001 lines)"}, "properties": {"repobilityId": "1ec037fa5848fed2", "scanner": "scanner-primary", "fingerprint": "0ee75beca21f4375", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9735d582720d9472", "level": "note", "message": {"text": "Very large file: tests/integration/test_cli_commands.py (1804 lines)"}, "properties": {"repobilityId": "c554da3d87da76c5", "scanner": "scanner-primary", "fingerprint": "9735d582720d9472", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2e1d027f330f3df3", "level": "note", "message": {"text": "Very large file: tests/unit/test_labels_service.py (1758 lines)"}, "properties": {"repobilityId": "0668b113cc1d310d", "scanner": "scanner-primary", "fingerprint": "2e1d027f330f3df3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-588d3dc8c99a2113", "level": "note", "message": {"text": "Very large file: src/compendium/services/catalog.py (1300 lines)"}, "properties": {"repobilityId": "d6f64bfb10acd271", "scanner": "scanner-primary", "fingerprint": "588d3dc8c99a2113", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b8d6cba13bdeb51e", "level": "note", "message": {"text": "Very large file: src/compendium/services/import_export.py (1621 lines)"}, "properties": {"repobilityId": "fb6f62b980962c79", "scanner": "scanner-primary", "fingerprint": "b8d6cba13bdeb51e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "d9ae88fb31a864a9", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "81f99ad02af53289", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "5caf4b21b38452fd", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "0e7579eadb662d0a", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-3aec0d54b2c2ceb9", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/conftest.py:7"}, "properties": {"repobilityId": "37ebf8ddc1e466ef", "scanner": "scanner-primary", "fingerprint": "3aec0d54b2c2ceb9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3d7cc161c0fcbad7", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/integration/test_csp_inline_handlers.py:9"}, "properties": {"repobilityId": "325d44453e3225a7", "scanner": "scanner-primary", "fingerprint": "3d7cc161c0fcbad7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3467c9f64d7fc325", "level": "note", "message": {"text": "Legacy-named symbol `test_role_clone_creates_editable_copy` in tests/integration/test_web_ui.py:1558"}, "properties": {"repobilityId": "94401e4559fd960a", "scanner": "scanner-primary", "fingerprint": "3467c9f64d7fc325", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1e26414718aef706", "level": "note", "message": {"text": "Legacy-named symbol `test_no_stale_code128_default_copy` in tests/integration/test_labels_web.py:383"}, "properties": {"repobilityId": "16e0cfdc1460b2da", "scanner": "scanner-primary", "fingerprint": "1e26414718aef706", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a9a737dc40eb52cd", "level": "none", "message": {"text": "Commented-code block (14 lines) in tests/integration/test_scan_web.py:387"}, "properties": {"repobilityId": "b16104435b6f1e49", "scanner": "scanner-primary", "fingerprint": "a9a737dc40eb52cd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bb9a68bae151d72a", "level": "note", "message": {"text": "Legacy-named symbol `test_delete_older_than_noop_when_nothing_old` in tests/integration/test_audit_prune.py:75"}, "properties": {"repobilityId": "42bc45b23a22ddf3", "scanner": "scanner-primary", "fingerprint": "bb9a68bae151d72a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8dade48f89f78a72", "level": "note", "message": {"text": "Legacy-named symbol `test_checkout_by_isbn_skips_checked_out_copy` in tests/integration/test_isbn_circulation.py:109"}, "properties": {"repobilityId": "9496097411346e0a", "scanner": "scanner-primary", "fingerprint": "8dade48f89f78a72", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7a6f42618812c605", "level": "note", "message": {"text": "Legacy-named symbol `t_old` in tests/integration/test_item_note_model.py:82"}, "properties": {"repobilityId": "166df24189df06c3", "scanner": "scanner-primary", "fingerprint": "7a6f42618812c605", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f66d9e887ef3ba2f", "level": "note", "message": {"text": "Legacy-named symbol `test_add_item_to_work_adds_copy` in tests/integration/test_catalog.py:92"}, "properties": {"repobilityId": "7deba931ecc1780a", "scanner": "scanner-primary", "fingerprint": "f66d9e887ef3ba2f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-74f8a2efb23264a5", "level": "note", "message": {"text": "Legacy-named symbol `added_copy` in tests/integration/test_import_export_api.py:217"}, "properties": {"repobilityId": "6499ec262622dde6", "scanner": "scanner-primary", "fingerprint": "74f8a2efb23264a5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1466429ab0df23b0", "level": "none", "message": {"text": "Commented-code block (8 lines) in tests/integration/test_backup.py:382"}, "properties": {"repobilityId": "37d5e720452bfbbc", "scanner": "scanner-primary", "fingerprint": "1466429ab0df23b0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-52d0111c5bc077b5", "level": "note", "message": {"text": "Legacy-named symbol `test_place_hold_succeeds_with_one_loanable_copy` in tests/integration/test_holds.py:143"}, "properties": {"repobilityId": "8d9a590161157d04", "scanner": "scanner-primary", "fingerprint": "52d0111c5bc077b5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-68a33c1a14a81b31", "level": "note", "message": {"text": "Legacy-named symbol `added_copy` in tests/integration/test_import_export_lt.py:146"}, "properties": {"repobilityId": "8721184f4105ae49", "scanner": "scanner-primary", "fingerprint": "68a33c1a14a81b31", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-173b8c6f92e98807", "level": "note", "message": {"text": "Legacy-named symbol `ReturnOld` in tests/integration/test_discovery.py:209"}, "properties": {"repobilityId": "5933443014e56bab", "scanner": "scanner-primary", "fingerprint": "173b8c6f92e98807", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b3c887bcfa83011b", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/unit/test_calendar_service.py:259"}, "properties": {"repobilityId": "a98b42ff8eb5fdec", "scanner": "scanner-primary", "fingerprint": "b3c887bcfa83011b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8eb013ba86cac20f", "level": "note", "message": {"text": "Legacy-named symbol `t_old` in tests/unit/test_item_note_repository.py:107"}, "properties": {"repobilityId": "9eccdb032e983045", "scanner": "scanner-primary", "fingerprint": "8eb013ba86cac20f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-223bc8ea1d2d4042", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/unit/test_settings_registry.py:312"}, "properties": {"repobilityId": "0a603ade5e038418", "scanner": "scanner-primary", "fingerprint": "223bc8ea1d2d4042", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-62cf475cbf050d4e", "level": "note", "message": {"text": "Legacy-named symbol `available_copy` in tests/unit/test_hold_service.py:34"}, "properties": {"repobilityId": "f812c1c794d0de42", "scanner": "scanner-primary", "fingerprint": "62cf475cbf050d4e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1b69474471166866", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/render_label_matrix.py:71"}, "properties": {"repobilityId": "6fa3497582b0687e", "scanner": "scanner-primary", "fingerprint": "1b69474471166866", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c5c74858fdfdb9bd", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/compendium/api/app.py:212"}, "properties": {"repobilityId": "9f8577fd45593ca9", "scanner": "scanner-primary", "fingerprint": "c5c74858fdfdb9bd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4f581dc8b752619e", "level": "note", "message": {"text": "Stub function `_main` (body is just `pass`/`return`) \u2014 src/compendium/cli/main.py:51"}, "properties": {"repobilityId": "649e4e29a258a65d", "scanner": "scanner-primary", "fingerprint": "4f581dc8b752619e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "empty-handler", "dead-code"]}}, {"ruleId": "scanner-27822964cb928051", "level": "note", "message": {"text": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/services/holds.py:125"}, "properties": {"repobilityId": "5509b7e4a94e96c1", "scanner": "scanner-primary", "fingerprint": "27822964cb928051", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2ed0e7386801c7ef", "level": "note", "message": {"text": "Legacy-named symbol `added_copy` in src/compendium/services/catalog.py:1063"}, "properties": {"repobilityId": "37fcf33b73bf1c2f", "scanner": "scanner-primary", "fingerprint": "2ed0e7386801c7ef", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f5648d0a7bb58b17", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/compendium/services/settings_registry.py:603"}, "properties": {"repobilityId": "45edcfcaf045068c", "scanner": "scanner-primary", "fingerprint": "f5648d0a7bb58b17", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-40b8f72c0855bda1", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/compendium/services/labels.py:35"}, "properties": {"repobilityId": "322bf14a1ecc791e", "scanner": "scanner-primary", "fingerprint": "40b8f72c0855bda1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4e558c7d4539ff6e", "level": "note", "message": {"text": "Legacy-named symbol `added_copy` in src/compendium/services/import_export.py:509"}, "properties": {"repobilityId": "bf5aae47f8cf70e3", "scanner": "scanner-primary", "fingerprint": "4e558c7d4539ff6e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b7e7d380b0eb9f07", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/compendium/services/import_export.py:933"}, "properties": {"repobilityId": "cdbd5c444e352cb0", "scanner": "scanner-primary", "fingerprint": "b7e7d380b0eb9f07", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-615d0d920b7c4555", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/compendium/db/engine.py:73"}, "properties": {"repobilityId": "940f5c2b636947af", "scanner": "scanner-primary", "fingerprint": "615d0d920b7c4555", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5c503d19e29d264f", "level": "note", "message": {"text": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/repositories/base.py:99"}, "properties": {"repobilityId": "ff3b71b6a45c133d", "scanner": "scanner-primary", "fingerprint": "5c503d19e29d264f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4e359b6430628a21", "level": "note", "message": {"text": "Legacy-named symbol `first_available_loanable_copy` in src/compendium/repositories/sql/work_repository.py:97"}, "properties": {"repobilityId": "63c4cf773cc1066f", "scanner": "scanner-primary", "fingerprint": "4e359b6430628a21", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-af022f937dd5b7fd", "level": "note", "message": {"text": "9 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "5597384795dea7a4", "scanner": "scanner-primary", "fingerprint": "af022f937dd5b7fd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "cf5534da00366dc2", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "e6d2d1701d7d3a48", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "22f3e5169455ed65", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "bde51eb6c4603d59", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "85d989750441d0c0", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "496ce6614788d712", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "da43b2887de69feb", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-02525d39071dd2c7", "level": "note", "message": {"text": "Near-duplicate function bodies in 5 places"}, "properties": {"repobilityId": "004ccb871485f0e4", "scanner": "scanner-primary", "fingerprint": "02525d39071dd2c7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "4fc2313df61776dc", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "bedbe7cd2d96387a", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "0b4f488854446665", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "ac868ee70ac11481", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "629a15f0c40b5a91", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "14f911f99d9bbf4f", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "99d9f2bc5d2143b4", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "1fc48fcea176f055", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "389acd5464a3b21a", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "ffd602e37476fbb8", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "6e1942a2d585c07a", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "e44df63885bfd771", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-f3dfabf5f2f85528", "level": "error", "message": {"text": "FastAPI POST `item_create_manual` without auth dependency \u2014 src/compendium/web/routes/items.py:288"}, "properties": {"repobilityId": "cf7a16fa322aed06", "scanner": "scanner-primary", "fingerprint": "f3dfabf5f2f85528", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/items.py"}, "region": {"startLine": 288}}}]}, {"ruleId": "scanner-43be01f8ae79a04f", "level": "error", "message": {"text": "FastAPI POST `edit_pending_save` without auth dependency \u2014 src/compendium/web/routes/scan.py:890"}, "properties": {"repobilityId": "2133cde4ace5ac50", "scanner": "scanner-primary", "fingerprint": "43be01f8ae79a04f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/scan.py"}, "region": {"startLine": 890}}}]}, {"ruleId": "scanner-e0603fba69ece6ab", "level": "error", "message": {"text": "FastAPI POST `work_edit_submit` without auth dependency \u2014 src/compendium/web/routes/catalog.py:380"}, "properties": {"repobilityId": "ccf2172f57afb4a0", "scanner": "scanner-primary", "fingerprint": "e0603fba69ece6ab", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/catalog.py"}, "region": {"startLine": 380}}}]}, {"ruleId": "scanner-1766cc75c216eb78", "level": "error", "message": {"text": "FastAPI POST `import_submit` without auth dependency \u2014 src/compendium/web/routes/bulk.py:268"}, "properties": {"repobilityId": "ea5b4d361f62338d", "scanner": "scanner-primary", "fingerprint": "1766cc75c216eb78", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/bulk.py"}, "region": {"startLine": 268}}}]}, {"ruleId": "scanner-b74540c51150b206", "level": "error", "message": {"text": "FastAPI POST `user_create` without auth dependency \u2014 src/compendium/web/routes/users.py:129"}, "properties": {"repobilityId": "c74a098d08dd4c26", "scanner": "scanner-primary", "fingerprint": "b74540c51150b206", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/users.py"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-87c9737578d1c768", "level": "error", "message": {"text": "FastAPI POST `policy_update` without auth dependency \u2014 src/compendium/web/routes/policies.py:138"}, "properties": {"repobilityId": "8638b51893d1f5eb", "scanner": "scanner-primary", "fingerprint": "87c9737578d1c768", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/policies.py"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-a3b4e88e97505a34", "level": "error", "message": {"text": "FastAPI POST `patron_create` without auth dependency \u2014 src/compendium/web/routes/patrons.py:144"}, "properties": {"repobilityId": "48e13ee75e8d08c0", "scanner": "scanner-primary", "fingerprint": "a3b4e88e97505a34", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/compendium/web/routes/patrons.py"}, "region": {"startLine": 144}}}]}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "6a9545811eed707d", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-da2ce8c5b380ae8b", "level": "note", "message": {"text": "Unused endpoint: POST /{notification_id}/retry"}, "properties": {"repobilityId": "1f21841c0654ee22", "scanner": "scanner-primary", "fingerprint": "da2ce8c5b380ae8b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b83ad31b50d48ece", "level": "note", "message": {"text": "Unused endpoint: GET /library-hours/"}, "properties": {"repobilityId": "c6e648c270a17b95", "scanner": "scanner-primary", "fingerprint": "b83ad31b50d48ece", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd2d35e48e6019b8", "level": "note", "message": {"text": "Unused endpoint: PATCH /library-hours/{weekday}"}, "properties": {"repobilityId": "733b235ae4f7d20b", "scanner": "scanner-primary", "fingerprint": "dd2d35e48e6019b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed47dca4e8069659", "level": "note", "message": {"text": "Unused endpoint: GET /closed-dates/"}, "properties": {"repobilityId": "0a6c83458d16544c", "scanner": "scanner-primary", "fingerprint": "ed47dca4e8069659", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-47a30b46c4821bd6", "level": "note", "message": {"text": "Unused endpoint: POST /closed-dates/"}, "properties": {"repobilityId": "4ef90a2029e64685", "scanner": "scanner-primary", "fingerprint": "47a30b46c4821bd6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4f4c319a9e792679", "level": "note", "message": {"text": "Unused endpoint: PATCH /closed-dates/{closed_date_id}"}, "properties": {"repobilityId": "f37f250d10887c79", "scanner": "scanner-primary", "fingerprint": "4f4c319a9e792679", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-69956a1d8bedbe45", "level": "note", "message": {"text": "Unused endpoint: DELETE /closed-dates/{closed_date_id}"}, "properties": {"repobilityId": "bb92363df1302183", "scanner": "scanner-primary", "fingerprint": "69956a1d8bedbe45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fa699835e925105d", "level": "note", "message": {"text": "Unused endpoint: POST /loans/checkout"}, "properties": {"repobilityId": "ce4a1b4a3d9bf552", "scanner": "scanner-primary", "fingerprint": "fa699835e925105d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff03d30994b9cd31", "level": "note", "message": {"text": "Unused endpoint: POST /loans/{loan_id}/checkin"}, "properties": {"repobilityId": "17267a667b1fd239", "scanner": "scanner-primary", "fingerprint": "ff03d30994b9cd31", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1966383c5747d526", "level": "note", "message": {"text": "Unused endpoint: POST /loans/{loan_id}/renew"}, "properties": {"repobilityId": "14b79e0ed4efb9c5", "scanner": "scanner-primary", "fingerprint": "1966383c5747d526", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a94e3c5b6607e329", "level": "note", "message": {"text": "Unused endpoint: GET /loans"}, "properties": {"repobilityId": "53f4c5be0a68eabf", "scanner": "scanner-primary", "fingerprint": "a94e3c5b6607e329", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65388cf31e8ecdc8", "level": "note", "message": {"text": "Unused endpoint: GET /loans/patron/{card_number}"}, "properties": {"repobilityId": "29142a8b7a8b37a5", "scanner": "scanner-primary", "fingerprint": "65388cf31e8ecdc8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55203b3fb1c0f67f", "level": "note", "message": {"text": "Unused endpoint: GET /loans/item/{barcode}"}, "properties": {"repobilityId": "5a6d3aaf0feaeae8", "scanner": "scanner-primary", "fingerprint": "55203b3fb1c0f67f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-276e148687d4f73e", "level": "note", "message": {"text": "Unused endpoint: GET /reports/checkouts"}, "properties": {"repobilityId": "855ca8fbc8ae1077", "scanner": "scanner-primary", "fingerprint": "276e148687d4f73e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-965bb299a9b4dd6c", "level": "note", "message": {"text": "Unused endpoint: GET /reports/popular"}, "properties": {"repobilityId": "1c4dbf4cda10c7dc", "scanner": "scanner-primary", "fingerprint": "965bb299a9b4dd6c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d339dda0eb394971", "level": "note", "message": {"text": "Unused endpoint: GET /reports/dormant"}, "properties": {"repobilityId": "86c0ee3b35215b04", "scanner": "scanner-primary", "fingerprint": "d339dda0eb394971", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3280a38285630dfa", "level": "note", "message": {"text": "Unused endpoint: GET /reports/overdues"}, "properties": {"repobilityId": "150f8391980314b1", "scanner": "scanner-primary", "fingerprint": "3280a38285630dfa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6fce1f96dd8860f0", "level": "note", "message": {"text": "Unused endpoint: GET /branches/"}, "properties": {"repobilityId": "7dbdf80962a791d5", "scanner": "scanner-primary", "fingerprint": "6fce1f96dd8860f0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5316f9f6e60d082c", "level": "note", "message": {"text": "Unused endpoint: PATCH /branches/{branch_id}"}, "properties": {"repobilityId": "5ec07ed34a9b0681", "scanner": "scanner-primary", "fingerprint": "5316f9f6e60d082c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-82572b7132f3d730", "level": "note", "message": {"text": "Unused endpoint: GET /{card_number}/fines"}, "properties": {"repobilityId": "3e3b918f1160b56a", "scanner": "scanner-primary", "fingerprint": "82572b7132f3d730", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0e765a95850f2f8", "level": "note", "message": {"text": "Unused endpoint: POST /{card_number}/fines/assess-overdue"}, "properties": {"repobilityId": "467a49490cfe0423", "scanner": "scanner-primary", "fingerprint": "a0e765a95850f2f8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "0dacf2ff3c657a52", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab101fcde60b507a", "level": "note", "message": {"text": "Unused endpoint: POST /{fine_id}/pay"}, "properties": {"repobilityId": "285982f4dd1f3400", "scanner": "scanner-primary", "fingerprint": "ab101fcde60b507a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-844b0025e620fb6b", "level": "note", "message": {"text": "Unused endpoint: POST /{fine_id}/waive"}, "properties": {"repobilityId": "71cae52d47ed479f", "scanner": "scanner-primary", "fingerprint": "844b0025e620fb6b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8de438f5fe08ea4e", "level": "note", "message": {"text": "Unused endpoint: GET /fines"}, "properties": {"repobilityId": "9772c8b655125e02", "scanner": "scanner-primary", "fingerprint": "8de438f5fe08ea4e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8cab827ff79810c3", "level": "note", "message": {"text": "Unused endpoint: PATCH /creators/{creator_id}"}, "properties": {"repobilityId": "1a2dac5678672951", "scanner": "scanner-primary", "fingerprint": "8cab827ff79810c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdbacfe9430a6ed", "level": "note", "message": {"text": "Unused endpoint: POST /auth/login"}, "properties": {"repobilityId": "722f8ca25859bd30", "scanner": "scanner-primary", "fingerprint": "8fdbacfe9430a6ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-93315e2a5fd371d4", "level": "note", "message": {"text": "Unused endpoint: POST /households"}, "properties": {"repobilityId": "a7ca7005e911ff8d", "scanner": "scanner-primary", "fingerprint": "93315e2a5fd371d4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb4896467dce6096", "level": "note", "message": {"text": "Unused endpoint: GET /households"}, "properties": {"repobilityId": "1a9ca742e9d945d3", "scanner": "scanner-primary", "fingerprint": "bb4896467dce6096", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00ebe6fedc4c80e5", "level": "note", "message": {"text": "Unused endpoint: GET /households/{household_id}"}, "properties": {"repobilityId": "1da04f889b6446f0", "scanner": "scanner-primary", "fingerprint": "00ebe6fedc4c80e5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d53f4e2e944adda8", "level": "note", "message": {"text": "Unused endpoint: PATCH /households/{household_id}"}, "properties": {"repobilityId": "ca9674ee762758f7", "scanner": "scanner-primary", "fingerprint": "d53f4e2e944adda8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-107b59a6100c61a1", "level": "note", "message": {"text": "Unused endpoint: DELETE /households/{household_id}"}, "properties": {"repobilityId": "4fe459468f103996", "scanner": "scanner-primary", "fingerprint": "107b59a6100c61a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d152462fa925131", "level": "note", "message": {"text": "Unused endpoint: POST /households/{household_id}/members"}, "properties": {"repobilityId": "957bcc4188de6b35", "scanner": "scanner-primary", "fingerprint": "8d152462fa925131", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2b94c0882cfbc759", "level": "note", "message": {"text": "Unused endpoint: DELETE /households/{household_id}/members/{card_number}"}, "properties": {"repobilityId": "74020b70126aa19f", "scanner": "scanner-primary", "fingerprint": "2b94c0882cfbc759", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-18f08ca36ea113c1", "level": "note", "message": {"text": "Unused endpoint: GET /items/{barcode}"}, "properties": {"repobilityId": "ba4656c201659f19", "scanner": "scanner-primary", "fingerprint": "18f08ca36ea113c1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4398ba9ef555ab55", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/withdraw"}, "properties": {"repobilityId": "aa3b874cf2a9046d", "scanner": "scanner-primary", "fingerprint": "4398ba9ef555ab55", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba53bd75cdaf87b7", "level": "note", "message": {"text": "Unused endpoint: PATCH /items/{barcode}"}, "properties": {"repobilityId": "747e435f5845c328", "scanner": "scanner-primary", "fingerprint": "ba53bd75cdaf87b7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3fb3b115603d26ac", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/loanable"}, "properties": {"repobilityId": "2da2187294eec5e4", "scanner": "scanner-primary", "fingerprint": "3fb3b115603d26ac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-62aa5af7266432a0", "level": "note", "message": {"text": "Unused endpoint: GET /items/{barcode}/notes"}, "properties": {"repobilityId": "00f80503b524f742", "scanner": "scanner-primary", "fingerprint": "62aa5af7266432a0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8ac919a6058f1e1", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/notes"}, "properties": {"repobilityId": "853ccf62ab779c34", "scanner": "scanner-primary", "fingerprint": "f8ac919a6058f1e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-924e7fedede00d81", "level": "note", "message": {"text": "Unused endpoint: DELETE /items/{barcode}/notes/{note_id}"}, "properties": {"repobilityId": "d4f022be882a8f63", "scanner": "scanner-primary", "fingerprint": "924e7fedede00d81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c305e4c7b1be169", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/lost"}, "properties": {"repobilityId": "5658f059f281d26c", "scanner": "scanner-primary", "fingerprint": "2c305e4c7b1be169", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a21bb873dd9d6e84", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/damaged"}, "properties": {"repobilityId": "eaa43b1faf7f07a8", "scanner": "scanner-primary", "fingerprint": "a21bb873dd9d6e84", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d6f29ef9908ecac5", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/clear-damage"}, "properties": {"repobilityId": "454533b1702b7717", "scanner": "scanner-primary", "fingerprint": "d6f29ef9908ecac5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eec7959930332735", "level": "note", "message": {"text": "Unused endpoint: POST /items/{barcode}/clear-lost"}, "properties": {"repobilityId": "a2cc2b4a48159d71", "scanner": "scanner-primary", "fingerprint": "eec7959930332735", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cea2e3b1566c12be", "level": "note", "message": {"text": "Unused endpoint: GET /patron-categories/"}, "properties": {"repobilityId": "f0c31054ff3a62bd", "scanner": "scanner-primary", "fingerprint": "cea2e3b1566c12be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-28eb91b5fb3eec35", "level": "note", "message": {"text": "Unused endpoint: POST /patron-categories/"}, "properties": {"repobilityId": "5d0a371c566d7742", "scanner": "scanner-primary", "fingerprint": "28eb91b5fb3eec35", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-83e85e9154c1aa9f", "level": "note", "message": {"text": "Unused endpoint: PATCH /patron-categories/{category_id}"}, "properties": {"repobilityId": "05225b7d0f42aedc", "scanner": "scanner-primary", "fingerprint": "83e85e9154c1aa9f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a2592f78c9e8344d", "level": "note", "message": {"text": "Unused endpoint: DELETE /patron-categories/{category_id}"}, "properties": {"repobilityId": "6972cb63c19f0201", "scanner": "scanner-primary", "fingerprint": "a2592f78c9e8344d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}