{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-223c773ceb36583c", "name": "Possibly dead Python function: recognize", "shortDescription": {"text": "Possibly dead Python function: recognize"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57b75ad46eeffa99", "name": "Possibly dead Python function: make_engine", "shortDescription": {"text": "Possibly dead Python function: make_engine"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df75799b5fca7b4e", "name": "Possibly dead Python function: health", "shortDescription": {"text": "Possibly dead Python function: health"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1f8959867f5f0e1", "name": "Possibly dead Python function: send_event", "shortDescription": {"text": "Possibly dead Python function: send_event"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7baf29f045c2e863", "name": "Possibly dead Python function: add_service", "shortDescription": {"text": "Possibly dead Python function: add_service"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-855d976e16cf4244", "name": "Possibly dead Python function: remove_service", "shortDescription": {"text": "Possibly dead Python function: remove_service"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf56d4d6f474d34b", "name": "Possibly dead Python function: update_service", "shortDescription": {"text": "Possibly dead Python function: update_service"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0cc0ce38f840ca4", "name": "Possibly dead Python function: write_credentials", "shortDescription": {"text": "Possibly dead Python function: write_credentials"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6cb2a7b2dacb6fc5", "name": "Possibly dead Python function: current_user", "shortDescription": {"text": "Possibly dead Python function: current_user"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84b9953260af951a", "name": "Possibly dead Python function: current_device", "shortDescription": {"text": "Possibly dead Python function: current_device"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92fec37ad6e756ca", "name": "Possibly dead Python function: run_once", "shortDescription": {"text": "Possibly dead Python function: run_once"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b0a84f4cdd980d0", "name": "Possibly dead Python function: run_once", "shortDescription": {"text": "Possibly dead Python function: run_once"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00d688c0b7b18d93", "name": "Possibly dead Python function: list_models", "shortDescription": {"text": "Possibly dead Python function: list_models"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1008ba42d2ecb703", "name": "Possibly dead Python function: generate_with_image_path", "shortDescription": {"text": "Possibly dead Python function: generate_with_image_path"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c49b5658bc842d7a", "name": "Possibly dead Python function: pull", "shortDescription": {"text": "Possibly dead Python function: pull"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e0a863b43eeba25", "name": "`truncate` class without `title=` for hover reveal \u2014 dashboard/src/components/PipelineHealth.tsx:161", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 dashboard/src/components/PipelineHealth.tsx:161"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9ceb16f9a1ca7f9c", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 backend/app/static/assets/index-BwTxGcoF.js:33", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 backend/app/static/assets/index-BwTxGcoF.js:33"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c7361e1b87d5d7e", "name": "Privileged port 587 in use", "shortDescription": {"text": "Privileged port 587 in use"}, "fullDescription": {"text": "Port 587 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3404fcfc69b0c4d7", "name": "Privileged port 465 in use", "shortDescription": {"text": "Privileged port 465 in use"}, "fullDescription": {"text": "Port 465 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4aaa6ca698e1fdfd", "name": "Possible secret in backend/app/static/assets/index-BwTxGcoF.js", "shortDescription": {"text": "Possible secret in backend/app/static/assets/index-BwTxGcoF.js"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-f0b366d8adb67339", "name": "Insecure pattern 'direct_innerhtml_assignment' in backend/app/static/assets/index-BwTxGcoF.js:37", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in backend/app/static/assets/index-BwTxGcoF.js:37"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de39ac9e5cbf2f3d", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/deploy-pages@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3345532e49ae8640", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a8ed4a016475288e", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "softprops/action-gh-release@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d76ce5e6455a26a7", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 19 placeholder/mock markers across 7 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-63e154d322a30c23", "name": "Commented-code block (5 lines) in dashboard/src/utils/datetime.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in dashboard/src/utils/datetime.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-caedaa8b4177eb3e", "name": "Commented-code block (5 lines) in agent-windows/src/config.py:33", "shortDescription": {"text": "Commented-code block (5 lines) in agent-windows/src/config.py:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-61bd7bf773d45006", "name": "Commented-code block (6 lines) in agent-windows/src/tray_app.py:94", "shortDescription": {"text": "Commented-code block (6 lines) in agent-windows/src/tray_app.py:94"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6cbe6cc548e44a26", "name": "Commented-code block (5 lines) in agent-windows/src/main.py:47", "shortDescription": {"text": "Commented-code block (5 lines) in agent-windows/src/main.py:47"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0a9751f2e0e0b0f7", "name": "Commented-code block (12 lines) in agent-windows/src/hardware_probe.py:97", "shortDescription": {"text": "Commented-code block (12 lines) in agent-windows/src/hardware_probe.py:97"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-55e06b6609a34eb4", "name": "Commented-code block (16 lines) in backend/app/settings.py:41", "shortDescription": {"text": "Commented-code block (16 lines) in backend/app/settings.py:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-22b17441f4e204e9", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/app/static/assets/index-BwTxGcoF.js:1", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/app/static/assets/index-BwTxGcoF.js:1"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6a15b9be26e1234", "name": "Commented-code block (6 lines) in backend/app/services/parent_auth.py:10", "shortDescription": {"text": "Commented-code block (6 lines) in backend/app/services/parent_auth.py:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nagent-windows/src/ocr_engine.py:recognize, agent-windows/src/ocr_engine.py:recognize, agent-windows/src/ocr_engine.py:recognize, agent-windows/src/ocr_engine.py:recognize\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/app/api/devices.py:resume_device, backend/app/api/devices.py:revoke_device\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa7d7a6110471f62", "name": "FastAPI POST `recovery_reset` without auth dependency \u2014 backend/app/api/auth.py:91", "shortDescription": {"text": "FastAPI POST `recovery_reset` without auth dependency \u2014 backend/app/api/auth.py:91"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b01c5f7ccc9e79ec", "name": "FastAPI POST `setup` without auth dependency \u2014 backend/app/api/auth.py:122", "shortDescription": {"text": "FastAPI POST `setup` without auth dependency \u2014 backend/app/api/auth.py:122"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-109a2e248ae08518", "name": "FastAPI POST `get_recovery_code` without auth dependency \u2014 backend/app/api/setup.py:32", "shortDescription": {"text": "FastAPI POST `get_recovery_code` without auth dependency \u2014 backend/app/api/setup.py:32"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6b6872a9c2e9f2f5", "name": "FastAPI POST `ingest` without auth dependency \u2014 backend/app/api/events.py:48", "shortDescription": {"text": "FastAPI POST `ingest` without auth dependency \u2014 backend/app/api/events.py:48"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f8ab3b6fcb3f06b", "name": "FastAPI POST `ingest_screenshot` without auth dependency \u2014 backend/app/api/events.py:153", "shortDescription": {"text": "FastAPI POST `ingest_screenshot` without auth dependency \u2014 backend/app/api/events.py:153"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-59f472e391aefbd5", "name": "FastAPI POST `create_child_request` without auth dependency \u2014 backend/app/api/child_requests.py:39", "shortDescription": {"text": "FastAPI POST `create_child_request` without auth dependency \u2014 backend/app/api/child_requests.py:39"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a2b951472a887771", "name": "FastAPI POST `pair_complete` without auth dependency \u2014 backend/app/api/devices.py:135", "shortDescription": {"text": "FastAPI POST `pair_complete` without auth dependency \u2014 backend/app/api/devices.py:135"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce524fdf3170b7a1", "name": "FastAPI POST `heartbeat` without auth dependency \u2014 backend/app/api/devices.py:222", "shortDescription": {"text": "FastAPI POST `heartbeat` without auth dependency \u2014 backend/app/api/devices.py:222"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c74e9db290bbb24", "name": "Dangling fetch: GET /setup/status (dashboard/src/api.ts:24)", "shortDescription": {"text": "Dangling fetch: GET /setup/status (dashboard/src/api.ts:24)"}, "fullDescription": {"text": "`dashboard/src/api.ts:24` calls `GET /setup/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/setup/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92cddb4e0f84096e", "name": "Dangling fetch: POST /setup/recovery (dashboard/src/api.ts:25)", "shortDescription": {"text": "Dangling fetch: POST /setup/recovery (dashboard/src/api.ts:25)"}, "fullDescription": {"text": "`dashboard/src/api.ts:25` calls `POST /setup/recovery` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/setup/recovery`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7cf1aeda65c0ccd4", "name": "Dangling fetch: POST /auth/setup (dashboard/src/api.ts:27)", "shortDescription": {"text": "Dangling fetch: POST /auth/setup (dashboard/src/api.ts:27)"}, "fullDescription": {"text": "`dashboard/src/api.ts:27` calls `POST /auth/setup` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/setup`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-23d155f14b1c57c6", "name": "Dangling fetch: POST /auth/login (dashboard/src/api.ts:29)", "shortDescription": {"text": "Dangling fetch: POST /auth/login (dashboard/src/api.ts:29)"}, "fullDescription": {"text": "`dashboard/src/api.ts:29` calls `POST /auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76b7cb990ee3714f", "name": "Dangling fetch: POST /auth/logout (dashboard/src/api.ts:30)", "shortDescription": {"text": "Dangling fetch: POST /auth/logout (dashboard/src/api.ts:30)"}, "fullDescription": {"text": "`dashboard/src/api.ts:30` calls `POST /auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5cf5940df8f11901", "name": "Dangling fetch: GET /auth/me (dashboard/src/api.ts:31)", "shortDescription": {"text": "Dangling fetch: GET /auth/me (dashboard/src/api.ts:31)"}, "fullDescription": {"text": "`dashboard/src/api.ts:31` calls `GET /auth/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4286c78bcee0e5b7", "name": "Dangling fetch: POST /auth/recovery-reset (dashboard/src/api.ts:33)", "shortDescription": {"text": "Dangling fetch: POST /auth/recovery-reset (dashboard/src/api.ts:33)"}, "fullDescription": {"text": "`dashboard/src/api.ts:33` calls `POST /auth/recovery-reset` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/recovery-reset`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ebb10cae3d57e73", "name": "Dangling fetch: GET /dashboard/overview (dashboard/src/api.ts:37)", "shortDescription": {"text": "Dangling fetch: GET /dashboard/overview (dashboard/src/api.ts:37)"}, "fullDescription": {"text": "`dashboard/src/api.ts:37` calls `GET /dashboard/overview` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/dashboard/overview`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93c2915c7bc99ceb", "name": "Dangling fetch: GET /devices (dashboard/src/api.ts:38)", "shortDescription": {"text": "Dangling fetch: GET /devices (dashboard/src/api.ts:38)"}, "fullDescription": {"text": "`dashboard/src/api.ts:38` calls `GET /devices` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/devices`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-02802273d95b3a00", "name": "Dangling fetch: POST /devices/pair/start (dashboard/src/api.ts:39)", "shortDescription": {"text": "Dangling fetch: POST /devices/pair/start (dashboard/src/api.ts:39)"}, "fullDescription": {"text": "`dashboard/src/api.ts:39` calls `POST /devices/pair/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/devices/pair/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-798d4fe88c76d8ce", "name": "Dangling fetch: POST /devices/${device_id}/pause (dashboard/src/api.ts:41)", "shortDescription": {"text": "Dangling fetch: POST /devices/${device_id}/pause (dashboard/src/api.ts:41)"}, "fullDescription": {"text": "`dashboard/src/api.ts:41` calls `POST /devices/${device_id}/pause` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/devices/<p>/pause`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-582df840bcd2ee4c", "name": "Dangling fetch: POST /devices/${device_id}/resume (dashboard/src/api.ts:43)", "shortDescription": {"text": "Dangling fetch: POST /devices/${device_id}/resume (dashboard/src/api.ts:43)"}, "fullDescription": {"text": "`dashboard/src/api.ts:43` calls `POST /devices/${device_id}/resume` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/devices/<p>/resume`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-82aac12b1cbc6e3c", "name": "Dangling fetch: DELETE /devices/${device_id} (dashboard/src/api.ts:45)", "shortDescription": {"text": "Dangling fetch: DELETE /devices/${device_id} (dashboard/src/api.ts:45)"}, "fullDescription": {"text": "`dashboard/src/api.ts:45` calls `DELETE /devices/${device_id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/devices/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ffc1f52137406039", "name": "Dangling fetch: PATCH /devices/${device_id}/profile (dashboard/src/api.ts:47)", "shortDescription": {"text": "Dangling fetch: PATCH /devices/${device_id}/profile (dashboard/src/api.ts:47)"}, "fullDescription": {"text": "`dashboard/src/api.ts:47` calls `PATCH /devices/${device_id}/profile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/devices/<p>/profile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-99069603c353e694", "name": "Dangling fetch: GET /alerts/${id} (dashboard/src/api.ts:52)", "shortDescription": {"text": "Dangling fetch: GET /alerts/${id} (dashboard/src/api.ts:52)"}, "fullDescription": {"text": "`dashboard/src/api.ts:52` calls `GET /alerts/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/alerts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b1f7afab9e2f6e8", "name": "Dangling fetch: POST /alerts/${id}/review (dashboard/src/api.ts:54)", "shortDescription": {"text": "Dangling fetch: POST /alerts/${id}/review (dashboard/src/api.ts:54)"}, "fullDescription": {"text": "`dashboard/src/api.ts:54` calls `POST /alerts/${id}/review` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/alerts/<p>/review`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3dc929fffe6a7844", "name": "Dangling fetch: POST /alerts/${id}/feedback (dashboard/src/api.ts:56)", "shortDescription": {"text": "Dangling fetch: POST /alerts/${id}/feedback (dashboard/src/api.ts:56)"}, "fullDescription": {"text": "`dashboard/src/api.ts:56` calls `POST /alerts/${id}/feedback` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/alerts/<p>/feedback`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5129d92bb1d992dd", "name": "Dangling fetch: GET /models/status (dashboard/src/api.ts:57)", "shortDescription": {"text": "Dangling fetch: GET /models/status (dashboard/src/api.ts:57)"}, "fullDescription": {"text": "`dashboard/src/api.ts:57` calls `GET /models/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/models/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d79ffe2a453a0cde", "name": "Dangling fetch: POST /models/test (dashboard/src/api.ts:58)", "shortDescription": {"text": "Dangling fetch: POST /models/test (dashboard/src/api.ts:58)"}, "fullDescription": {"text": "`dashboard/src/api.ts:58` calls `POST /models/test` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/models/test`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-173b52c2cfa8a26e", "name": "Dangling fetch: GET /profiles (dashboard/src/api.ts:59)", "shortDescription": {"text": "Dangling fetch: GET /profiles (dashboard/src/api.ts:59)"}, "fullDescription": {"text": "`dashboard/src/api.ts:59` calls `GET /profiles` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/profiles`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f3efce18b8fa90e", "name": "Dangling fetch: POST /profiles (dashboard/src/api.ts:66)", "shortDescription": {"text": "Dangling fetch: POST /profiles (dashboard/src/api.ts:66)"}, "fullDescription": {"text": "`dashboard/src/api.ts:66` calls `POST /profiles` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/profiles`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-367d3d5f14ea4b28", "name": "Dangling fetch: PATCH /profiles/${profile_id} (dashboard/src/api.ts:81)", "shortDescription": {"text": "Dangling fetch: PATCH /profiles/${profile_id} (dashboard/src/api.ts:81)"}, "fullDescription": {"text": "`dashboard/src/api.ts:81` calls `PATCH /profiles/${profile_id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/profiles/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-952548df5010bbf1", "name": "Dangling fetch: GET /profiles/policy/meta (dashboard/src/api.ts:85)", "shortDescription": {"text": "Dangling fetch: GET /profiles/policy/meta (dashboard/src/api.ts:85)"}, "fullDescription": {"text": "`dashboard/src/api.ts:85` calls `GET /profiles/policy/meta` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/profiles/policy/meta`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ae5c4aeb73199ea", "name": "Dangling fetch: GET /settings/notifications (dashboard/src/api.ts:86)", "shortDescription": {"text": "Dangling fetch: GET /settings/notifications (dashboard/src/api.ts:86)"}, "fullDescription": {"text": "`dashboard/src/api.ts:86` calls `GET /settings/notifications` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/notifications`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3e99f284cf18640c", "name": "Dangling fetch: PATCH /settings/notifications (dashboard/src/api.ts:88)", "shortDescription": {"text": "Dangling fetch: PATCH /settings/notifications (dashboard/src/api.ts:88)"}, "fullDescription": {"text": "`dashboard/src/api.ts:88` calls `PATCH /settings/notifications` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/notifications`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f7806df46adde7a", "name": "Dangling fetch: POST /settings/notifications/test (dashboard/src/api.ts:90)", "shortDescription": {"text": "Dangling fetch: POST /settings/notifications/test (dashboard/src/api.ts:90)"}, "fullDescription": {"text": "`dashboard/src/api.ts:90` calls `POST /settings/notifications/test` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/notifications/test`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-91c50787641fc161", "name": "Dangling fetch: GET /settings/retention (dashboard/src/api.ts:91)", "shortDescription": {"text": "Dangling fetch: GET /settings/retention (dashboard/src/api.ts:91)"}, "fullDescription": {"text": "`dashboard/src/api.ts:91` calls `GET /settings/retention` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/retention`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8c5b8c63a90ea8f9", "name": "Dangling fetch: PATCH /settings/retention (dashboard/src/api.ts:93)", "shortDescription": {"text": "Dangling fetch: PATCH /settings/retention (dashboard/src/api.ts:93)"}, "fullDescription": {"text": "`dashboard/src/api.ts:93` calls `PATCH /settings/retention` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/retention`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6ff2b5d6e389ebd", "name": "Dangling fetch: POST /settings/retention/run-cleanup (dashboard/src/api.ts:95)", "shortDescription": {"text": "Dangling fetch: POST /settings/retention/run-cleanup (dashboard/src/api.ts:95)"}, "fullDescription": {"text": "`dashboard/src/api.ts:95` calls `POST /settings/retention/run-cleanup` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/retention/run-cleanup`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-146f4c53d8f51920", "name": "Dangling fetch: GET /storage (dashboard/src/api.ts:96)", "shortDescription": {"text": "Dangling fetch: GET /storage (dashboard/src/api.ts:96)"}, "fullDescription": {"text": "`dashboard/src/api.ts:96` calls `GET /storage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/storage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dcecfcd5130a6abc", "name": "Dangling fetch: POST /storage/export (dashboard/src/api.ts:97)", "shortDescription": {"text": "Dangling fetch: POST /storage/export (dashboard/src/api.ts:97)"}, "fullDescription": {"text": "`dashboard/src/api.ts:97` calls `POST /storage/export` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/storage/export`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a36141f1e73adbe0", "name": "Dangling fetch: POST /storage/wipe (dashboard/src/api.ts:99)", "shortDescription": {"text": "Dangling fetch: POST /storage/wipe (dashboard/src/api.ts:99)"}, "fullDescription": {"text": "`dashboard/src/api.ts:99` calls `POST /storage/wipe` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/storage/wipe`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b118f0be8ecba4bc", "name": "Dangling fetch: GET /policies/${profile_id}/effective (dashboard/src/api.ts:104)", "shortDescription": {"text": "Dangling fetch: GET /policies/${profile_id}/effective (dashboard/src/api.ts:104)"}, "fullDescription": {"text": "`dashboard/src/api.ts:104` calls `GET /policies/${profile_id}/effective` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/policies/<p>/effective`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9d1574db1021b9b1", "name": "Dangling fetch: PATCH /policies/${profile_id}/effective (dashboard/src/api.ts:106)", "shortDescription": {"text": "Dangling fetch: PATCH /policies/${profile_id}/effective (dashboard/src/api.ts:106)"}, "fullDescription": {"text": "`dashboard/src/api.ts:106` calls `PATCH /policies/${profile_id}/effective` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/policies/<p>/effective`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b1d5926fda286fa", "name": "Unused endpoint: GET /{full_path:path}", "shortDescription": {"text": "Unused endpoint: GET /{full_path:path}"}, "fullDescription": {"text": "`backend/app/main.py` declares `GET /{full_path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/app/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f5614c18a2feac7", "name": "Unused endpoint: GET /api", "shortDescription": {"text": "Unused endpoint: GET /api"}, "fullDescription": {"text": "`backend/app/api/storage.py` declares `GET /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fade9d72cd7b1df", "name": "Unused endpoint: POST /api/export", "shortDescription": {"text": "Unused endpoint: POST /api/export"}, "fullDescription": {"text": "`backend/app/api/storage.py` declares `POST /api/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cba8dce382a2ee0", "name": "Unused endpoint: POST /api/wipe", "shortDescription": {"text": "Unused endpoint: POST /api/wipe"}, "fullDescription": {"text": "`backend/app/api/storage.py` declares `POST /api/wipe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87f7ca9628364786", "name": "Unused endpoint: GET /api/overview", "shortDescription": {"text": "Unused endpoint: GET /api/overview"}, "fullDescription": {"text": "`backend/app/api/dashboard.py` declares `GET /api/overview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-200ab2e98a288506", "name": "Unused endpoint: POST /api/login", "shortDescription": {"text": "Unused endpoint: POST /api/login"}, "fullDescription": {"text": "`backend/app/api/auth.py` declares `POST /api/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a10936f69cf3bbb4", "name": "Unused endpoint: POST /api/logout", "shortDescription": {"text": "Unused endpoint: POST /api/logout"}, "fullDescription": {"text": "`backend/app/api/auth.py` declares `POST /api/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c1545494ab6166c", "name": "Unused endpoint: GET /api/me", "shortDescription": {"text": "Unused endpoint: GET /api/me"}, "fullDescription": {"text": "`backend/app/api/auth.py` declares `GET /api/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf5889f7b3ebfb2b", "name": "Unused endpoint: POST /api/recovery-reset", "shortDescription": {"text": "Unused endpoint: POST /api/recovery-reset"}, "fullDescription": {"text": "`backend/app/api/auth.py` declares `POST /api/recovery-reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b711cd9aa491588", "name": "Unused endpoint: POST /api/setup", "shortDescription": {"text": "Unused endpoint: POST /api/setup"}, "fullDescription": {"text": "`backend/app/api/auth.py` declares `POST /api/setup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42a16dc697ac3c7f", "name": "Unused endpoint: POST /api/{risk_id}/feedback", "shortDescription": {"text": "Unused endpoint: POST /api/{risk_id}/feedback"}, "fullDescription": {"text": "`backend/app/api/risks.py` declares `POST /api/{risk_id}/feedback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-963710f42a2c8219", "name": "Unused endpoint: GET /api/status", "shortDescription": {"text": "Unused endpoint: GET /api/status"}, "fullDescription": {"text": "`backend/app/api/setup.py` declares `GET /api/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1356e53f35e7d590", "name": "Unused endpoint: POST /api/recovery", "shortDescription": {"text": "Unused endpoint: POST /api/recovery"}, "fullDescription": {"text": "`backend/app/api/setup.py` declares `POST /api/recovery` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4261811fbf19d8fe", "name": "Unused endpoint: POST /api", "shortDescription": {"text": "Unused endpoint: POST /api"}, "fullDescription": {"text": "`backend/app/api/events.py` declares `POST /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f9c795bd4d759c8", "name": "Unused endpoint: GET /api/{event_id}/text", "shortDescription": {"text": "Unused endpoint: GET /api/{event_id}/text"}, "fullDescription": {"text": "`backend/app/api/events.py` declares `GET /api/{event_id}/text` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79e9dd5853bea487", "name": "Unused endpoint: POST /api/screenshot", "shortDescription": {"text": "Unused endpoint: POST /api/screenshot"}, "fullDescription": {"text": "`backend/app/api/events.py` declares `POST /api/screenshot` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-456bb8d2f10724a9", "name": "Unused endpoint: GET /api/{event_id}/screenshot", "shortDescription": {"text": "Unused endpoint: GET /api/{event_id}/screenshot"}, "fullDescription": {"text": "`backend/app/api/events.py` declares `GET /api/{event_id}/screenshot` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-696b458c3bb071dd", "name": "Unused endpoint: POST /api/test", "shortDescription": {"text": "Unused endpoint: POST /api/test"}, "fullDescription": {"text": "`backend/app/api/models.py` declares `POST /api/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cdf832aada84a030", "name": "Unused endpoint: GET /api/{alert_id}", "shortDescription": {"text": "Unused endpoint: GET /api/{alert_id}"}, "fullDescription": {"text": "`backend/app/api/alerts.py` declares `GET /api/{alert_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f0eb1712bbdfc1b", "name": "Unused endpoint: POST /api/{alert_id}/review", "shortDescription": {"text": "Unused endpoint: POST /api/{alert_id}/review"}, "fullDescription": {"text": "`backend/app/api/alerts.py` declares `POST /api/{alert_id}/review` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31d0e8081e3eb411", "name": "Unused endpoint: POST /api/{alert_id}/feedback", "shortDescription": {"text": "Unused endpoint: POST /api/{alert_id}/feedback"}, "fullDescription": {"text": "`backend/app/api/alerts.py` declares `POST /api/{alert_id}/feedback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-100aca63af4fdbd8", "name": "Unused endpoint: POST /api/{alert_id}/action", "shortDescription": {"text": "Unused endpoint: POST /api/{alert_id}/action"}, "fullDescription": {"text": "`backend/app/api/alerts.py` declares `POST /api/{alert_id}/action` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/app/api/child_requests.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f21859d3a82fb59", "name": "Unused endpoint: POST /{request_id}/review", "shortDescription": {"text": "Unused endpoint: POST /{request_id}/review"}, "fullDescription": {"text": "`backend/app/api/child_requests.py` declares `POST /{request_id}/review` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-052e15fed9cbd592", "name": "Unused endpoint: PATCH /api/{device_id}/profile", "shortDescription": {"text": "Unused endpoint: PATCH /api/{device_id}/profile"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `PATCH /api/{device_id}/profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be0e140093ae6201", "name": "Unused endpoint: POST /api/pair/start", "shortDescription": {"text": "Unused endpoint: POST /api/pair/start"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `POST /api/pair/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd97fb65934d365d", "name": "Unused endpoint: POST /api/pair/complete", "shortDescription": {"text": "Unused endpoint: POST /api/pair/complete"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `POST /api/pair/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd0549e95a026026", "name": "Unused endpoint: GET /api/capture-config", "shortDescription": {"text": "Unused endpoint: GET /api/capture-config"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `GET /api/capture-config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5617e6e31fb66cb", "name": "Unused endpoint: POST /api/heartbeat", "shortDescription": {"text": "Unused endpoint: POST /api/heartbeat"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `POST /api/heartbeat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16811b17779961e2", "name": "Unused endpoint: POST /api/{device_id}/pause", "shortDescription": {"text": "Unused endpoint: POST /api/{device_id}/pause"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `POST /api/{device_id}/pause` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee359ddd3bc4d18e", "name": "Unused endpoint: POST /api/{device_id}/resume", "shortDescription": {"text": "Unused endpoint: POST /api/{device_id}/resume"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `POST /api/{device_id}/resume` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9077cb6eafefd0b", "name": "Unused endpoint: DELETE /api/{device_id}", "shortDescription": {"text": "Unused endpoint: DELETE /api/{device_id}"}, "fullDescription": {"text": "`backend/app/api/devices.py` declares `DELETE /api/{device_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fe20b274a60b160", "name": "Unused endpoint: GET /api/{profile_id}/effective", "shortDescription": {"text": "Unused endpoint: GET /api/{profile_id}/effective"}, "fullDescription": {"text": "`backend/app/api/policies.py` declares `GET /api/{profile_id}/effective` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e2e5f5cf772603f", "name": "Unused endpoint: PATCH /api/{profile_id}/effective", "shortDescription": {"text": "Unused endpoint: PATCH /api/{profile_id}/effective"}, "fullDescription": {"text": "`backend/app/api/policies.py` declares `PATCH /api/{profile_id}/effective` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0dec3c98db6201d", "name": "Unused endpoint: PATCH /api/{policy_id}", "shortDescription": {"text": "Unused endpoint: PATCH /api/{policy_id}"}, "fullDescription": {"text": "`backend/app/api/policies.py` declares `PATCH /api/{policy_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c064ebea01bdf27e", "name": "Unused endpoint: PATCH /api/{profile_id}", "shortDescription": {"text": "Unused endpoint: PATCH /api/{profile_id}"}, "fullDescription": {"text": "`backend/app/api/profiles.py` declares `PATCH /api/{profile_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5351f092299f84fa", "name": "Unused endpoint: GET /api/policy/meta", "shortDescription": {"text": "Unused endpoint: GET /api/policy/meta"}, "fullDescription": {"text": "`backend/app/api/profiles.py` declares `GET /api/policy/meta` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77c03b359df0c1a0", "name": "Unused endpoint: DELETE /api/{profile_id}", "shortDescription": {"text": "Unused endpoint: DELETE /api/{profile_id}"}, "fullDescription": {"text": "`backend/app/api/profiles.py` declares `DELETE /api/{profile_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3af64e805d88ef35", "name": "Unused endpoint: GET /notifications", "shortDescription": {"text": "Unused endpoint: GET /notifications"}, "fullDescription": {"text": "`backend/app/api/settings.py` declares `GET /notifications` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f31350b04efd146", "name": "Unused endpoint: PATCH /notifications", "shortDescription": {"text": "Unused endpoint: PATCH /notifications"}, "fullDescription": {"text": "`backend/app/api/settings.py` declares `PATCH /notifications` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aeb23cd521acf64a", "name": "Unused endpoint: POST /notifications/test", "shortDescription": {"text": "Unused endpoint: POST /notifications/test"}, "fullDescription": {"text": "`backend/app/api/settings.py` declares `POST /notifications/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0399243c128aed5", "name": "Unused endpoint: GET /retention", "shortDescription": {"text": "Unused endpoint: GET /retention"}, "fullDescription": {"text": "`backend/app/api/settings.py` declares `GET /retention` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d302964999de10f", "name": "Unused endpoint: PATCH /retention", "shortDescription": {"text": "Unused endpoint: PATCH /retention"}, "fullDescription": {"text": "`backend/app/api/settings.py` declares `PATCH /retention` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2af146ac788ab36", "name": "Unused endpoint: POST /retention/run-cleanup", "shortDescription": {"text": "Unused endpoint: POST /retention/run-cleanup"}, "fullDescription": {"text": "`backend/app/api/settings.py` declares `POST /retention/run-cleanup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21071"}, "properties": {"repository": "the-vibe-dev/guardiannode", "repoUrl": "https://github.com/the-vibe-dev/guardiannode", "branch": "main"}, "results": [{"ruleId": "scanner-223c773ceb36583c", "level": "note", "message": {"text": "Possibly dead Python function: recognize"}, "properties": {"repobilityId": "7a185546e73115fd", "scanner": "scanner-primary", "fingerprint": "223c773ceb36583c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/ocr_engine.py:60"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-57b75ad46eeffa99", "level": "note", "message": {"text": "Possibly dead Python function: make_engine"}, "properties": {"repobilityId": "537eb7b6dbe1961b", "scanner": "scanner-primary", "fingerprint": "57b75ad46eeffa99", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/ocr_engine.py:81"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-df75799b5fca7b4e", "level": "note", "message": {"text": "Possibly dead Python function: health"}, "properties": {"repobilityId": "b0dbdc8073a0048c", "scanner": "scanner-primary", "fingerprint": "df75799b5fca7b4e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/backend_client.py:16"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1f8959867f5f0e1", "level": "note", "message": {"text": "Possibly dead Python function: send_event"}, "properties": {"repobilityId": "661c5e1dfb570d68", "scanner": "scanner-primary", "fingerprint": "c1f8959867f5f0e1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/backend_client.py:22"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7baf29f045c2e863", "level": "note", "message": {"text": "Possibly dead Python function: add_service"}, "properties": {"repobilityId": "85bab69f48ba8a50", "scanner": "scanner-primary", "fingerprint": "7baf29f045c2e863", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/pairing_client.py:39"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-855d976e16cf4244", "level": "note", "message": {"text": "Possibly dead Python function: remove_service"}, "properties": {"repobilityId": "b2f4fd6d5a03a686", "scanner": "scanner-primary", "fingerprint": "855d976e16cf4244", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/pairing_client.py:54"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cf56d4d6f474d34b", "level": "note", "message": {"text": "Possibly dead Python function: update_service"}, "properties": {"repobilityId": "a0d30da761ce82d5", "scanner": "scanner-primary", "fingerprint": "cf56d4d6f474d34b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/pairing_client.py:57"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0cc0ce38f840ca4", "level": "note", "message": {"text": "Possibly dead Python function: write_credentials"}, "properties": {"repobilityId": "3b727added869d0b", "scanner": "scanner-primary", "fingerprint": "e0cc0ce38f840ca4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "agent-windows/src/parent_auth.py:25"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6cb2a7b2dacb6fc5", "level": "note", "message": {"text": "Possibly dead Python function: current_user"}, "properties": {"repobilityId": "271089411e6e6afb", "scanner": "scanner-primary", "fingerprint": "6cb2a7b2dacb6fc5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/deps.py:20"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-84b9953260af951a", "level": "note", "message": {"text": "Possibly dead Python function: current_device"}, "properties": {"repobilityId": "41b4b4579434f132", "scanner": "scanner-primary", "fingerprint": "84b9953260af951a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/deps.py:30"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-92fec37ad6e756ca", "level": "note", "message": {"text": "Possibly dead Python function: run_once"}, "properties": {"repobilityId": "697a8f279dd38dce", "scanner": "scanner-primary", "fingerprint": "92fec37ad6e756ca", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/workers/cleanup_worker.py:29"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b0a84f4cdd980d0", "level": "note", "message": {"text": "Possibly dead Python function: run_once"}, "properties": {"repobilityId": "697a8f279dd38dce", "scanner": "scanner-primary", "fingerprint": "1b0a84f4cdd980d0", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/workers/offline_monitor.py:135"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-00d688c0b7b18d93", "level": "note", "message": {"text": "Possibly dead Python function: list_models"}, "properties": {"repobilityId": "e51c5236028c4e4f", "scanner": "scanner-primary", "fingerprint": "00d688c0b7b18d93", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/services/ollama_client.py:52"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1008ba42d2ecb703", "level": "note", "message": {"text": "Possibly dead Python function: generate_with_image_path"}, "properties": {"repobilityId": "caa53bf273e5a9bd", "scanner": "scanner-primary", "fingerprint": "1008ba42d2ecb703", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/services/ollama_client.py:114"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c49b5658bc842d7a", "level": "note", "message": {"text": "Possibly dead Python function: pull"}, "properties": {"repobilityId": "27605631f5e68ae4", "scanner": "scanner-primary", "fingerprint": "c49b5658bc842d7a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/services/ollama_client.py:134"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2e0a863b43eeba25", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 dashboard/src/components/PipelineHealth.tsx:161"}, "properties": {"repobilityId": "804379ff46c579f4", "scanner": "scanner-primary", "fingerprint": "2e0a863b43eeba25", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9ceb16f9a1ca7f9c", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 backend/app/static/assets/index-BwTxGcoF.js:33"}, "properties": {"repobilityId": "ce27c567fe5c2c42", "scanner": "scanner-primary", "fingerprint": "9ceb16f9a1ca7f9c", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-5c7361e1b87d5d7e", "level": "warning", "message": {"text": "Privileged port 587 in use"}, "properties": {"repobilityId": "a87a96c3b2e62c08", "scanner": "scanner-primary", "fingerprint": "5c7361e1b87d5d7e", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/src/pages/Settings.tsx"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3404fcfc69b0c4d7", "level": "warning", "message": {"text": "Privileged port 465 in use"}, "properties": {"repobilityId": "bcd1f06b60a2b6bc", "scanner": "scanner-primary", "fingerprint": "3404fcfc69b0c4d7", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/src/pages/Settings.tsx"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-4aaa6ca698e1fdfd", "level": "error", "message": {"text": "Possible secret in backend/app/static/assets/index-BwTxGcoF.js"}, "properties": {"repobilityId": "638cba26dd3861b8", "scanner": "scanner-primary", "fingerprint": "4aaa6ca698e1fdfd", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/static/assets/index-BwTxGcoF.js"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-f0b366d8adb67339", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in backend/app/static/assets/index-BwTxGcoF.js:37"}, "properties": {"repobilityId": "bc05ecc09c2c29b0", "scanner": "scanner-primary", "fingerprint": "f0b366d8adb67339", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/static/assets/index-BwTxGcoF.js"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-de39ac9e5cbf2f3d", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6e208bcb7189dc85", "scanner": "scanner-primary", "fingerprint": "de39ac9e5cbf2f3d", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-docs.yml"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-3345532e49ae8640", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "32c4cca348173c51", "scanner": "scanner-primary", "fingerprint": "3345532e49ae8640", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-docs.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a8ed4a016475288e", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e8c393d9c1d6489e", "scanner": "scanner-primary", "fingerprint": "a8ed4a016475288e", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-installers.yml"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-a8ed4a016475288e", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "192311099d8e3fe2", "scanner": "scanner-primary", "fingerprint": "a8ed4a016475288e", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-installers.yml"}, "region": {"startLine": 197}}}]}, {"ruleId": "scanner-d76ce5e6455a26a7", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "4c32daa347fba59b", "scanner": "scanner-primary", "fingerprint": "d76ce5e6455a26a7", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release-installers.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "4814dd45e2d294e9", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "76d2c90da9c2f4b8", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "dcf81b6b41880435", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "cb8db163ffb6ce79", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-63e154d322a30c23", "level": "none", "message": {"text": "Commented-code block (5 lines) in dashboard/src/utils/datetime.ts:3"}, "properties": {"repobilityId": "a230e08bcbd40d05", "scanner": "scanner-primary", "fingerprint": "63e154d322a30c23", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-caedaa8b4177eb3e", "level": "none", "message": {"text": "Commented-code block (5 lines) in agent-windows/src/config.py:33"}, "properties": {"repobilityId": "c005e039cf188eff", "scanner": "scanner-primary", "fingerprint": "caedaa8b4177eb3e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-61bd7bf773d45006", "level": "none", "message": {"text": "Commented-code block (6 lines) in agent-windows/src/tray_app.py:94"}, "properties": {"repobilityId": "a8d91ebee26a5567", "scanner": "scanner-primary", "fingerprint": "61bd7bf773d45006", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6cbe6cc548e44a26", "level": "none", "message": {"text": "Commented-code block (5 lines) in agent-windows/src/main.py:47"}, "properties": {"repobilityId": "bb15d4e99494b27d", "scanner": "scanner-primary", "fingerprint": "6cbe6cc548e44a26", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0a9751f2e0e0b0f7", "level": "none", "message": {"text": "Commented-code block (12 lines) in agent-windows/src/hardware_probe.py:97"}, "properties": {"repobilityId": "27a1363e07c39722", "scanner": "scanner-primary", "fingerprint": "0a9751f2e0e0b0f7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-55e06b6609a34eb4", "level": "none", "message": {"text": "Commented-code block (16 lines) in backend/app/settings.py:41"}, "properties": {"repobilityId": "6d8d948ebbabda67", "scanner": "scanner-primary", "fingerprint": "55e06b6609a34eb4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-22b17441f4e204e9", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/app/static/assets/index-BwTxGcoF.js:1"}, "properties": {"repobilityId": "d5aed2bc9745cec4", "scanner": "scanner-primary", "fingerprint": "22b17441f4e204e9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a6a15b9be26e1234", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/app/services/parent_auth.py:10"}, "properties": {"repobilityId": "ffd93f92f2d76ff4", "scanner": "scanner-primary", "fingerprint": "a6a15b9be26e1234", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "d17bbab828be77f4", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "36ce0efd9eb41451", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-fa7d7a6110471f62", "level": "error", "message": {"text": "FastAPI POST `recovery_reset` without auth dependency \u2014 backend/app/api/auth.py:91"}, "properties": {"repobilityId": "8c9ff3e0e3cc22ed", "scanner": "scanner-primary", "fingerprint": "fa7d7a6110471f62", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/auth.py"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-b01c5f7ccc9e79ec", "level": "error", "message": {"text": "FastAPI POST `setup` without auth dependency \u2014 backend/app/api/auth.py:122"}, "properties": {"repobilityId": "3bb99658b1264e49", "scanner": "scanner-primary", "fingerprint": "b01c5f7ccc9e79ec", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/auth.py"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-109a2e248ae08518", "level": "error", "message": {"text": "FastAPI POST `get_recovery_code` without auth dependency \u2014 backend/app/api/setup.py:32"}, "properties": {"repobilityId": "134332e9d6d25d77", "scanner": "scanner-primary", "fingerprint": "109a2e248ae08518", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/setup.py"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-6b6872a9c2e9f2f5", "level": "error", "message": {"text": "FastAPI POST `ingest` without auth dependency \u2014 backend/app/api/events.py:48"}, "properties": {"repobilityId": "4d7fe0ab14edab6a", "scanner": "scanner-primary", "fingerprint": "6b6872a9c2e9f2f5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/events.py"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-7f8ab3b6fcb3f06b", "level": "error", "message": {"text": "FastAPI POST `ingest_screenshot` without auth dependency \u2014 backend/app/api/events.py:153"}, "properties": {"repobilityId": "cbdb418a406e4906", "scanner": "scanner-primary", "fingerprint": "7f8ab3b6fcb3f06b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/events.py"}, "region": {"startLine": 153}}}]}, {"ruleId": "scanner-59f472e391aefbd5", "level": "error", "message": {"text": "FastAPI POST `create_child_request` without auth dependency \u2014 backend/app/api/child_requests.py:39"}, "properties": {"repobilityId": "d9e38a2466b33c0b", "scanner": "scanner-primary", "fingerprint": "59f472e391aefbd5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/child_requests.py"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-a2b951472a887771", "level": "error", "message": {"text": "FastAPI POST `pair_complete` without auth dependency \u2014 backend/app/api/devices.py:135"}, "properties": {"repobilityId": "e7cf1095510a5341", "scanner": "scanner-primary", "fingerprint": "a2b951472a887771", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/devices.py"}, "region": {"startLine": 135}}}]}, {"ruleId": "scanner-ce524fdf3170b7a1", "level": "error", "message": {"text": "FastAPI POST `heartbeat` without auth dependency \u2014 backend/app/api/devices.py:222"}, "properties": {"repobilityId": "53cd3a0b93a6afc4", "scanner": "scanner-primary", "fingerprint": "ce524fdf3170b7a1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/api/devices.py"}, "region": {"startLine": 222}}}]}, {"ruleId": "scanner-6c74e9db290bbb24", "level": "error", "message": {"text": "Dangling fetch: GET /setup/status (dashboard/src/api.ts:24)"}, "properties": {"repobilityId": "09f85f250226d877", "scanner": "scanner-primary", "fingerprint": "6c74e9db290bbb24", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-92cddb4e0f84096e", "level": "error", "message": {"text": "Dangling fetch: POST /setup/recovery (dashboard/src/api.ts:25)"}, "properties": {"repobilityId": "84b35d18f4ded6ac", "scanner": "scanner-primary", "fingerprint": "92cddb4e0f84096e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7cf1aeda65c0ccd4", "level": "error", "message": {"text": "Dangling fetch: POST /auth/setup (dashboard/src/api.ts:27)"}, "properties": {"repobilityId": "55e0d87e7412e680", "scanner": "scanner-primary", "fingerprint": "7cf1aeda65c0ccd4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-23d155f14b1c57c6", "level": "error", "message": {"text": "Dangling fetch: POST /auth/login (dashboard/src/api.ts:29)"}, "properties": {"repobilityId": "f50512590075a831", "scanner": "scanner-primary", "fingerprint": "23d155f14b1c57c6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-76b7cb990ee3714f", "level": "error", "message": {"text": "Dangling fetch: POST /auth/logout (dashboard/src/api.ts:30)"}, "properties": {"repobilityId": "764dc2846ee5cfef", "scanner": "scanner-primary", "fingerprint": "76b7cb990ee3714f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5cf5940df8f11901", "level": "error", "message": {"text": "Dangling fetch: GET /auth/me (dashboard/src/api.ts:31)"}, "properties": {"repobilityId": "b6bccf04d3ad8405", "scanner": "scanner-primary", "fingerprint": "5cf5940df8f11901", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4286c78bcee0e5b7", "level": "error", "message": {"text": "Dangling fetch: POST /auth/recovery-reset (dashboard/src/api.ts:33)"}, "properties": {"repobilityId": "71d9db80c7960add", "scanner": "scanner-primary", "fingerprint": "4286c78bcee0e5b7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3ebb10cae3d57e73", "level": "error", "message": {"text": "Dangling fetch: GET /dashboard/overview (dashboard/src/api.ts:37)"}, "properties": {"repobilityId": "555946e8ecb63346", "scanner": "scanner-primary", "fingerprint": "3ebb10cae3d57e73", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-93c2915c7bc99ceb", "level": "error", "message": {"text": "Dangling fetch: GET /devices (dashboard/src/api.ts:38)"}, "properties": {"repobilityId": "1f3637985e0fc0fc", "scanner": "scanner-primary", "fingerprint": "93c2915c7bc99ceb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-02802273d95b3a00", "level": "error", "message": {"text": "Dangling fetch: POST /devices/pair/start (dashboard/src/api.ts:39)"}, "properties": {"repobilityId": "3d454d619f637c57", "scanner": "scanner-primary", "fingerprint": "02802273d95b3a00", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-798d4fe88c76d8ce", "level": "error", "message": {"text": "Dangling fetch: POST /devices/${device_id}/pause (dashboard/src/api.ts:41)"}, "properties": {"repobilityId": "b08a11596208b39e", "scanner": "scanner-primary", "fingerprint": "798d4fe88c76d8ce", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-582df840bcd2ee4c", "level": "error", "message": {"text": "Dangling fetch: POST /devices/${device_id}/resume (dashboard/src/api.ts:43)"}, "properties": {"repobilityId": "7fcd1ca95031f7fc", "scanner": "scanner-primary", "fingerprint": "582df840bcd2ee4c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-82aac12b1cbc6e3c", "level": "error", "message": {"text": "Dangling fetch: DELETE /devices/${device_id} (dashboard/src/api.ts:45)"}, "properties": {"repobilityId": "e4d24f1768a73bf0", "scanner": "scanner-primary", "fingerprint": "82aac12b1cbc6e3c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ffc1f52137406039", "level": "error", "message": {"text": "Dangling fetch: PATCH /devices/${device_id}/profile (dashboard/src/api.ts:47)"}, "properties": {"repobilityId": "cfaeb69010e03563", "scanner": "scanner-primary", "fingerprint": "ffc1f52137406039", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-99069603c353e694", "level": "error", "message": {"text": "Dangling fetch: GET /alerts/${id} (dashboard/src/api.ts:52)"}, "properties": {"repobilityId": "597a54d6cfa0d309", "scanner": "scanner-primary", "fingerprint": "99069603c353e694", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0b1f7afab9e2f6e8", "level": "error", "message": {"text": "Dangling fetch: POST /alerts/${id}/review (dashboard/src/api.ts:54)"}, "properties": {"repobilityId": "2b741680d4ea6cf1", "scanner": "scanner-primary", "fingerprint": "0b1f7afab9e2f6e8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3dc929fffe6a7844", "level": "error", "message": {"text": "Dangling fetch: POST /alerts/${id}/feedback (dashboard/src/api.ts:56)"}, "properties": {"repobilityId": "23a88479c5c11c22", "scanner": "scanner-primary", "fingerprint": "3dc929fffe6a7844", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5129d92bb1d992dd", "level": "error", "message": {"text": "Dangling fetch: GET /models/status (dashboard/src/api.ts:57)"}, "properties": {"repobilityId": "b0b734d995c4ea79", "scanner": "scanner-primary", "fingerprint": "5129d92bb1d992dd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d79ffe2a453a0cde", "level": "error", "message": {"text": "Dangling fetch: POST /models/test (dashboard/src/api.ts:58)"}, "properties": {"repobilityId": "433e6defabdc6480", "scanner": "scanner-primary", "fingerprint": "d79ffe2a453a0cde", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-173b52c2cfa8a26e", "level": "error", "message": {"text": "Dangling fetch: GET /profiles (dashboard/src/api.ts:59)"}, "properties": {"repobilityId": "3e039377305430e1", "scanner": "scanner-primary", "fingerprint": "173b52c2cfa8a26e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3f3efce18b8fa90e", "level": "error", "message": {"text": "Dangling fetch: POST /profiles (dashboard/src/api.ts:66)"}, "properties": {"repobilityId": "2181bf207e9accd9", "scanner": "scanner-primary", "fingerprint": "3f3efce18b8fa90e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-367d3d5f14ea4b28", "level": "error", "message": {"text": "Dangling fetch: PATCH /profiles/${profile_id} (dashboard/src/api.ts:81)"}, "properties": {"repobilityId": "1bb5fc087e5f6097", "scanner": "scanner-primary", "fingerprint": "367d3d5f14ea4b28", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-952548df5010bbf1", "level": "error", "message": {"text": "Dangling fetch: GET /profiles/policy/meta (dashboard/src/api.ts:85)"}, "properties": {"repobilityId": "323fb6f8e3a301b3", "scanner": "scanner-primary", "fingerprint": "952548df5010bbf1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1ae5c4aeb73199ea", "level": "error", "message": {"text": "Dangling fetch: GET /settings/notifications (dashboard/src/api.ts:86)"}, "properties": {"repobilityId": "504b51cc69005acc", "scanner": "scanner-primary", "fingerprint": "1ae5c4aeb73199ea", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3e99f284cf18640c", "level": "error", "message": {"text": "Dangling fetch: PATCH /settings/notifications (dashboard/src/api.ts:88)"}, "properties": {"repobilityId": "7306944176c4bc5b", "scanner": "scanner-primary", "fingerprint": "3e99f284cf18640c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5f7806df46adde7a", "level": "error", "message": {"text": "Dangling fetch: POST /settings/notifications/test (dashboard/src/api.ts:90)"}, "properties": {"repobilityId": "af331cc2ebb020a0", "scanner": "scanner-primary", "fingerprint": "5f7806df46adde7a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-91c50787641fc161", "level": "error", "message": {"text": "Dangling fetch: GET /settings/retention (dashboard/src/api.ts:91)"}, "properties": {"repobilityId": "61b8b5516b14d136", "scanner": "scanner-primary", "fingerprint": "91c50787641fc161", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8c5b8c63a90ea8f9", "level": "error", "message": {"text": "Dangling fetch: PATCH /settings/retention (dashboard/src/api.ts:93)"}, "properties": {"repobilityId": "44b2b4640cac7bfb", "scanner": "scanner-primary", "fingerprint": "8c5b8c63a90ea8f9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f6ff2b5d6e389ebd", "level": "error", "message": {"text": "Dangling fetch: POST /settings/retention/run-cleanup (dashboard/src/api.ts:95)"}, "properties": {"repobilityId": "ffc4b2bd7449bcb4", "scanner": "scanner-primary", "fingerprint": "f6ff2b5d6e389ebd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-146f4c53d8f51920", "level": "error", "message": {"text": "Dangling fetch: GET /storage (dashboard/src/api.ts:96)"}, "properties": {"repobilityId": "4fe4f03fb3f1b341", "scanner": "scanner-primary", "fingerprint": "146f4c53d8f51920", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-dcecfcd5130a6abc", "level": "error", "message": {"text": "Dangling fetch: POST /storage/export (dashboard/src/api.ts:97)"}, "properties": {"repobilityId": "b506c1e58d60bed0", "scanner": "scanner-primary", "fingerprint": "dcecfcd5130a6abc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a36141f1e73adbe0", "level": "error", "message": {"text": "Dangling fetch: POST /storage/wipe (dashboard/src/api.ts:99)"}, "properties": {"repobilityId": "f2b2fc7743ecf908", "scanner": "scanner-primary", "fingerprint": "a36141f1e73adbe0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b118f0be8ecba4bc", "level": "error", "message": {"text": "Dangling fetch: GET /policies/${profile_id}/effective (dashboard/src/api.ts:104)"}, "properties": {"repobilityId": "7fb58bc3ee71bec3", "scanner": "scanner-primary", "fingerprint": "b118f0be8ecba4bc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9d1574db1021b9b1", "level": "error", "message": {"text": "Dangling fetch: PATCH /policies/${profile_id}/effective (dashboard/src/api.ts:106)"}, "properties": {"repobilityId": "8113bdd888508209", "scanner": "scanner-primary", "fingerprint": "9d1574db1021b9b1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1b1d5926fda286fa", "level": "note", "message": {"text": "Unused endpoint: GET /{full_path:path}"}, "properties": {"repobilityId": "574058a6b8490f0e", "scanner": "scanner-primary", "fingerprint": "1b1d5926fda286fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9a7ab29051c0367b", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f5614c18a2feac7", "level": "note", "message": {"text": "Unused endpoint: GET /api"}, "properties": {"repobilityId": "1b89f53f3a76db70", "scanner": "scanner-primary", "fingerprint": "8f5614c18a2feac7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6fade9d72cd7b1df", "level": "note", "message": {"text": "Unused endpoint: POST /api/export"}, "properties": {"repobilityId": "48b30901e41a066b", "scanner": "scanner-primary", "fingerprint": "6fade9d72cd7b1df", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5cba8dce382a2ee0", "level": "note", "message": {"text": "Unused endpoint: POST /api/wipe"}, "properties": {"repobilityId": "5ce7a08922835a0f", "scanner": "scanner-primary", "fingerprint": "5cba8dce382a2ee0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-87f7ca9628364786", "level": "note", "message": {"text": "Unused endpoint: GET /api/overview"}, "properties": {"repobilityId": "4ec5f72e194ed77d", "scanner": "scanner-primary", "fingerprint": "87f7ca9628364786", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-200ab2e98a288506", "level": "note", "message": {"text": "Unused endpoint: POST /api/login"}, "properties": {"repobilityId": "8b2f8d6aed2cf9f8", "scanner": "scanner-primary", "fingerprint": "200ab2e98a288506", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a10936f69cf3bbb4", "level": "note", "message": {"text": "Unused endpoint: POST /api/logout"}, "properties": {"repobilityId": "28ce70c351d05ca2", "scanner": "scanner-primary", "fingerprint": "a10936f69cf3bbb4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c1545494ab6166c", "level": "note", "message": {"text": "Unused endpoint: GET /api/me"}, "properties": {"repobilityId": "1a7575300e462e84", "scanner": "scanner-primary", "fingerprint": "5c1545494ab6166c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bf5889f7b3ebfb2b", "level": "note", "message": {"text": "Unused endpoint: POST /api/recovery-reset"}, "properties": {"repobilityId": "aba1dc42dede3fb8", "scanner": "scanner-primary", "fingerprint": "bf5889f7b3ebfb2b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b711cd9aa491588", "level": "note", "message": {"text": "Unused endpoint: POST /api/setup"}, "properties": {"repobilityId": "c2a4e023efe3d184", "scanner": "scanner-primary", "fingerprint": "7b711cd9aa491588", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-42a16dc697ac3c7f", "level": "note", "message": {"text": "Unused endpoint: POST /api/{risk_id}/feedback"}, "properties": {"repobilityId": "488d59677e75c4a8", "scanner": "scanner-primary", "fingerprint": "42a16dc697ac3c7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-963710f42a2c8219", "level": "note", "message": {"text": "Unused endpoint: GET /api/status"}, "properties": {"repobilityId": "a63e5fc5e086ffad", "scanner": "scanner-primary", "fingerprint": "963710f42a2c8219", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1356e53f35e7d590", "level": "note", "message": {"text": "Unused endpoint: POST /api/recovery"}, "properties": {"repobilityId": "16849955105f9fc2", "scanner": "scanner-primary", "fingerprint": "1356e53f35e7d590", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4261811fbf19d8fe", "level": "note", "message": {"text": "Unused endpoint: POST /api"}, "properties": {"repobilityId": "b54c3b90965a08fd", "scanner": "scanner-primary", "fingerprint": "4261811fbf19d8fe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f9c795bd4d759c8", "level": "note", "message": {"text": "Unused endpoint: GET /api/{event_id}/text"}, "properties": {"repobilityId": "6230081e6df6e15c", "scanner": "scanner-primary", "fingerprint": "7f9c795bd4d759c8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-79e9dd5853bea487", "level": "note", "message": {"text": "Unused endpoint: POST /api/screenshot"}, "properties": {"repobilityId": "e60ba8e67ed1550e", "scanner": "scanner-primary", "fingerprint": "79e9dd5853bea487", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-456bb8d2f10724a9", "level": "note", "message": {"text": "Unused endpoint: GET /api/{event_id}/screenshot"}, "properties": {"repobilityId": "a5e7a37ad0026155", "scanner": "scanner-primary", "fingerprint": "456bb8d2f10724a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-696b458c3bb071dd", "level": "note", "message": {"text": "Unused endpoint: POST /api/test"}, "properties": {"repobilityId": "3c200ac5a533f64a", "scanner": "scanner-primary", "fingerprint": "696b458c3bb071dd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cdf832aada84a030", "level": "note", "message": {"text": "Unused endpoint: GET /api/{alert_id}"}, "properties": {"repobilityId": "5a4d935275cac2f5", "scanner": "scanner-primary", "fingerprint": "cdf832aada84a030", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6f0eb1712bbdfc1b", "level": "note", "message": {"text": "Unused endpoint: POST /api/{alert_id}/review"}, "properties": {"repobilityId": "e4fd2be297d5aec3", "scanner": "scanner-primary", "fingerprint": "6f0eb1712bbdfc1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-31d0e8081e3eb411", "level": "note", "message": {"text": "Unused endpoint: POST /api/{alert_id}/feedback"}, "properties": {"repobilityId": "94f0db3d7afeb1c7", "scanner": "scanner-primary", "fingerprint": "31d0e8081e3eb411", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-100aca63af4fdbd8", "level": "note", "message": {"text": "Unused endpoint: POST /api/{alert_id}/action"}, "properties": {"repobilityId": "5f06f5903ed4faec", "scanner": "scanner-primary", "fingerprint": "100aca63af4fdbd8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "86ce3c140a95bd39", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0f21859d3a82fb59", "level": "note", "message": {"text": "Unused endpoint: POST /{request_id}/review"}, "properties": {"repobilityId": "a80e8765ef6b8b50", "scanner": "scanner-primary", "fingerprint": "0f21859d3a82fb59", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-052e15fed9cbd592", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/{device_id}/profile"}, "properties": {"repobilityId": "cd59e6623fef013c", "scanner": "scanner-primary", "fingerprint": "052e15fed9cbd592", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-be0e140093ae6201", "level": "note", "message": {"text": "Unused endpoint: POST /api/pair/start"}, "properties": {"repobilityId": "17807ebaad088f4d", "scanner": "scanner-primary", "fingerprint": "be0e140093ae6201", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd97fb65934d365d", "level": "note", "message": {"text": "Unused endpoint: POST /api/pair/complete"}, "properties": {"repobilityId": "4d6bdce53c8b2156", "scanner": "scanner-primary", "fingerprint": "dd97fb65934d365d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd0549e95a026026", "level": "note", "message": {"text": "Unused endpoint: GET /api/capture-config"}, "properties": {"repobilityId": "2d8458ce37c0995d", "scanner": "scanner-primary", "fingerprint": "fd0549e95a026026", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5617e6e31fb66cb", "level": "note", "message": {"text": "Unused endpoint: POST /api/heartbeat"}, "properties": {"repobilityId": "8bf366f171079962", "scanner": "scanner-primary", "fingerprint": "d5617e6e31fb66cb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-16811b17779961e2", "level": "note", "message": {"text": "Unused endpoint: POST /api/{device_id}/pause"}, "properties": {"repobilityId": "7b620715ae6954db", "scanner": "scanner-primary", "fingerprint": "16811b17779961e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee359ddd3bc4d18e", "level": "note", "message": {"text": "Unused endpoint: POST /api/{device_id}/resume"}, "properties": {"repobilityId": "b7f09591a9c0056f", "scanner": "scanner-primary", "fingerprint": "ee359ddd3bc4d18e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9077cb6eafefd0b", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/{device_id}"}, "properties": {"repobilityId": "4c68ee03a44cb6c8", "scanner": "scanner-primary", "fingerprint": "c9077cb6eafefd0b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4fe20b274a60b160", "level": "note", "message": {"text": "Unused endpoint: GET /api/{profile_id}/effective"}, "properties": {"repobilityId": "a1e7812061c3e6b6", "scanner": "scanner-primary", "fingerprint": "4fe20b274a60b160", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e2e5f5cf772603f", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/{profile_id}/effective"}, "properties": {"repobilityId": "c8bb4e57ab3a1e1b", "scanner": "scanner-primary", "fingerprint": "8e2e5f5cf772603f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0dec3c98db6201d", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/{policy_id}"}, "properties": {"repobilityId": "f82a7225b20f07e0", "scanner": "scanner-primary", "fingerprint": "e0dec3c98db6201d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c064ebea01bdf27e", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/{profile_id}"}, "properties": {"repobilityId": "76f02d652414478f", "scanner": "scanner-primary", "fingerprint": "c064ebea01bdf27e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5351f092299f84fa", "level": "note", "message": {"text": "Unused endpoint: GET /api/policy/meta"}, "properties": {"repobilityId": "4ad40a58492bd143", "scanner": "scanner-primary", "fingerprint": "5351f092299f84fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77c03b359df0c1a0", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/{profile_id}"}, "properties": {"repobilityId": "ab1b5497fcdd7c40", "scanner": "scanner-primary", "fingerprint": "77c03b359df0c1a0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3af64e805d88ef35", "level": "note", "message": {"text": "Unused endpoint: GET /notifications"}, "properties": {"repobilityId": "d0e7f42187927e46", "scanner": "scanner-primary", "fingerprint": "3af64e805d88ef35", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5f31350b04efd146", "level": "note", "message": {"text": "Unused endpoint: PATCH /notifications"}, "properties": {"repobilityId": "30b710dabd1ae305", "scanner": "scanner-primary", "fingerprint": "5f31350b04efd146", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aeb23cd521acf64a", "level": "note", "message": {"text": "Unused endpoint: POST /notifications/test"}, "properties": {"repobilityId": "2e1cff35501e2a8a", "scanner": "scanner-primary", "fingerprint": "aeb23cd521acf64a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b0399243c128aed5", "level": "note", "message": {"text": "Unused endpoint: GET /retention"}, "properties": {"repobilityId": "61a956b1c8f63ca2", "scanner": "scanner-primary", "fingerprint": "b0399243c128aed5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7d302964999de10f", "level": "note", "message": {"text": "Unused endpoint: PATCH /retention"}, "properties": {"repobilityId": "7624dad2d04247b4", "scanner": "scanner-primary", "fingerprint": "7d302964999de10f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d2af146ac788ab36", "level": "note", "message": {"text": "Unused endpoint: POST /retention/run-cleanup"}, "properties": {"repobilityId": "dfad9f8cda44e8cf", "scanner": "scanner-primary", "fingerprint": "d2af146ac788ab36", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}