{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-d0f9fb3b411b03d2", "name": "Stray `console.log` in TS/JS \u2014 server.js:51", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:51"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c9ead98014bdba3", "name": "Stray `console.log` in TS/JS \u2014 lib/assistant.js:2598", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/assistant.js:2598"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2133f575404b6667", "name": "Stray `console.log` in TS/JS \u2014 lib/email.js:343", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/email.js:343"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fbc491e7f753071", "name": "Stray `console.log` in TS/JS \u2014 lib/db.js:1104", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/db.js:1104"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa4f9bb140cdd37c", "name": "Stray `console.log` in TS/JS \u2014 lib/commitments.js:207", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/commitments.js:207"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-51ee800d48b8aaee", "name": "Stray `console.log` in TS/JS \u2014 lib/memory_extractor.js:272", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/memory_extractor.js:272"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f242bc5448ad27aa", "name": "Stray `console.log` in TS/JS \u2014 lib/voice.js:312", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/voice.js:312"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f09f08500de0e78", "name": "Stray `console.log` in TS/JS \u2014 lib/backfill.js:668", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/backfill.js:668"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1fb7d862533cf1d", "name": "Stray `console.log` in TS/JS \u2014 lib/snooze.js:182", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/snooze.js:182"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91c017e27ee7a244", "name": "Stray `console.log` in TS/JS \u2014 lib/gmailPush.js:277", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/gmailPush.js:277"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f78b44721828b9b4", "name": "Stray `console.log` in TS/JS \u2014 lib/emailExtractions.js:282", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/emailExtractions.js:282"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5000a8d80795e340", "name": "Stray `console.log` in TS/JS \u2014 lib/inbox_cache.js:96", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 lib/inbox_cache.js:96"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-697b20a6eaf81662", "name": "Stray `console.log` in TS/JS \u2014 public/assistant.js:407", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 public/assistant.js:407"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9f28e56df0fd689", "name": "Stray `console.log` in TS/JS \u2014 public/voice.js:280", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 public/voice.js:280"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9445d669fefb183", "name": "Stray `console.log` in TS/JS \u2014 public/inbox.js:1890", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 public/inbox.js:1890"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d86a453284538bf", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/shortcuts-global.js:89", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/shortcuts-global.js:89"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f46fac34f2dc8c3b", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/help.html:710", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/help.html:710"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5048fbf16c94f82c", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/assistant.js:357", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/assistant.js:357"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96dc1e642e326e39", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/markdown-inline.js:210", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/markdown-inline.js:210"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7c1ca8ec182dc4d", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/pricing.html:299", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/pricing.html:299"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd890213a9c6f15b", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/m-inbox.html:194", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/m-inbox.html:194"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-648872a622a2e755", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/voice.js:247", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/voice.js:247"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80d985592ee2a7bd", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/welcome.html:335", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/welcome.html:335"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ac20ff4ac05d860", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/trial-banner.js:64", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/trial-banner.js:64"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e092f00ef0c06ff", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/settings.html:2347", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/settings.html:2347"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17804701afb784ec", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/tasks.js:69", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/tasks.js:69"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cd447b74fd191a43", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/promises.html:384", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/promises.html:384"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d31d62fb855fea4a", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/contacts.js:59", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/contacts.js:59"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-626500fb52cd12e8", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/inbox-rightpanel.js:41", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/inbox-rightpanel.js:41"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a8f40c05daa4e92", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/calendar.js:73", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/calendar.js:73"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b403a1f4f5ea4cd", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/inbox.js:120", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/inbox.js:120"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2e30602008fbb54b", "name": "Insecure pattern 'direct_outerhtml_assignment' in public/inbox.js:2279", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in public/inbox.js:2279"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-35e52c09fb1163fe", "name": "Insecure pattern 'insert_adjacent_html' in public/inbox.js:4507", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/inbox.js:4507"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0145590f9d5c66e5", "name": "Very large file: server.js (7408 lines)", "shortDescription": {"text": "Very large file: server.js (7408 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e230f8cf3bf5035d", "name": "Very large file: lib/assistant.js (3289 lines)", "shortDescription": {"text": "Very large file: lib/assistant.js (3289 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d2dd98c76a6b5f1", "name": "Very large file: lib/i18n.js (1643 lines)", "shortDescription": {"text": "Very large file: lib/i18n.js (1643 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-653c45dff3c8fe0d", "name": "Very large file: public/assistant.js (2722 lines)", "shortDescription": {"text": "Very large file: public/assistant.js (2722 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4aad9e2d1f8eceb9", "name": "Very large file: public/inbox.js (5152 lines)", "shortDescription": {"text": "Very large file: public/inbox.js (5152 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 52 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 53 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 82 placeholder/mock markers across 10 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing ci, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-97cd2bc7eb2a6bd0", "name": "Commented-code block (11 lines) in server.js:78", "shortDescription": {"text": "Commented-code block (11 lines) in server.js:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4002e007e603dac0", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server.js:5656", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server.js:5656"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a51da8f2754aefc", "name": "Commented-code block (9 lines) in lib/assistant.js:426", "shortDescription": {"text": "Commented-code block (9 lines) in lib/assistant.js:426"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5377b7e95a571b71", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/assistant.js:1466", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/assistant.js:1466"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95b3b98d3d6b7c07", "name": "Commented-code block (7 lines) in lib/plans.js:1", "shortDescription": {"text": "Commented-code block (7 lines) in lib/plans.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e47c709d83c8231", "name": "Commented-code block (5 lines) in lib/email.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in lib/email.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c1295877780f4e79", "name": "Commented-code block (7 lines) in lib/classifier.js:261", "shortDescription": {"text": "Commented-code block (7 lines) in lib/classifier.js:261"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c465173089c50240", "name": "Commented-code block (7 lines) in lib/attachments.js:8", "shortDescription": {"text": "Commented-code block (7 lines) in lib/attachments.js:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9eee686461132ad3", "name": "Commented-code block (6 lines) in lib/memory.js:1", "shortDescription": {"text": "Commented-code block (6 lines) in lib/memory.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-44897a3bef47c336", "name": "Commented-code block (5 lines) in lib/slack.js:4", "shortDescription": {"text": "Commented-code block (5 lines) in lib/slack.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5dc777f3c3cb96ce", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/slack.js:91", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/slack.js:91"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09e8472aa9793114", "name": "Commented-code block (5 lines) in lib/mime.js:151", "shortDescription": {"text": "Commented-code block (5 lines) in lib/mime.js:151"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9d48bd483c870a56", "name": "Commented-code block (7 lines) in lib/db.js:41", "shortDescription": {"text": "Commented-code block (7 lines) in lib/db.js:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-437506d346c95109", "name": "Commented-code block (6 lines) in lib/auth.js:1", "shortDescription": {"text": "Commented-code block (6 lines) in lib/auth.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ddbb4c13df0af9e0", "name": "Commented-code block (6 lines) in lib/commitments.js:16", "shortDescription": {"text": "Commented-code block (6 lines) in lib/commitments.js:16"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-07dbee1068def36c", "name": "Commented-code block (6 lines) in lib/notifications.js:17", "shortDescription": {"text": "Commented-code block (6 lines) in lib/notifications.js:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5c2af6e985266050", "name": "Commented-code block (5 lines) in lib/slackSync.js:4", "shortDescription": {"text": "Commented-code block (5 lines) in lib/slackSync.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-00c0da17968f3328", "name": "Commented-code block (7 lines) in lib/briefing.js:3", "shortDescription": {"text": "Commented-code block (7 lines) in lib/briefing.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a6aa12cf47bd612c", "name": "Commented-code block (13 lines) in lib/research.js:3", "shortDescription": {"text": "Commented-code block (13 lines) in lib/research.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-06df8c55f0499d2c", "name": "Commented-code block (8 lines) in lib/voice.js:12", "shortDescription": {"text": "Commented-code block (8 lines) in lib/voice.js:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e416e936dc1664f", "name": "Commented-code block (11 lines) in lib/realtime.js:12", "shortDescription": {"text": "Commented-code block (11 lines) in lib/realtime.js:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bbce94ab42176e93", "name": "Commented-code block (5 lines) in lib/backfill.js:7", "shortDescription": {"text": "Commented-code block (5 lines) in lib/backfill.js:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b2d6505203a6a786", "name": "Commented-code block (6 lines) in lib/gmail.js:6", "shortDescription": {"text": "Commented-code block (6 lines) in lib/gmail.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-72868667d4aabaaa", "name": "Commented-code block (5 lines) in lib/gmailPush.js:6", "shortDescription": {"text": "Commented-code block (5 lines) in lib/gmailPush.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-05d4d2d7d2786725", "name": "Commented-code block (6 lines) in lib/tasks.js:255", "shortDescription": {"text": "Commented-code block (6 lines) in lib/tasks.js:255"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4081689bdcf591dd", "name": "Commented-code block (6 lines) in lib/decisionRules.js:3", "shortDescription": {"text": "Commented-code block (6 lines) in lib/decisionRules.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b6ff8ff3129842b9", "name": "Commented-code block (8 lines) in lib/emailExtractions.js:3", "shortDescription": {"text": "Commented-code block (8 lines) in lib/emailExtractions.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-90837524cc27fddc", "name": "Commented-code block (5 lines) in lib/contacts.js:158", "shortDescription": {"text": "Commented-code block (5 lines) in lib/contacts.js:158"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4b4208d6c51a4cf6", "name": "Commented-code block (7 lines) in lib/stripe.js:1", "shortDescription": {"text": "Commented-code block (7 lines) in lib/stripe.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-32eed130eba7a199", "name": "Commented-code block (5 lines) in lib/calendar.js:47", "shortDescription": {"text": "Commented-code block (5 lines) in lib/calendar.js:47"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-454572b1d7e3da1e", "name": "Commented-code block (5 lines) in lib/inbox_cache.js:5", "shortDescription": {"text": "Commented-code block (5 lines) in lib/inbox_cache.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14aea538d758c563", "name": "Commented-code block (6 lines) in lib/tts.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in lib/tts.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-296049af657df6ec", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/tts.js:138", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/tts.js:138"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc80af7144f68c88", "name": "Commented-code block (5 lines) in lib/mail/google.js:5", "shortDescription": {"text": "Commented-code block (5 lines) in lib/mail/google.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-63704a95a428b890", "name": "Commented-code block (6 lines) in lib/mail/index.js:8", "shortDescription": {"text": "Commented-code block (6 lines) in lib/mail/index.js:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5d8688f94e9556c3", "name": "Commented-code block (6 lines) in lib/mail/microsoft.js:211", "shortDescription": {"text": "Commented-code block (6 lines) in lib/mail/microsoft.js:211"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7ec7786ad5b9e5e9", "name": "`fetch()` without try/.catch or AbortSignal \u2014 lib/mail/microsoft.js:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/mail/microsoft.js:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16e597fe1b7e7158", "name": "Commented-code block (7 lines) in public/shortcuts-global.js:1", "shortDescription": {"text": "Commented-code block (7 lines) in public/shortcuts-global.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-886f2b1a698b30d7", "name": "Commented-code block (6 lines) in public/task-notifier.js:1", "shortDescription": {"text": "Commented-code block (6 lines) in public/task-notifier.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9ba91c1fb8dec1d7", "name": "Commented-code block (9 lines) in public/assistant.js:1", "shortDescription": {"text": "Commented-code block (9 lines) in public/assistant.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5ce69cdd67d9ee99", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/assistant.js:442", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/assistant.js:442"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a9c3f2aecfa737d4", "name": "Commented-code block (12 lines) in public/markdown-inline.js:10", "shortDescription": {"text": "Commented-code block (12 lines) in public/markdown-inline.js:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf0fd46ed8692aaf", "name": "Commented-code block (6 lines) in public/voice.js:11", "shortDescription": {"text": "Commented-code block (6 lines) in public/voice.js:11"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-24eba11c3c76e49d", "name": "Commented-code block (5 lines) in public/i18n.js:3", "shortDescription": {"text": "Commented-code block (5 lines) in public/i18n.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-00e0e55558bf121a", "name": "Commented-code block (7 lines) in public/trial-banner.js:1", "shortDescription": {"text": "Commented-code block (7 lines) in public/trial-banner.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-caf72c504fd587c6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/trial-banner.js:16", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/trial-banner.js:16"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6d34d97396c27128", "name": "Commented-code block (6 lines) in public/appearance.js:15", "shortDescription": {"text": "Commented-code block (6 lines) in public/appearance.js:15"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8bd07e802c73d73d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/tasks.js:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/tasks.js:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d19b632acde77856", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/contacts.js:266", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/contacts.js:266"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b07c5899bc6303b1", "name": "Commented-code block (5 lines) in public/inbox-rightpanel.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in public/inbox-rightpanel.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2ff0fb8f8eda6f51", "name": "Commented-code block (16 lines) in public/inbox.js:204", "shortDescription": {"text": "Commented-code block (16 lines) in public/inbox.js:204"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-770cde9ba4bf6818", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/inbox.js:794", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/inbox.js:794"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0b7578dd2a289b6", "name": "26 env vars used in code but missing from .env.example", "shortDescription": {"text": "26 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_EMAILS`, `APP_URL`, `COMP_EMAILS`, `DELTA_ADVANCED_MODEL`, `DELTA_BASIC_MODEL`, `DELTA_BRIEFING_MODEL`, `DELTA_CHAT_MODEL`, `DELTA_CLASSIFY_MODEL` + 18 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25a9c135a2bc85dd", "name": "Dangling fetch: POST https://slack.com/api/oauth.v2.access (lib/slack.js:91)", "shortDescription": {"text": "Dangling fetch: POST https://slack.com/api/oauth.v2.access (lib/slack.js:91)"}, "fullDescription": {"text": "`lib/slack.js:91` calls `POST https://slack.com/api/oauth.v2.access` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/slack.com/api/oauth.v2.access`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f4b37a17591b0cf7", "name": "Dangling fetch: POST https://api.openai.com/v1/realtime/client_secrets (lib/realtime.js:333)", "shortDescription": {"text": "Dangling fetch: POST https://api.openai.com/v1/realtime/client_secrets (lib/realtime.js:333)"}, "fullDescription": {"text": "`lib/realtime.js:333` calls `POST https://api.openai.com/v1/realtime/client_secrets` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.openai.com/v1/realtime/client_secrets`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4ab20e8b8634325", "name": "Dangling fetch: POST https://api.openai.com/v1/embeddings (lib/embeddings.js:22)", "shortDescription": {"text": "Dangling fetch: POST https://api.openai.com/v1/embeddings (lib/embeddings.js:22)"}, "fullDescription": {"text": "`lib/embeddings.js:22` calls `POST https://api.openai.com/v1/embeddings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.openai.com/v1/embeddings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e9fa207fcb4213c1", "name": "Dangling fetch: POST https://api.openai.com/v1/audio/transcriptions (lib/transcribe.js:47)", "shortDescription": {"text": "Dangling fetch: POST https://api.openai.com/v1/audio/transcriptions (lib/transcribe.js:47)"}, "fullDescription": {"text": "`lib/transcribe.js:47` calls `POST https://api.openai.com/v1/audio/transcriptions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.openai.com/v1/audio/transcriptions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cd875a25fbd944e6", "name": "Dangling fetch: POST https://api.openai.com/v1/audio/speech (lib/tts.js:114)", "shortDescription": {"text": "Dangling fetch: POST https://api.openai.com/v1/audio/speech (lib/tts.js:114)"}, "fullDescription": {"text": "`lib/tts.js:114` calls `POST https://api.openai.com/v1/audio/speech` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.openai.com/v1/audio/speech`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-29573bfb7978a240", "name": "Dangling fetch: POST https://api.elevenlabs.io/v1/text-to-speech/${voice}?optimize_streaming_latency=2 (lib/tts.js:138)", "shortDescription": {"text": "Dangling fetch: POST https://api.elevenlabs.io/v1/text-to-speech/${voice}?optimize_streaming_latency=2 (lib/tts.js:138)"}, "fullDescription": {"text": "`lib/tts.js:138` calls `POST https://api.elevenlabs.io/v1/text-to-speech/${voice}?optimize_streaming_latency=2` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.elevenlabs.io/v1/text-to-speech/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78277a94fc1da100", "name": "Dangling fetch: POST https://api.openai.com/v1/realtime/calls?model=${encodeURIComponent(voiceMode.model)} (public/voice", "shortDescription": {"text": "Dangling fetch: POST https://api.openai.com/v1/realtime/calls?model=${encodeURIComponent(voiceMode.model)} (public/voice.js:126)"}, "fullDescription": {"text": "`public/voice.js:126` calls `POST https://api.openai.com/v1/realtime/calls?model=${encodeURIComponent(voiceMode.model)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.openai.com/v1/realtime/calls`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bdcea8e7200cac75", "name": "Dangling fetch: GET /api/me/appearance-prefs (public/appearance.js:50)", "shortDescription": {"text": "Dangling fetch: GET /api/me/appearance-prefs (public/appearance.js:50)"}, "fullDescription": {"text": "`public/appearance.js:50` calls `GET /api/me/appearance-prefs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/me/appearance-prefs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eadf6054c953f759", "name": "Dangling fetch: GET /api/me/calendar-prefs (public/calendar.js:466)", "shortDescription": {"text": "Dangling fetch: GET /api/me/calendar-prefs (public/calendar.js:466)"}, "fullDescription": {"text": "`public/calendar.js:466` calls `GET /api/me/calendar-prefs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/me/calendar-prefs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4de8650da7860520", "name": "Dangling fetch: GET /api/me/compose-prefs (public/inbox.js:2748)", "shortDescription": {"text": "Dangling fetch: GET /api/me/compose-prefs (public/inbox.js:2748)"}, "fullDescription": {"text": "`public/inbox.js:2748` calls `GET /api/me/compose-prefs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/me/compose-prefs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5be75a2c2c191250", "name": "Unused endpoint: USE /webhooks/stripe", "shortDescription": {"text": "Unused endpoint: USE /webhooks/stripe"}, "fullDescription": {"text": "`server.js` declares `USE /webhooks/stripe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e9f0c712241895d", "name": "Unused endpoint: GET /auth/google", "shortDescription": {"text": "Unused endpoint: GET /auth/google"}, "fullDescription": {"text": "`server.js` declares `GET /auth/google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-392dcbd9c0e4ed85", "name": "Unused endpoint: GET /auth/google/callback", "shortDescription": {"text": "Unused endpoint: GET /auth/google/callback"}, "fullDescription": {"text": "`server.js` declares `GET /auth/google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4ee452467a77fea", "name": "Unused endpoint: GET /auth/microsoft", "shortDescription": {"text": "Unused endpoint: GET /auth/microsoft"}, "fullDescription": {"text": "`server.js` declares `GET /auth/microsoft` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-239257db12035088", "name": "Unused endpoint: GET /auth/microsoft/callback", "shortDescription": {"text": "Unused endpoint: GET /auth/microsoft/callback"}, "fullDescription": {"text": "`server.js` declares `GET /auth/microsoft/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c059f57186114027", "name": "Unused endpoint: POST /auth/logout", "shortDescription": {"text": "Unused endpoint: POST /auth/logout"}, "fullDescription": {"text": "`server.js` declares `POST /auth/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c702f92b682cca1", "name": "Unused endpoint: GET /auth/logout", "shortDescription": {"text": "Unused endpoint: GET /auth/logout"}, "fullDescription": {"text": "`server.js` declares `GET /auth/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c2cfd73ef2e3487", "name": "Unused endpoint: GET /pricing", "shortDescription": {"text": "Unused endpoint: GET /pricing"}, "fullDescription": {"text": "`server.js` declares `GET /pricing` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9299b6d38b686db7", "name": "Unused endpoint: GET /api/auth/providers", "shortDescription": {"text": "Unused endpoint: GET /api/auth/providers"}, "fullDescription": {"text": "`server.js` declares `GET /api/auth/providers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd5f34ed3a71a3a9", "name": "Unused endpoint: GET /m/inbox", "shortDescription": {"text": "Unused endpoint: GET /m/inbox"}, "fullDescription": {"text": "`server.js` declares `GET /m/inbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9daee89b78e9ceac", "name": "Unused endpoint: GET /privacy", "shortDescription": {"text": "Unused endpoint: GET /privacy"}, "fullDescription": {"text": "`server.js` declares `GET /privacy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ebe3481a27b770a5", "name": "Unused endpoint: GET /terms", "shortDescription": {"text": "Unused endpoint: GET /terms"}, "fullDescription": {"text": "`server.js` declares `GET /terms` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccd55bfbd01cf75e", "name": "Unused endpoint: POST /api/waitlist/provider", "shortDescription": {"text": "Unused endpoint: POST /api/waitlist/provider"}, "fullDescription": {"text": "`server.js` declares `POST /api/waitlist/provider` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9481944d13e157c", "name": "Unused endpoint: GET /admin/diag/provider-waitlist", "shortDescription": {"text": "Unused endpoint: GET /admin/diag/provider-waitlist"}, "fullDescription": {"text": "`server.js` declares `GET /admin/diag/provider-waitlist` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f55d735a5546f8b5", "name": "Unused endpoint: GET /admin/diag/stripe-portal-check", "shortDescription": {"text": "Unused endpoint: GET /admin/diag/stripe-portal-check"}, "fullDescription": {"text": "`server.js` declares `GET /admin/diag/stripe-portal-check` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e378d495a47dbd93", "name": "Unused endpoint: GET /admin/diag/user-activity", "shortDescription": {"text": "Unused endpoint: GET /admin/diag/user-activity"}, "fullDescription": {"text": "`server.js` declares `GET /admin/diag/user-activity` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a226e251e045be1c", "name": "Unused endpoint: GET /admin/cron/reviewer-watch", "shortDescription": {"text": "Unused endpoint: GET /admin/cron/reviewer-watch"}, "fullDescription": {"text": "`server.js` declares `GET /admin/cron/reviewer-watch` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aed5517ca64f55e7", "name": "Unused endpoint: GET /api/mail/inbox", "shortDescription": {"text": "Unused endpoint: GET /api/mail/inbox"}, "fullDescription": {"text": "`server.js` declares `GET /api/mail/inbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e14c9a02ab6ec228", "name": "Unused endpoint: GET /api/mail/message/:id", "shortDescription": {"text": "Unused endpoint: GET /api/mail/message/:id"}, "fullDescription": {"text": "`server.js` declares `GET /api/mail/message/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0830cd647588f848", "name": "Unused endpoint: POST /api/mail/send", "shortDescription": {"text": "Unused endpoint: POST /api/mail/send"}, "fullDescription": {"text": "`server.js` declares `POST /api/mail/send` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1117e48d6a75b60", "name": "Unused endpoint: GET /api/mail/folders", "shortDescription": {"text": "Unused endpoint: GET /api/mail/folders"}, "fullDescription": {"text": "`server.js` declares `GET /api/mail/folders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fb8db0f7bf09974", "name": "Unused endpoint: POST /admin/diag/restore-user", "shortDescription": {"text": "Unused endpoint: POST /admin/diag/restore-user"}, "fullDescription": {"text": "`server.js` declares `POST /admin/diag/restore-user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab959fb2b3c21d70", "name": "Unused endpoint: DELETE /admin/diag/delete-user", "shortDescription": {"text": "Unused endpoint: DELETE /admin/diag/delete-user"}, "fullDescription": {"text": "`server.js` declares `DELETE /admin/diag/delete-user` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-40d1259764973389", "name": "Unused endpoint: GET /admin/diag/microsoft-calendar", "shortDescription": {"text": "Unused endpoint: GET /admin/diag/microsoft-calendar"}, "fullDescription": {"text": "`server.js` declares `GET /admin/diag/microsoft-calendar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7346d450634abe36", "name": "Unused endpoint: GET /admin/diag/microsoft-inbox", "shortDescription": {"text": "Unused endpoint: GET /admin/diag/microsoft-inbox"}, "fullDescription": {"text": "`server.js` declares `GET /admin/diag/microsoft-inbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da49fd123cc95586", "name": "Unused endpoint: GET /welcome", "shortDescription": {"text": "Unused endpoint: GET /welcome"}, "fullDescription": {"text": "`server.js` declares `GET /welcome` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-512ccb0fd0b230ba", "name": "Unused endpoint: GET /settings", "shortDescription": {"text": "Unused endpoint: GET /settings"}, "fullDescription": {"text": "`server.js` declares `GET /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f9819d9ecb49931", "name": "Unused endpoint: GET /calendar", "shortDescription": {"text": "Unused endpoint: GET /calendar"}, "fullDescription": {"text": "`server.js` declares `GET /calendar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edf3354c30f8a8ee", "name": "Unused endpoint: GET /promises", "shortDescription": {"text": "Unused endpoint: GET /promises"}, "fullDescription": {"text": "`server.js` declares `GET /promises` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60561387e4df646a", "name": "Unused endpoint: PATCH /api/tasks/lists/:id", "shortDescription": {"text": "Unused endpoint: PATCH /api/tasks/lists/:id"}, "fullDescription": {"text": "`server.js` declares `PATCH /api/tasks/lists/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d45a3a0f6438f530", "name": "Unused endpoint: DELETE /api/tasks/lists/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/tasks/lists/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/tasks/lists/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf16ae0930dc161a", "name": "Unused endpoint: GET /api/tasks", "shortDescription": {"text": "Unused endpoint: GET /api/tasks"}, "fullDescription": {"text": "`server.js` declares `GET /api/tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abcdaab0f31bad94", "name": "Unused endpoint: PATCH /api/me/language", "shortDescription": {"text": "Unused endpoint: PATCH /api/me/language"}, "fullDescription": {"text": "`server.js` declares `PATCH /api/me/language` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0d6dc0d3c3e353d", "name": "Unused endpoint: GET /api/me/plan", "shortDescription": {"text": "Unused endpoint: GET /api/me/plan"}, "fullDescription": {"text": "`server.js` declares `GET /api/me/plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f65e9a5767cf6b6", "name": "Unused endpoint: POST /api/billing/checkout", "shortDescription": {"text": "Unused endpoint: POST /api/billing/checkout"}, "fullDescription": {"text": "`server.js` declares `POST /api/billing/checkout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b866b6b0abeff2e0", "name": "Unused endpoint: POST /api/billing/change-plan", "shortDescription": {"text": "Unused endpoint: POST /api/billing/change-plan"}, "fullDescription": {"text": "`server.js` declares `POST /api/billing/change-plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6583515438ad9de7", "name": "Unused endpoint: POST /api/billing/portal", "shortDescription": {"text": "Unused endpoint: POST /api/billing/portal"}, "fullDescription": {"text": "`server.js` declares `POST /api/billing/portal` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0b4d98711d639c6", "name": "Unused endpoint: POST /api/admin/stripe-setup", "shortDescription": {"text": "Unused endpoint: POST /api/admin/stripe-setup"}, "fullDescription": {"text": "`server.js` declares `POST /api/admin/stripe-setup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1dfcc9529630142e", "name": "Unused endpoint: POST /webhooks/stripe", "shortDescription": {"text": "Unused endpoint: POST /webhooks/stripe"}, "fullDescription": {"text": "`server.js` declares `POST /webhooks/stripe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-663f9e690d0dfc3f", "name": "Unused endpoint: PATCH /api/calendar/events/:id", "shortDescription": {"text": "Unused endpoint: PATCH /api/calendar/events/:id"}, "fullDescription": {"text": "`server.js` declares `PATCH /api/calendar/events/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46f846fd85ff3b05", "name": "Unused endpoint: POST /api/gmail/push/webhook", "shortDescription": {"text": "Unused endpoint: POST /api/gmail/push/webhook"}, "fullDescription": {"text": "`server.js` declares `POST /api/gmail/push/webhook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7592a73e9a4cfdaf", "name": "Unused endpoint: POST /api/gmail/push/enable", "shortDescription": {"text": "Unused endpoint: POST /api/gmail/push/enable"}, "fullDescription": {"text": "`server.js` declares `POST /api/gmail/push/enable` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4582933a951b9ca3", "name": "Unused endpoint: POST /api/gmail/push/disable", "shortDescription": {"text": "Unused endpoint: POST /api/gmail/push/disable"}, "fullDescription": {"text": "`server.js` declares `POST /api/gmail/push/disable` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c2e84e138d384f4", "name": "Unused endpoint: GET /api/gmail/push/status", "shortDescription": {"text": "Unused endpoint: GET /api/gmail/push/status"}, "fullDescription": {"text": "`server.js` declares `GET /api/gmail/push/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65386a5fee96df6b", "name": "Unused endpoint: GET /api/decision-rules/rules", "shortDescription": {"text": "Unused endpoint: GET /api/decision-rules/rules"}, "fullDescription": {"text": "`server.js` declares `GET /api/decision-rules/rules` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd85f98241272735", "name": "Unused endpoint: PATCH /api/decision-rules/rules/:id", "shortDescription": {"text": "Unused endpoint: PATCH /api/decision-rules/rules/:id"}, "fullDescription": {"text": "`server.js` declares `PATCH /api/decision-rules/rules/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05a2eba4807442ea", "name": "Unused endpoint: DELETE /api/decision-rules/rules/:id", "shortDescription": {"text": "Unused endpoint: DELETE /api/decision-rules/rules/:id"}, "fullDescription": {"text": "`server.js` declares `DELETE /api/decision-rules/rules/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dab284d387ded039", "name": "Unused endpoint: POST /api/decision-rules/mine", "shortDescription": {"text": "Unused endpoint: POST /api/decision-rules/mine"}, "fullDescription": {"text": "`server.js` declares `POST /api/decision-rules/mine` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c80d15878f8ab78e", "name": "Unused endpoint: GET /api/commitments", "shortDescription": {"text": "Unused endpoint: GET /api/commitments"}, "fullDescription": {"text": "`server.js` declares `GET /api/commitments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19359"}, "properties": {"repository": "shahryar-oss/nexamails", "repoUrl": "https://github.com/shahryar-oss/nexamails", "branch": "main"}, "results": [{"ruleId": "scanner-d0f9fb3b411b03d2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:51"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "d0f9fb3b411b03d2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9c9ead98014bdba3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/assistant.js:2598"}, "properties": {"repobilityId": "bd3e3afe690c6378", "scanner": "scanner-primary", "fingerprint": "9c9ead98014bdba3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2133f575404b6667", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/email.js:343"}, "properties": {"repobilityId": "b97432fe9a30e71c", "scanner": "scanner-primary", "fingerprint": "2133f575404b6667", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2fbc491e7f753071", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/db.js:1104"}, "properties": {"repobilityId": "410b356045e362c5", "scanner": "scanner-primary", "fingerprint": "2fbc491e7f753071", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa4f9bb140cdd37c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/commitments.js:207"}, "properties": {"repobilityId": "6171ccf6919eced9", "scanner": "scanner-primary", "fingerprint": "aa4f9bb140cdd37c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-51ee800d48b8aaee", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/memory_extractor.js:272"}, "properties": {"repobilityId": "8b9ed41684d4e972", "scanner": "scanner-primary", "fingerprint": "51ee800d48b8aaee", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f242bc5448ad27aa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/voice.js:312"}, "properties": {"repobilityId": "3089448bffd581b1", "scanner": "scanner-primary", "fingerprint": "f242bc5448ad27aa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3f09f08500de0e78", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/backfill.js:668"}, "properties": {"repobilityId": "4f1ad0cc9462869e", "scanner": "scanner-primary", "fingerprint": "3f09f08500de0e78", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f1fb7d862533cf1d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/snooze.js:182"}, "properties": {"repobilityId": "a8da1714c298fd19", "scanner": "scanner-primary", "fingerprint": "f1fb7d862533cf1d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-91c017e27ee7a244", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/gmailPush.js:277"}, "properties": {"repobilityId": "cccfdb3e7cca423f", "scanner": "scanner-primary", "fingerprint": "91c017e27ee7a244", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f78b44721828b9b4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/emailExtractions.js:282"}, "properties": {"repobilityId": "65a1f3742fdfe183", "scanner": "scanner-primary", "fingerprint": "f78b44721828b9b4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5000a8d80795e340", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 lib/inbox_cache.js:96"}, "properties": {"repobilityId": "50a6fbc049426538", "scanner": "scanner-primary", "fingerprint": "5000a8d80795e340", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-697b20a6eaf81662", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 public/assistant.js:407"}, "properties": {"repobilityId": "4675bc20ab3c0cab", "scanner": "scanner-primary", "fingerprint": "697b20a6eaf81662", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c9f28e56df0fd689", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 public/voice.js:280"}, "properties": {"repobilityId": "f6d55ec6a27bf729", "scanner": "scanner-primary", "fingerprint": "c9f28e56df0fd689", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c9445d669fefb183", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 public/inbox.js:1890"}, "properties": {"repobilityId": "6a18836f4d0efb68", "scanner": "scanner-primary", "fingerprint": "c9445d669fefb183", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7d86a453284538bf", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/shortcuts-global.js:89"}, "properties": {"repobilityId": "7ddeeeb1ce11e42a", "scanner": "scanner-primary", "fingerprint": "7d86a453284538bf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/shortcuts-global.js"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-f46fac34f2dc8c3b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/help.html:710"}, "properties": {"repobilityId": "7cd3aaa8fa777f29", "scanner": "scanner-primary", "fingerprint": "f46fac34f2dc8c3b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/help.html"}, "region": {"startLine": 710}}}]}, {"ruleId": "scanner-5048fbf16c94f82c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/assistant.js:357"}, "properties": {"repobilityId": "c7e4a9785c751ac3", "scanner": "scanner-primary", "fingerprint": "5048fbf16c94f82c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/assistant.js"}, "region": {"startLine": 357}}}]}, {"ruleId": "scanner-96dc1e642e326e39", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/markdown-inline.js:210"}, "properties": {"repobilityId": "e706d6a012f72ade", "scanner": "scanner-primary", "fingerprint": "96dc1e642e326e39", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/markdown-inline.js"}, "region": {"startLine": 210}}}]}, {"ruleId": "scanner-a7c1ca8ec182dc4d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/pricing.html:299"}, "properties": {"repobilityId": "4b13893f909afcd0", "scanner": "scanner-primary", "fingerprint": "a7c1ca8ec182dc4d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/pricing.html"}, "region": {"startLine": 299}}}]}, {"ruleId": "scanner-dd890213a9c6f15b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/m-inbox.html:194"}, "properties": {"repobilityId": "b79a1d2143ff287d", "scanner": "scanner-primary", "fingerprint": "dd890213a9c6f15b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/m-inbox.html"}, "region": {"startLine": 194}}}]}, {"ruleId": "scanner-648872a622a2e755", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/voice.js:247"}, "properties": {"repobilityId": "d93d68889f06323e", "scanner": "scanner-primary", "fingerprint": "648872a622a2e755", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/voice.js"}, "region": {"startLine": 247}}}]}, {"ruleId": "scanner-80d985592ee2a7bd", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/welcome.html:335"}, "properties": {"repobilityId": "c88df5b73f30b3d8", "scanner": "scanner-primary", "fingerprint": "80d985592ee2a7bd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/welcome.html"}, "region": {"startLine": 335}}}]}, {"ruleId": "scanner-4ac20ff4ac05d860", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/trial-banner.js:64"}, "properties": {"repobilityId": "386a76234f1ddbd9", "scanner": "scanner-primary", "fingerprint": "4ac20ff4ac05d860", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/trial-banner.js"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-1e092f00ef0c06ff", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/settings.html:2347"}, "properties": {"repobilityId": "6ab5f94575e9a184", "scanner": "scanner-primary", "fingerprint": "1e092f00ef0c06ff", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/settings.html"}, "region": {"startLine": 2347}}}]}, {"ruleId": "scanner-17804701afb784ec", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/tasks.js:69"}, "properties": {"repobilityId": "0f8982186645346a", "scanner": "scanner-primary", "fingerprint": "17804701afb784ec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/tasks.js"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-cd447b74fd191a43", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/promises.html:384"}, "properties": {"repobilityId": "23d358ad43a269bd", "scanner": "scanner-primary", "fingerprint": "cd447b74fd191a43", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/promises.html"}, "region": {"startLine": 384}}}]}, {"ruleId": "scanner-d31d62fb855fea4a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/contacts.js:59"}, "properties": {"repobilityId": "81babd82370c6e24", "scanner": "scanner-primary", "fingerprint": "d31d62fb855fea4a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/contacts.js"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-626500fb52cd12e8", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/inbox-rightpanel.js:41"}, "properties": {"repobilityId": "6793c39da3be0140", "scanner": "scanner-primary", "fingerprint": "626500fb52cd12e8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/inbox-rightpanel.js"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-8a8f40c05daa4e92", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/calendar.js:73"}, "properties": {"repobilityId": "52c07f6fd2698826", "scanner": "scanner-primary", "fingerprint": "8a8f40c05daa4e92", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/calendar.js"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-5b403a1f4f5ea4cd", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/inbox.js:120"}, "properties": {"repobilityId": "4373e73a03962963", "scanner": "scanner-primary", "fingerprint": "5b403a1f4f5ea4cd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/inbox.js"}, "region": {"startLine": 120}}}]}, {"ruleId": "scanner-2e30602008fbb54b", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in public/inbox.js:2279"}, "properties": {"repobilityId": "818b4f6d52e44e8d", "scanner": "scanner-primary", "fingerprint": "2e30602008fbb54b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/inbox.js"}, "region": {"startLine": 2279}}}]}, {"ruleId": "scanner-35e52c09fb1163fe", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/inbox.js:4507"}, "properties": {"repobilityId": "acfa665c8799a843", "scanner": "scanner-primary", "fingerprint": "35e52c09fb1163fe", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/inbox.js"}, "region": {"startLine": 4507}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-0145590f9d5c66e5", "level": "note", "message": {"text": "Very large file: server.js (7408 lines)"}, "properties": {"repobilityId": "1479ba50e708c5c1", "scanner": "scanner-primary", "fingerprint": "0145590f9d5c66e5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e230f8cf3bf5035d", "level": "note", "message": {"text": "Very large file: lib/assistant.js (3289 lines)"}, "properties": {"repobilityId": "d7f637958511fddb", "scanner": "scanner-primary", "fingerprint": "e230f8cf3bf5035d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0d2dd98c76a6b5f1", "level": "note", "message": {"text": "Very large file: lib/i18n.js (1643 lines)"}, "properties": {"repobilityId": "e9d85593461c907f", "scanner": "scanner-primary", "fingerprint": "0d2dd98c76a6b5f1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-653c45dff3c8fe0d", "level": "note", "message": {"text": "Very large file: public/assistant.js (2722 lines)"}, "properties": {"repobilityId": "16030461be778667", "scanner": "scanner-primary", "fingerprint": "653c45dff3c8fe0d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4aad9e2d1f8eceb9", "level": "note", "message": {"text": "Very large file: public/inbox.js (5152 lines)"}, "properties": {"repobilityId": "822428a2fdf83037", "scanner": "scanner-primary", "fingerprint": "4aad9e2d1f8eceb9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "8a1b08ce2bfedbe1", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "e3393dfca269ed79", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "7d8440dc66d3cce1", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "0d03b18d70fd90c1", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "001cdf0133f456ac", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "3a58aadd2ad98d8f", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "8db6ee0ae9a6f25d", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "16142d69f8955c69", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-97cd2bc7eb2a6bd0", "level": "none", "message": {"text": "Commented-code block (11 lines) in server.js:78"}, "properties": {"repobilityId": "a217a9497b84e710", "scanner": "scanner-primary", "fingerprint": "97cd2bc7eb2a6bd0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4002e007e603dac0", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server.js:5656"}, "properties": {"repobilityId": "76db0c7a35749d76", "scanner": "scanner-primary", "fingerprint": "4002e007e603dac0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2a51da8f2754aefc", "level": "none", "message": {"text": "Commented-code block (9 lines) in lib/assistant.js:426"}, "properties": {"repobilityId": "1ae398a2886cbba2", "scanner": "scanner-primary", "fingerprint": "2a51da8f2754aefc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5377b7e95a571b71", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/assistant.js:1466"}, "properties": {"repobilityId": "329fef97002075eb", "scanner": "scanner-primary", "fingerprint": "5377b7e95a571b71", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-95b3b98d3d6b7c07", "level": "none", "message": {"text": "Commented-code block (7 lines) in lib/plans.js:1"}, "properties": {"repobilityId": "cf8602318dd81d92", "scanner": "scanner-primary", "fingerprint": "95b3b98d3d6b7c07", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1e47c709d83c8231", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/email.js:1"}, "properties": {"repobilityId": "ee19314571c563c6", "scanner": "scanner-primary", "fingerprint": "1e47c709d83c8231", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c1295877780f4e79", "level": "none", "message": {"text": "Commented-code block (7 lines) in lib/classifier.js:261"}, "properties": {"repobilityId": "0404cacf1393e844", "scanner": "scanner-primary", "fingerprint": "c1295877780f4e79", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c465173089c50240", "level": "none", "message": {"text": "Commented-code block (7 lines) in lib/attachments.js:8"}, "properties": {"repobilityId": "d9ca2236472f5845", "scanner": "scanner-primary", "fingerprint": "c465173089c50240", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9eee686461132ad3", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/memory.js:1"}, "properties": {"repobilityId": "fab997b08f743b90", "scanner": "scanner-primary", "fingerprint": "9eee686461132ad3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-44897a3bef47c336", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/slack.js:4"}, "properties": {"repobilityId": "f656b9fee7b8a101", "scanner": "scanner-primary", "fingerprint": "44897a3bef47c336", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5dc777f3c3cb96ce", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/slack.js:91"}, "properties": {"repobilityId": "11a15d38f3af364b", "scanner": "scanner-primary", "fingerprint": "5dc777f3c3cb96ce", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-09e8472aa9793114", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/mime.js:151"}, "properties": {"repobilityId": "29d4d0fe9d419dae", "scanner": "scanner-primary", "fingerprint": "09e8472aa9793114", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9d48bd483c870a56", "level": "none", "message": {"text": "Commented-code block (7 lines) in lib/db.js:41"}, "properties": {"repobilityId": "0e20c439a543394b", "scanner": "scanner-primary", "fingerprint": "9d48bd483c870a56", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-437506d346c95109", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/auth.js:1"}, "properties": {"repobilityId": "b16e55ea70857885", "scanner": "scanner-primary", "fingerprint": "437506d346c95109", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ddbb4c13df0af9e0", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/commitments.js:16"}, "properties": {"repobilityId": "82b782ceb1529096", "scanner": "scanner-primary", "fingerprint": "ddbb4c13df0af9e0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-07dbee1068def36c", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/notifications.js:17"}, "properties": {"repobilityId": "01aaeea0e0fdd992", "scanner": "scanner-primary", "fingerprint": "07dbee1068def36c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5c2af6e985266050", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/slackSync.js:4"}, "properties": {"repobilityId": "a30215d0caff946d", "scanner": "scanner-primary", "fingerprint": "5c2af6e985266050", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-00c0da17968f3328", "level": "none", "message": {"text": "Commented-code block (7 lines) in lib/briefing.js:3"}, "properties": {"repobilityId": "1774318cf333fa84", "scanner": "scanner-primary", "fingerprint": "00c0da17968f3328", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a6aa12cf47bd612c", "level": "none", "message": {"text": "Commented-code block (13 lines) in lib/research.js:3"}, "properties": {"repobilityId": "2e6186f38941e9dc", "scanner": "scanner-primary", "fingerprint": "a6aa12cf47bd612c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-06df8c55f0499d2c", "level": "none", "message": {"text": "Commented-code block (8 lines) in lib/voice.js:12"}, "properties": {"repobilityId": "6da69a11cc1d5eca", "scanner": "scanner-primary", "fingerprint": "06df8c55f0499d2c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1e416e936dc1664f", "level": "none", "message": {"text": "Commented-code block (11 lines) in lib/realtime.js:12"}, "properties": {"repobilityId": "f9a7e9de5a5643c8", "scanner": "scanner-primary", "fingerprint": "1e416e936dc1664f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bbce94ab42176e93", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/backfill.js:7"}, "properties": {"repobilityId": "ec1152fc23294f85", "scanner": "scanner-primary", "fingerprint": "bbce94ab42176e93", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b2d6505203a6a786", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/gmail.js:6"}, "properties": {"repobilityId": "4e179f29a8ebe0ff", "scanner": "scanner-primary", "fingerprint": "b2d6505203a6a786", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-72868667d4aabaaa", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/gmailPush.js:6"}, "properties": {"repobilityId": "01f5ed7a441b51f2", "scanner": "scanner-primary", "fingerprint": "72868667d4aabaaa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-05d4d2d7d2786725", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/tasks.js:255"}, "properties": {"repobilityId": "68883a13664ea51e", "scanner": "scanner-primary", "fingerprint": "05d4d2d7d2786725", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4081689bdcf591dd", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/decisionRules.js:3"}, "properties": {"repobilityId": "f0d4e85492386a8c", "scanner": "scanner-primary", "fingerprint": "4081689bdcf591dd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b6ff8ff3129842b9", "level": "none", "message": {"text": "Commented-code block (8 lines) in lib/emailExtractions.js:3"}, "properties": {"repobilityId": "19144ec3065f74a2", "scanner": "scanner-primary", "fingerprint": "b6ff8ff3129842b9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-90837524cc27fddc", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/contacts.js:158"}, "properties": {"repobilityId": "36fd8d8bfc07565a", "scanner": "scanner-primary", "fingerprint": "90837524cc27fddc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4b4208d6c51a4cf6", "level": "none", "message": {"text": "Commented-code block (7 lines) in lib/stripe.js:1"}, "properties": {"repobilityId": "999333c4b60b553d", "scanner": "scanner-primary", "fingerprint": "4b4208d6c51a4cf6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-32eed130eba7a199", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/calendar.js:47"}, "properties": {"repobilityId": "1fd7fc0bde8e307f", "scanner": "scanner-primary", "fingerprint": "32eed130eba7a199", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-454572b1d7e3da1e", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/inbox_cache.js:5"}, "properties": {"repobilityId": "01f031cf8e21dbc9", "scanner": "scanner-primary", "fingerprint": "454572b1d7e3da1e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-14aea538d758c563", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/tts.js:5"}, "properties": {"repobilityId": "82f6118c15ea64a9", "scanner": "scanner-primary", "fingerprint": "14aea538d758c563", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-296049af657df6ec", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/tts.js:138"}, "properties": {"repobilityId": "21a4df6b0aaab6ec", "scanner": "scanner-primary", "fingerprint": "296049af657df6ec", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-cc80af7144f68c88", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/mail/google.js:5"}, "properties": {"repobilityId": "2b16c6a628b7b98b", "scanner": "scanner-primary", "fingerprint": "cc80af7144f68c88", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-63704a95a428b890", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/mail/index.js:8"}, "properties": {"repobilityId": "ec78bc310905b89a", "scanner": "scanner-primary", "fingerprint": "63704a95a428b890", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5d8688f94e9556c3", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/mail/microsoft.js:211"}, "properties": {"repobilityId": "c7478f61537db6fe", "scanner": "scanner-primary", "fingerprint": "5d8688f94e9556c3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7ec7786ad5b9e5e9", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 lib/mail/microsoft.js:6"}, "properties": {"repobilityId": "8f58b13bb9b07930", "scanner": "scanner-primary", "fingerprint": "7ec7786ad5b9e5e9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-16e597fe1b7e7158", "level": "none", "message": {"text": "Commented-code block (7 lines) in public/shortcuts-global.js:1"}, "properties": {"repobilityId": "889d3614feae4ba6", "scanner": "scanner-primary", "fingerprint": "16e597fe1b7e7158", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-886f2b1a698b30d7", "level": "none", "message": {"text": "Commented-code block (6 lines) in public/task-notifier.js:1"}, "properties": {"repobilityId": "0491b19a60242e38", "scanner": "scanner-primary", "fingerprint": "886f2b1a698b30d7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9ba91c1fb8dec1d7", "level": "none", "message": {"text": "Commented-code block (9 lines) in public/assistant.js:1"}, "properties": {"repobilityId": "0190524c9ca83af2", "scanner": "scanner-primary", "fingerprint": "9ba91c1fb8dec1d7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5ce69cdd67d9ee99", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/assistant.js:442"}, "properties": {"repobilityId": "34a18db2829440b7", "scanner": "scanner-primary", "fingerprint": "5ce69cdd67d9ee99", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a9c3f2aecfa737d4", "level": "none", "message": {"text": "Commented-code block (12 lines) in public/markdown-inline.js:10"}, "properties": {"repobilityId": "14d8c99ed9575dcc", "scanner": "scanner-primary", "fingerprint": "a9c3f2aecfa737d4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf0fd46ed8692aaf", "level": "none", "message": {"text": "Commented-code block (6 lines) in public/voice.js:11"}, "properties": {"repobilityId": "d58e67faa6476a54", "scanner": "scanner-primary", "fingerprint": "bf0fd46ed8692aaf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-24eba11c3c76e49d", "level": "none", "message": {"text": "Commented-code block (5 lines) in public/i18n.js:3"}, "properties": {"repobilityId": "a5fecccc04b20247", "scanner": "scanner-primary", "fingerprint": "24eba11c3c76e49d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-00e0e55558bf121a", "level": "none", "message": {"text": "Commented-code block (7 lines) in public/trial-banner.js:1"}, "properties": {"repobilityId": "e1854134ab2e0108", "scanner": "scanner-primary", "fingerprint": "00e0e55558bf121a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-caf72c504fd587c6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/trial-banner.js:16"}, "properties": {"repobilityId": "3eb8e199502813aa", "scanner": "scanner-primary", "fingerprint": "caf72c504fd587c6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6d34d97396c27128", "level": "none", "message": {"text": "Commented-code block (6 lines) in public/appearance.js:15"}, "properties": {"repobilityId": "ffb05e08430621f3", "scanner": "scanner-primary", "fingerprint": "6d34d97396c27128", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8bd07e802c73d73d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/tasks.js:50"}, "properties": {"repobilityId": "57c35af5ca57af7b", "scanner": "scanner-primary", "fingerprint": "8bd07e802c73d73d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d19b632acde77856", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/contacts.js:266"}, "properties": {"repobilityId": "865a2958cd6b883a", "scanner": "scanner-primary", "fingerprint": "d19b632acde77856", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b07c5899bc6303b1", "level": "none", "message": {"text": "Commented-code block (5 lines) in public/inbox-rightpanel.js:1"}, "properties": {"repobilityId": "b8230b0a8dc16db9", "scanner": "scanner-primary", "fingerprint": "b07c5899bc6303b1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2ff0fb8f8eda6f51", "level": "none", "message": {"text": "Commented-code block (16 lines) in public/inbox.js:204"}, "properties": {"repobilityId": "a5d557ea23cc2e69", "scanner": "scanner-primary", "fingerprint": "2ff0fb8f8eda6f51", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-770cde9ba4bf6818", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/inbox.js:794"}, "properties": {"repobilityId": "92170f917ac99688", "scanner": "scanner-primary", "fingerprint": "770cde9ba4bf6818", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b0b7578dd2a289b6", "level": "note", "message": {"text": "26 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "8099a5c5713d37b9", "scanner": "scanner-primary", "fingerprint": "b0b7578dd2a289b6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-25a9c135a2bc85dd", "level": "error", "message": {"text": "Dangling fetch: POST https://slack.com/api/oauth.v2.access (lib/slack.js:91)"}, "properties": {"repobilityId": "9bdd8eaf88f2ab07", "scanner": "scanner-primary", "fingerprint": "25a9c135a2bc85dd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f4b37a17591b0cf7", "level": "error", "message": {"text": "Dangling fetch: POST https://api.openai.com/v1/realtime/client_secrets (lib/realtime.js:333)"}, "properties": {"repobilityId": "15d374c34983feb3", "scanner": "scanner-primary", "fingerprint": "f4b37a17591b0cf7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e4ab20e8b8634325", "level": "error", "message": {"text": "Dangling fetch: POST https://api.openai.com/v1/embeddings (lib/embeddings.js:22)"}, "properties": {"repobilityId": "68d6a503aabf05ab", "scanner": "scanner-primary", "fingerprint": "e4ab20e8b8634325", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e9fa207fcb4213c1", "level": "error", "message": {"text": "Dangling fetch: POST https://api.openai.com/v1/audio/transcriptions (lib/transcribe.js:47)"}, "properties": {"repobilityId": "e58046efd31eb584", "scanner": "scanner-primary", "fingerprint": "e9fa207fcb4213c1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cd875a25fbd944e6", "level": "error", "message": {"text": "Dangling fetch: POST https://api.openai.com/v1/audio/speech (lib/tts.js:114)"}, "properties": {"repobilityId": "0708a857420719bd", "scanner": "scanner-primary", "fingerprint": "cd875a25fbd944e6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-29573bfb7978a240", "level": "error", "message": {"text": "Dangling fetch: POST https://api.elevenlabs.io/v1/text-to-speech/${voice}?optimize_streaming_latency=2 (lib/tts.js:138)"}, "properties": {"repobilityId": "e26e3001db23d177", "scanner": "scanner-primary", "fingerprint": "29573bfb7978a240", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-78277a94fc1da100", "level": "error", "message": {"text": "Dangling fetch: POST https://api.openai.com/v1/realtime/calls?model=${encodeURIComponent(voiceMode.model)} (public/voice.js:126)"}, "properties": {"repobilityId": "0ca435947f9f993e", "scanner": "scanner-primary", "fingerprint": "78277a94fc1da100", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bdcea8e7200cac75", "level": "error", "message": {"text": "Dangling fetch: GET /api/me/appearance-prefs (public/appearance.js:50)"}, "properties": {"repobilityId": "514504ffd8ed3eaf", "scanner": "scanner-primary", "fingerprint": "bdcea8e7200cac75", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-eadf6054c953f759", "level": "error", "message": {"text": "Dangling fetch: GET /api/me/calendar-prefs (public/calendar.js:466)"}, "properties": {"repobilityId": "abb266bf35604592", "scanner": "scanner-primary", "fingerprint": "eadf6054c953f759", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4de8650da7860520", "level": "error", "message": {"text": "Dangling fetch: GET /api/me/compose-prefs (public/inbox.js:2748)"}, "properties": {"repobilityId": "d4db08ac4378fb21", "scanner": "scanner-primary", "fingerprint": "4de8650da7860520", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5be75a2c2c191250", "level": "note", "message": {"text": "Unused endpoint: USE /webhooks/stripe"}, "properties": {"repobilityId": "ea5ffd986bd1ea83", "scanner": "scanner-primary", "fingerprint": "5be75a2c2c191250", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2e9f0c712241895d", "level": "note", "message": {"text": "Unused endpoint: GET /auth/google"}, "properties": {"repobilityId": "b1d68179f12a8117", "scanner": "scanner-primary", "fingerprint": "2e9f0c712241895d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-392dcbd9c0e4ed85", "level": "note", "message": {"text": "Unused endpoint: GET /auth/google/callback"}, "properties": {"repobilityId": "80b850cd20022d10", "scanner": "scanner-primary", "fingerprint": "392dcbd9c0e4ed85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4ee452467a77fea", "level": "note", "message": {"text": "Unused endpoint: GET /auth/microsoft"}, "properties": {"repobilityId": "9162dbe9584c3cac", "scanner": "scanner-primary", "fingerprint": "b4ee452467a77fea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-239257db12035088", "level": "note", "message": {"text": "Unused endpoint: GET /auth/microsoft/callback"}, "properties": {"repobilityId": "56c3eabf02c377b6", "scanner": "scanner-primary", "fingerprint": "239257db12035088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c059f57186114027", "level": "note", "message": {"text": "Unused endpoint: POST /auth/logout"}, "properties": {"repobilityId": "b10c8daad0c2922a", "scanner": "scanner-primary", "fingerprint": "c059f57186114027", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c702f92b682cca1", "level": "note", "message": {"text": "Unused endpoint: GET /auth/logout"}, "properties": {"repobilityId": "02f69dc7d0da32a9", "scanner": "scanner-primary", "fingerprint": "1c702f92b682cca1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0c2cfd73ef2e3487", "level": "note", "message": {"text": "Unused endpoint: GET /pricing"}, "properties": {"repobilityId": "35c19035aad7406c", "scanner": "scanner-primary", "fingerprint": "0c2cfd73ef2e3487", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9299b6d38b686db7", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/providers"}, "properties": {"repobilityId": "10bfbd0c1c9bf6b4", "scanner": "scanner-primary", "fingerprint": "9299b6d38b686db7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bd5f34ed3a71a3a9", "level": "note", "message": {"text": "Unused endpoint: GET /m/inbox"}, "properties": {"repobilityId": "507f1f39ab99e058", "scanner": "scanner-primary", "fingerprint": "bd5f34ed3a71a3a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9daee89b78e9ceac", "level": "note", "message": {"text": "Unused endpoint: GET /privacy"}, "properties": {"repobilityId": "a5fa38dbc797b050", "scanner": "scanner-primary", "fingerprint": "9daee89b78e9ceac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ebe3481a27b770a5", "level": "note", "message": {"text": "Unused endpoint: GET /terms"}, "properties": {"repobilityId": "0fa4731df48945a3", "scanner": "scanner-primary", "fingerprint": "ebe3481a27b770a5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ccd55bfbd01cf75e", "level": "note", "message": {"text": "Unused endpoint: POST /api/waitlist/provider"}, "properties": {"repobilityId": "c81c5960c040a532", "scanner": "scanner-primary", "fingerprint": "ccd55bfbd01cf75e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e9481944d13e157c", "level": "note", "message": {"text": "Unused endpoint: GET /admin/diag/provider-waitlist"}, "properties": {"repobilityId": "7bb18b510d8ff806", "scanner": "scanner-primary", "fingerprint": "e9481944d13e157c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f55d735a5546f8b5", "level": "note", "message": {"text": "Unused endpoint: GET /admin/diag/stripe-portal-check"}, "properties": {"repobilityId": "0adaadc9b269e295", "scanner": "scanner-primary", "fingerprint": "f55d735a5546f8b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e378d495a47dbd93", "level": "note", "message": {"text": "Unused endpoint: GET /admin/diag/user-activity"}, "properties": {"repobilityId": "e2abbaa84f2631c5", "scanner": "scanner-primary", "fingerprint": "e378d495a47dbd93", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a226e251e045be1c", "level": "note", "message": {"text": "Unused endpoint: GET /admin/cron/reviewer-watch"}, "properties": {"repobilityId": "cfe4506a4dc95ab1", "scanner": "scanner-primary", "fingerprint": "a226e251e045be1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aed5517ca64f55e7", "level": "note", "message": {"text": "Unused endpoint: GET /api/mail/inbox"}, "properties": {"repobilityId": "b48bda52485cae49", "scanner": "scanner-primary", "fingerprint": "aed5517ca64f55e7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e14c9a02ab6ec228", "level": "note", "message": {"text": "Unused endpoint: GET /api/mail/message/:id"}, "properties": {"repobilityId": "6d2f932e4cf6a961", "scanner": "scanner-primary", "fingerprint": "e14c9a02ab6ec228", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0830cd647588f848", "level": "note", "message": {"text": "Unused endpoint: POST /api/mail/send"}, "properties": {"repobilityId": "0bce88fa386f7f16", "scanner": "scanner-primary", "fingerprint": "0830cd647588f848", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1117e48d6a75b60", "level": "note", "message": {"text": "Unused endpoint: GET /api/mail/folders"}, "properties": {"repobilityId": "8a7e95b1ce60d6a4", "scanner": "scanner-primary", "fingerprint": "c1117e48d6a75b60", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2fb8db0f7bf09974", "level": "note", "message": {"text": "Unused endpoint: POST /admin/diag/restore-user"}, "properties": {"repobilityId": "5b38a02aed01eedf", "scanner": "scanner-primary", "fingerprint": "2fb8db0f7bf09974", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab959fb2b3c21d70", "level": "note", "message": {"text": "Unused endpoint: DELETE /admin/diag/delete-user"}, "properties": {"repobilityId": "5b9fcbb9d4ef5297", "scanner": "scanner-primary", "fingerprint": "ab959fb2b3c21d70", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-40d1259764973389", "level": "note", "message": {"text": "Unused endpoint: GET /admin/diag/microsoft-calendar"}, "properties": {"repobilityId": "bf109d8a1ae585a6", "scanner": "scanner-primary", "fingerprint": "40d1259764973389", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7346d450634abe36", "level": "note", "message": {"text": "Unused endpoint: GET /admin/diag/microsoft-inbox"}, "properties": {"repobilityId": "af63887ab44b22b9", "scanner": "scanner-primary", "fingerprint": "7346d450634abe36", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9b883326e67da4e4", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-da49fd123cc95586", "level": "note", "message": {"text": "Unused endpoint: GET /welcome"}, "properties": {"repobilityId": "8dee18b374892dd3", "scanner": "scanner-primary", "fingerprint": "da49fd123cc95586", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-512ccb0fd0b230ba", "level": "note", "message": {"text": "Unused endpoint: GET /settings"}, "properties": {"repobilityId": "dc74b3b47e3f5d95", "scanner": "scanner-primary", "fingerprint": "512ccb0fd0b230ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5f9819d9ecb49931", "level": "note", "message": {"text": "Unused endpoint: GET /calendar"}, "properties": {"repobilityId": "f5a9e5d0a07f93fc", "scanner": "scanner-primary", "fingerprint": "5f9819d9ecb49931", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-edf3354c30f8a8ee", "level": "note", "message": {"text": "Unused endpoint: GET /promises"}, "properties": {"repobilityId": "4c178f2168571333", "scanner": "scanner-primary", "fingerprint": "edf3354c30f8a8ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60561387e4df646a", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/tasks/lists/:id"}, "properties": {"repobilityId": "b28ce3c6f989e6e6", "scanner": "scanner-primary", "fingerprint": "60561387e4df646a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d45a3a0f6438f530", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/tasks/lists/:id"}, "properties": {"repobilityId": "aa08c59646ff3004", "scanner": "scanner-primary", "fingerprint": "d45a3a0f6438f530", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cf16ae0930dc161a", "level": "note", "message": {"text": "Unused endpoint: GET /api/tasks"}, "properties": {"repobilityId": "c073568a26bd90e7", "scanner": "scanner-primary", "fingerprint": "cf16ae0930dc161a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-abcdaab0f31bad94", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/me/language"}, "properties": {"repobilityId": "c1d221404663955b", "scanner": "scanner-primary", "fingerprint": "abcdaab0f31bad94", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c0d6dc0d3c3e353d", "level": "note", "message": {"text": "Unused endpoint: GET /api/me/plan"}, "properties": {"repobilityId": "53b95377f1766045", "scanner": "scanner-primary", "fingerprint": "c0d6dc0d3c3e353d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f65e9a5767cf6b6", "level": "note", "message": {"text": "Unused endpoint: POST /api/billing/checkout"}, "properties": {"repobilityId": "d398145700e93cff", "scanner": "scanner-primary", "fingerprint": "2f65e9a5767cf6b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b866b6b0abeff2e0", "level": "note", "message": {"text": "Unused endpoint: POST /api/billing/change-plan"}, "properties": {"repobilityId": "e14c1a04f27e6ebf", "scanner": "scanner-primary", "fingerprint": "b866b6b0abeff2e0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6583515438ad9de7", "level": "note", "message": {"text": "Unused endpoint: POST /api/billing/portal"}, "properties": {"repobilityId": "d4805819c4f6fd8b", "scanner": "scanner-primary", "fingerprint": "6583515438ad9de7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0b4d98711d639c6", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/stripe-setup"}, "properties": {"repobilityId": "2dba4fe6eb716a1f", "scanner": "scanner-primary", "fingerprint": "e0b4d98711d639c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1dfcc9529630142e", "level": "note", "message": {"text": "Unused endpoint: POST /webhooks/stripe"}, "properties": {"repobilityId": "60eba82d1949a4b9", "scanner": "scanner-primary", "fingerprint": "1dfcc9529630142e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-663f9e690d0dfc3f", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/calendar/events/:id"}, "properties": {"repobilityId": "a205a6676515b73a", "scanner": "scanner-primary", "fingerprint": "663f9e690d0dfc3f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-46f846fd85ff3b05", "level": "note", "message": {"text": "Unused endpoint: POST /api/gmail/push/webhook"}, "properties": {"repobilityId": "260aa0a09d1d40ed", "scanner": "scanner-primary", "fingerprint": "46f846fd85ff3b05", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7592a73e9a4cfdaf", "level": "note", "message": {"text": "Unused endpoint: POST /api/gmail/push/enable"}, "properties": {"repobilityId": "639430543901d0b0", "scanner": "scanner-primary", "fingerprint": "7592a73e9a4cfdaf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4582933a951b9ca3", "level": "note", "message": {"text": "Unused endpoint: POST /api/gmail/push/disable"}, "properties": {"repobilityId": "c40af97573e8568e", "scanner": "scanner-primary", "fingerprint": "4582933a951b9ca3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c2e84e138d384f4", "level": "note", "message": {"text": "Unused endpoint: GET /api/gmail/push/status"}, "properties": {"repobilityId": "30573d86226cdc16", "scanner": "scanner-primary", "fingerprint": "9c2e84e138d384f4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65386a5fee96df6b", "level": "note", "message": {"text": "Unused endpoint: GET /api/decision-rules/rules"}, "properties": {"repobilityId": "98613cefaac2d7d3", "scanner": "scanner-primary", "fingerprint": "65386a5fee96df6b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd85f98241272735", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/decision-rules/rules/:id"}, "properties": {"repobilityId": "18cf7789f71cb249", "scanner": "scanner-primary", "fingerprint": "fd85f98241272735", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-05a2eba4807442ea", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/decision-rules/rules/:id"}, "properties": {"repobilityId": "cc2e105016365789", "scanner": "scanner-primary", "fingerprint": "05a2eba4807442ea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dab284d387ded039", "level": "note", "message": {"text": "Unused endpoint: POST /api/decision-rules/mine"}, "properties": {"repobilityId": "f6e20de2c3763dd9", "scanner": "scanner-primary", "fingerprint": "dab284d387ded039", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c80d15878f8ab78e", "level": "note", "message": {"text": "Unused endpoint: GET /api/commitments"}, "properties": {"repobilityId": "da87af5e8f01bce3", "scanner": "scanner-primary", "fingerprint": "c80d15878f8ab78e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}