{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "WEB003", "name": "Public web service has no security.txt", "shortDescription": {"text": "Public web service has no security.txt"}, "fullDescription": {"text": "security.txt gives researchers and customers a safe disclosure channel. Public web apps and APIs should publish it under /.well-known/security.txt."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "medium", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "WEB015", "name": "Public web app has no Content Security Policy", "shortDescription": {"text": "Public web app has no Content Security Policy"}, "fullDescription": {"text": "A Content Security Policy reduces the blast radius of injected scripts if the app is ever served through preview, static hosting, or a web container outside its normal sandbox."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "AUC001", "name": "[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks but does not define .repobilit", "shortDescription": {"text": "[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks but does not define .repobility/access.yml or equivalent authorization documentation."}, "fullDescription": {"text": "The repository uses web/API frameworks but does not define .repobility/access.yml or equivalent authorization documentation."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "medium", "confidence": 0.92, "cwe": "CWE-285", "owasp": "WSTG-AUTHZ"}}, {"id": "GHSA-58qx-3vcg-4xpx", "name": "ws: GHSA-58qx-3vcg-4xpx", "shortDescription": {"text": "ws: GHSA-58qx-3vcg-4xpx"}, "fullDescription": {"text": "ws: Uninitialized memory disclosure"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vmf3-w455-68vh", "name": "tar: GHSA-vmf3-w455-68vh", "shortDescription": {"text": "tar: GHSA-vmf3-w455-68vh"}, "fullDescription": {"text": "node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q8mj-m7cp-5q26", "name": "qs: GHSA-q8mj-m7cp-5q26", "shortDescription": {"text": "qs: GHSA-q8mj-m7cp-5q26"}, "fullDescription": {"text": "qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6rw7-vpxm-498p", "name": "qs: GHSA-6rw7-vpxm-498p", "shortDescription": {"text": "qs: GHSA-6rw7-vpxm-498p"}, "fullDescription": {"text": "qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qx2v-qp2m-jg93", "name": "postcss: GHSA-qx2v-qp2m-jg93", "shortDescription": {"text": "postcss: GHSA-qx2v-qp2m-jg93"}, "fullDescription": {"text": "PostCSS has XSS via Unescaped </style> in its CSS Stringify Output"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3v7f-55p6-f55p", "name": "picomatch: GHSA-3v7f-55p6-f55p", "shortDescription": {"text": "picomatch: GHSA-3v7f-55p6-f55p"}, "fullDescription": {"text": "Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-27v5-c462-wpq7", "name": "path-to-regexp: GHSA-27v5-c462-wpq7", "shortDescription": {"text": "path-to-regexp: GHSA-27v5-c462-wpq7"}, "fullDescription": {"text": "path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8f24-v5vv-gm5j", "name": "next-intl: GHSA-8f24-v5vv-gm5j", "shortDescription": {"text": "next-intl: GHSA-8f24-v5vv-gm5j"}, "fullDescription": {"text": "next-intl has an open redirect vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4c35-wcg5-mm9h", "name": "next-intl: GHSA-4c35-wcg5-mm9h", "shortDescription": {"text": "next-intl: GHSA-4c35-wcg5-mm9h"}, "fullDescription": {"text": "next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-h67p-54hq-rp68", "name": "js-yaml: GHSA-h67p-54hq-rp68", "shortDescription": {"text": "js-yaml: GHSA-h67p-54hq-rp68"}, "fullDescription": {"text": "JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-xrhx-7g5j-rcj5", "name": "hono: GHSA-xrhx-7g5j-rcj5", "shortDescription": {"text": "hono: GHSA-xrhx-7g5j-rcj5"}, "fullDescription": {"text": "Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-xpcf-pg52-r92g", "name": "hono: GHSA-xpcf-pg52-r92g", "shortDescription": {"text": "hono: GHSA-xpcf-pg52-r92g"}, "fullDescription": {"text": "Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-xf4j-xp2r-rqqx", "name": "hono: GHSA-xf4j-xp2r-rqqx", "shortDescription": {"text": "hono: GHSA-xf4j-xp2r-rqqx"}, "fullDescription": {"text": "Hono: Path traversal in toSSG() allows writing files outside the output directory"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-wmmm-f939-6g9c", "name": "hono: GHSA-wmmm-f939-6g9c", "shortDescription": {"text": "hono: GHSA-wmmm-f939-6g9c"}, "fullDescription": {"text": "Hono: Middleware bypass via repeated slashes in serveStatic"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-w332-q679-j88p", "name": "hono: GHSA-w332-q679-j88p", "shortDescription": {"text": "hono: GHSA-w332-q679-j88p"}, "fullDescription": {"text": "Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-v8w9-8mx6-g223", "name": "hono: GHSA-v8w9-8mx6-g223", "shortDescription": {"text": "hono: GHSA-v8w9-8mx6-g223"}, "fullDescription": {"text": "Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r5rp-j6wh-rvv4", "name": "hono: GHSA-r5rp-j6wh-rvv4", "shortDescription": {"text": "hono: GHSA-r5rp-j6wh-rvv4"}, "fullDescription": {"text": "Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r354-f388-2fhh", "name": "hono: GHSA-r354-f388-2fhh", "shortDescription": {"text": "hono: GHSA-r354-f388-2fhh"}, "fullDescription": {"text": "Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qp7p-654g-cw7p", "name": "hono: GHSA-qp7p-654g-cw7p", "shortDescription": {"text": "hono: GHSA-qp7p-654g-cw7p"}, "fullDescription": {"text": "Hono has CSS Declaration Injection via Style Object Values in JSX SSR"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-p77w-8qqv-26rm", "name": "hono: GHSA-p77w-8qqv-26rm", "shortDescription": {"text": "hono: GHSA-p77w-8qqv-26rm"}, "fullDescription": {"text": "Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-p6xx-57qc-3wxr", "name": "hono: GHSA-p6xx-57qc-3wxr", "shortDescription": {"text": "hono: GHSA-p6xx-57qc-3wxr"}, "fullDescription": {"text": "Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f577-qrjj-4474", "name": "hono: GHSA-f577-qrjj-4474", "shortDescription": {"text": "hono: GHSA-f577-qrjj-4474"}, "fullDescription": {"text": "Hono: JWT middleware accepts any Authorization scheme, not only Bearer"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9vqf-7f2p-gf9v", "name": "hono: GHSA-9vqf-7f2p-gf9v", "shortDescription": {"text": "hono: GHSA-9vqf-7f2p-gf9v"}, "fullDescription": {"text": "Hono: bodyLimit() can be bypassed for chunked / unknown-length requests"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9r54-q6cx-xmh5", "name": "hono: GHSA-9r54-q6cx-xmh5", "shortDescription": {"text": "hono: GHSA-9r54-q6cx-xmh5"}, "fullDescription": {"text": "Hono vulnerable to XSS through ErrorBoundary component "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-6wqw-2p9w-4vw4", "name": "hono: GHSA-6wqw-2p9w-4vw4", "shortDescription": {"text": "hono: GHSA-6wqw-2p9w-4vw4"}, "fullDescription": {"text": "Hono cache middleware ignores \"Cache-Control: private\" leading to Web Cache Deception"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-69xw-7hcm-h432", "name": "hono: GHSA-69xw-7hcm-h432", "shortDescription": {"text": "hono: GHSA-69xw-7hcm-h432"}, "fullDescription": {"text": "hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5pq2-9x2x-5p6w", "name": "hono: GHSA-5pq2-9x2x-5p6w", "shortDescription": {"text": "hono: GHSA-5pq2-9x2x-5p6w"}, "fullDescription": {"text": "Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-458j-xx4x-4375", "name": "hono: GHSA-458j-xx4x-4375", "shortDescription": {"text": "hono: GHSA-458j-xx4x-4375"}, "fullDescription": {"text": "hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3hrh-pfw6-9m5x", "name": "hono: GHSA-3hrh-pfw6-9m5x", "shortDescription": {"text": "hono: GHSA-3hrh-pfw6-9m5x"}, "fullDescription": {"text": "Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-2gcr-mfcq-wcc3", "name": "hono: GHSA-2gcr-mfcq-wcc3", "shortDescription": {"text": "hono: GHSA-2gcr-mfcq-wcc3"}, "fullDescription": {"text": "Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-26pp-8wgv-hjvm", "name": "hono: GHSA-26pp-8wgv-hjvm", "shortDescription": {"text": "hono: GHSA-26pp-8wgv-hjvm"}, "fullDescription": {"text": "Hono missing validation of cookie name on write path in setCookie()"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jxxr-4gwj-5jf2", "name": "brace-expansion: GHSA-jxxr-4gwj-5jf2", "shortDescription": {"text": "brace-expansion: GHSA-jxxr-4gwj-5jf2"}, "fullDescription": {"text": "brace-expansion: Large numeric range defeats documented `max` DoS protection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-2g4f-4pwh-qvx6", "name": "ajv: GHSA-2g4f-4pwh-qvx6", "shortDescription": {"text": "ajv: GHSA-2g4f-4pwh-qvx6"}, "fullDescription": {"text": "ajv has ReDoS when using `$data` option"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8988-4f7v-96qf", "name": "@opentelemetry/core: GHSA-8988-4f7v-96qf", "shortDescription": {"text": "@opentelemetry/core: GHSA-8988-4f7v-96qf"}, "fullDescription": {"text": "OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-92pp-h63x-v22m", "name": "@hono/node-server: GHSA-92pp-h63x-v22m", "shortDescription": {"text": "@hono/node-server: GHSA-92pp-h63x-v22m"}, "fullDescription": {"text": "@hono/node-server: Middleware bypass via repeated slashes in serveStatic"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-wfc6-r584-vfw7", "name": "next: GHSA-wfc6-r584-vfw7", "shortDescription": {"text": "next: GHSA-wfc6-r584-vfw7"}, "fullDescription": {"text": "Next.js vulnerable to cache poisoning in React Server Component responses"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mq59-m269-xvcx", "name": "next: GHSA-mq59-m269-xvcx", "shortDescription": {"text": "next: GHSA-mq59-m269-xvcx"}, "fullDescription": {"text": "Next.js: null origin can bypass Server Actions CSRF checks"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-h64f-5h5j-jqjh", "name": "next: GHSA-h64f-5h5j-jqjh", "shortDescription": {"text": "next: GHSA-h64f-5h5j-jqjh"}, "fullDescription": {"text": "Next.js has a Denial of Service in the Image Optimization API"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-h27x-g6w4-24gq", "name": "next: GHSA-h27x-g6w4-24gq", "shortDescription": {"text": "next: GHSA-h27x-g6w4-24gq"}, "fullDescription": {"text": "Next.js: Unbounded postponed resume buffering can lead to DoS"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gx5p-jg67-6x7h", "name": "next: GHSA-gx5p-jg67-6x7h", "shortDescription": {"text": "next: GHSA-gx5p-jg67-6x7h"}, "fullDescription": {"text": "Next.js has cross-site scripting in beforeInteractive scripts with untrusted input"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-ggv3-7p47-pfv8", "name": "next: GHSA-ggv3-7p47-pfv8", "shortDescription": {"text": "next: GHSA-ggv3-7p47-pfv8"}, "fullDescription": {"text": "Next.js: HTTP request smuggling in rewrites"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-ffhc-5mcf-pf4q", "name": "next: GHSA-ffhc-5mcf-pf4q", "shortDescription": {"text": "next: GHSA-ffhc-5mcf-pf4q"}, "fullDescription": {"text": "Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9g9p-9gw9-jx7f", "name": "next: GHSA-9g9p-9gw9-jx7f", "shortDescription": {"text": "next: GHSA-9g9p-9gw9-jx7f"}, "fullDescription": {"text": "Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-5f7q-jpqc-wp7h", "name": "next: GHSA-5f7q-jpqc-wp7h", "shortDescription": {"text": "next: GHSA-5f7q-jpqc-wp7h"}, "fullDescription": {"text": "Next.js has Unbounded Memory Consumption via PPR Resume Endpoint "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3x4c-7xq6-9pq8", "name": "next: GHSA-3x4c-7xq6-9pq8", "shortDescription": {"text": "next: GHSA-3x4c-7xq6-9pq8"}, "fullDescription": {"text": "Next.js: Unbounded next/image disk cache growth can exhaust storage"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "medium", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "DEPCUR-NPM", "name": "npm package `lint-staged` is 1 major version(s) behind (^16.4.0 -> 17.0.7)", "shortDescription": {"text": "npm package `lint-staged` is 1 major version(s) behind (^16.4.0 -> 17.0.7)"}, "fullDescription": {"text": "`lint-staged` is pinned/resolved at ^16.4.0 but the latest stable release on the npm registry is 17.0.7 (1 major version(s) behind). Outdated dependencies accumulate unpatched bugs and make future security upgrades harder. This is the version-currency signal Dependabot version-update PRs raise."}, "properties": {"scanner": "repobility-dependency-currency", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "MINED115", "name": "Action `supabase/setup-cli` pinned to mutable ref `@v2`", "shortDescription": {"text": "Action `supabase/setup-cli` pinned to mutable ref `@v2`"}, "fullDescription": {"text": "`uses: supabase/setup-cli@v2` resolves at workflow-run time. Tags and branches can be re-pushed by the action owner; that made the tj-actions/changed-files compromise (2025) instantly affect many repos. Treat official first-party action tags as lower risk, but pin security-sensitive third-party actions to a 40-char commit SHA + lock with Dependabot or renovate."}, "properties": {"scanner": "repobility-supply-chain", "category": "dependency", "severity": "medium", "confidence": 0.9, "cwe": "", "owasp": ""}}, {"id": "WEB011", "name": "Public web app has no humans.txt", "shortDescription": {"text": "Public web app has no humans.txt"}, "fullDescription": {"text": "humans.txt is optional, but it gives operators and reviewers a simple place to find ownership, contact, and important public documentation links."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.5, "cwe": "", "owasp": ""}}, {"id": "WEB008", "name": "Public docs site has no llms.txt", "shortDescription": {"text": "Public docs site has no llms.txt"}, "fullDescription": {"text": "AI coding agents increasingly read llms.txt to find canonical docs and API workflows. Without it, agents are more likely to browse pages repeatedly or use stale instructions."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.64, "cwe": "", "owasp": ""}}, {"id": "WEB002", "name": "Public web app has no sitemap", "shortDescription": {"text": "Public web app has no sitemap"}, "fullDescription": {"text": "A sitemap gives search engines, docs crawlers, and AI agents a structured list of public pages. Without one, important docs and product pages are easy to miss."}, "properties": {"scanner": "repobility-web-presence", "category": "quality", "severity": "low", "confidence": 0.72, "cwe": "", "owasp": ""}}, {"id": "AUC005", "name": "[AUC005] No authorization-focused tests detected: No test files with common authorization, ownership, 403, admin, or sup", "shortDescription": {"text": "[AUC005] No authorization-focused tests detected: No test files with common authorization, ownership, 403, admin, or super_admin assertions were found."}, "fullDescription": {"text": "No test files with common authorization, ownership, 403, admin, or super_admin assertions were found."}, "properties": {"scanner": "repobility-access-control", "category": "auth", "severity": "low", "confidence": 0.76, "cwe": "CWE-285", "owasp": "WSTG-AUTHZ"}}, {"id": "GHSA-w7fw-mjwx-w883", "name": "qs: GHSA-w7fw-mjwx-w883", "shortDescription": {"text": "qs: GHSA-w7fw-mjwx-w883"}, "fullDescription": {"text": "qs's arrayLimit bypass in comma parsing allows denial of service"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-hm8q-7f3q-5f36", "name": "hono: GHSA-hm8q-7f3q-5f36", "shortDescription": {"text": "hono: GHSA-hm8q-7f3q-5f36"}, "fullDescription": {"text": "Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-gq3j-xvxp-8hrf", "name": "hono: GHSA-gq3j-xvxp-8hrf", "shortDescription": {"text": "hono: GHSA-gq3j-xvxp-8hrf"}, "fullDescription": {"text": "Hono added timing comparison hardening in basicAuth and bearerAuth"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-73rr-hh4g-fpgx", "name": "diff: GHSA-73rr-hh4g-fpgx", "shortDescription": {"text": "diff: GHSA-73rr-hh4g-fpgx"}, "fullDescription": {"text": "jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-4x5r-pxfx-6jf8", "name": "@babel/core: GHSA-4x5r-pxfx-6jf8", "shortDescription": {"text": "@babel/core: GHSA-4x5r-pxfx-6jf8"}, "fullDescription": {"text": "@babel/core: Arbitrary File Read via sourceMappingURL Comment"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-vfv6-92ff-j949", "name": "next: GHSA-vfv6-92ff-j949", "shortDescription": {"text": "next: GHSA-vfv6-92ff-j949"}, "fullDescription": {"text": "Next.js vulnerable to cache poisoning via collisions in React Server Component cache-busting"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-jcc7-9wpm-mj36", "name": "next: GHSA-jcc7-9wpm-mj36", "shortDescription": {"text": "next: GHSA-jcc7-9wpm-mj36"}, "fullDescription": {"text": "Next.js: null origin can bypass dev HMR websocket CSRF checks"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3g8h-86w9-wvmq", "name": "next: GHSA-3g8h-86w9-wvmq", "shortDescription": {"text": "next: GHSA-3g8h-86w9-wvmq"}, "fullDescription": {"text": "Next.js's Middleware / Proxy redirects can be cache-poisoned"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "low", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "AIC003", "name": "Duplicated implementation block across source files", "shortDescription": {"text": "Duplicated implementation block across source files"}, "fullDescription": {"text": "Duplicated blocks are a common artifact when generated code is pasted or recreated instead of reused. They increase maintenance cost because every future bug fix must be found in multiple locations."}, "properties": {"scanner": "repobility-ai-code-hygiene", "category": "quality", "severity": "low", "confidence": 0.86, "cwe": "", "owasp": ""}}, {"id": "CORE_NO_LICENSE", "name": "No LICENSE file", "shortDescription": {"text": "No LICENSE file"}, "fullDescription": {"text": "Add a LICENSE file to your repository. Use choosealicense.com to pick the right license (MIT for permissive, Apache 2.0 for patent protection, GPL for copyleft)."}, "properties": {"scanner": "repobility-core", "category": "documentation", "severity": "low", "confidence": null, "cwe": "", "owasp": ""}}, {"id": "MINED058", "name": "[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escaping. Pair with DOMPurify or neve", "shortDescription": {"text": "[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escaping. Pair with DOMPurify or never use with user data."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-79 / A03:2021 for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED056", "name": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order.", "shortDescription": {"text": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-682 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "MINED044", "name": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed.", "shortDescription": {"text": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed."}, "fullDescription": {"text": "Review and fix per the pattern semantics. See CWE-532 /  for context."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "info", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "GHSA-96hv-2xvq-fx4p", "name": "ws: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "ws: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "ws: Memory exhaustion DoS from tiny fragments and data chunks"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-r6q2-hw4h-h46w", "name": "tar: GHSA-r6q2-hw4h-h46w", "shortDescription": {"text": "tar: GHSA-r6q2-hw4h-h46w"}, "fullDescription": {"text": "Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-qffp-2rhf-9h96", "name": "tar: GHSA-qffp-2rhf-9h96", "shortDescription": {"text": "tar: GHSA-qffp-2rhf-9h96"}, "fullDescription": {"text": "tar has Hardlink Path Traversal via Drive-Relative Linkpath"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-9ppj-qmqm-q256", "name": "tar: GHSA-9ppj-qmqm-q256", "shortDescription": {"text": "tar: GHSA-9ppj-qmqm-q256"}, "fullDescription": {"text": "node-tar Symlink Path Traversal via Drive-Relative Linkpath"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8qq5-rm4j-mr97", "name": "tar: GHSA-8qq5-rm4j-mr97", "shortDescription": {"text": "tar: GHSA-8qq5-rm4j-mr97"}, "fullDescription": {"text": "node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-83g3-92jg-28cx", "name": "tar: GHSA-83g3-92jg-28cx", "shortDescription": {"text": "tar: GHSA-83g3-92jg-28cx"}, "fullDescription": {"text": "Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-34x7-hfp2-rc4v", "name": "tar: GHSA-34x7-hfp2-rc4v", "shortDescription": {"text": "tar: GHSA-34x7-hfp2-rc4v"}, "fullDescription": {"text": "node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-c2c7-rcm5-vvqj", "name": "picomatch: GHSA-c2c7-rcm5-vvqj", "shortDescription": {"text": "picomatch: GHSA-c2c7-rcm5-vvqj"}, "fullDescription": {"text": "Picomatch has a ReDoS vulnerability via extglob quantifiers"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-j3q9-mxjg-w52f", "name": "path-to-regexp: GHSA-j3q9-mxjg-w52f", "shortDescription": {"text": "path-to-regexp: GHSA-j3q9-mxjg-w52f"}, "fullDescription": {"text": "path-to-regexp vulnerable to Denial of Service via sequential optional groups"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7r86-cg39-jmmj", "name": "minimatch: GHSA-7r86-cg39-jmmj", "shortDescription": {"text": "minimatch: GHSA-7r86-cg39-jmmj"}, "fullDescription": {"text": "minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3ppc-4f35-3m26", "name": "minimatch: GHSA-3ppc-4f35-3m26", "shortDescription": {"text": "minimatch: GHSA-3ppc-4f35-3m26"}, "fullDescription": {"text": "minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-23c5-xmqv-rm74", "name": "minimatch: GHSA-23c5-xmqv-rm74", "shortDescription": {"text": "minimatch: GHSA-23c5-xmqv-rm74"}, "fullDescription": {"text": "minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q5qw-h33p-qvwr", "name": "hono: GHSA-q5qw-h33p-qvwr", "shortDescription": {"text": "hono: GHSA-q5qw-h33p-qvwr"}, "fullDescription": {"text": "Hono vulnerable to arbitrary file access via serveStatic vulnerability "}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-f67f-6cw9-8mq4", "name": "hono: GHSA-f67f-6cw9-8mq4", "shortDescription": {"text": "hono: GHSA-f67f-6cw9-8mq4"}, "fullDescription": {"text": "Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-3vhc-576x-3qv4", "name": "hono: GHSA-3vhc-576x-3qv4", "shortDescription": {"text": "hono: GHSA-3vhc-576x-3qv4"}, "fullDescription": {"text": "Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks \"alg\" (untrusted header.alg fallback)"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-v39h-62p7-jpjc", "name": "fast-uri: GHSA-v39h-62p7-jpjc", "shortDescription": {"text": "fast-uri: GHSA-v39h-62p7-jpjc"}, "fullDescription": {"text": "fast-uri vulnerable to host confusion via percent-encoded authority delimiters"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q3j6-qgpj-74h6", "name": "fast-uri: GHSA-q3j6-qgpj-74h6", "shortDescription": {"text": "fast-uri: GHSA-q3j6-qgpj-74h6"}, "fullDescription": {"text": "fast-uri vulnerable to path traversal via percent-encoded dot segments"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8r9q-7v3j-jr4g", "name": "@modelcontextprotocol/sdk: GHSA-8r9q-7v3j-jr4g", "shortDescription": {"text": "@modelcontextprotocol/sdk: GHSA-8r9q-7v3j-jr4g"}, "fullDescription": {"text": "Anthropic's MCP TypeScript SDK has a ReDoS vulnerability"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-345p-7cg4-v4c7", "name": "@modelcontextprotocol/sdk: GHSA-345p-7cg4-v4c7", "shortDescription": {"text": "@modelcontextprotocol/sdk: GHSA-345p-7cg4-v4c7"}, "fullDescription": {"text": "@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-7h2j-956f-4vf2", "name": "@isaacs/brace-expansion: GHSA-7h2j-956f-4vf2", "shortDescription": {"text": "@isaacs/brace-expansion: GHSA-7h2j-956f-4vf2"}, "fullDescription": {"text": "@isaacs/brace-expansion has Uncontrolled Resource Consumption"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-wc8c-qw6v-h7f6", "name": "@hono/node-server: GHSA-wc8c-qw6v-h7f6", "shortDescription": {"text": "@hono/node-server: GHSA-wc8c-qw6v-h7f6"}, "fullDescription": {"text": "@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-q4gf-8mx6-v5v3", "name": "next: GHSA-q4gf-8mx6-v5v3", "shortDescription": {"text": "next: GHSA-q4gf-8mx6-v5v3"}, "fullDescription": {"text": "Next.js has a Denial of Service with Server Components"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-mg66-mrh9-m8jx", "name": "next: GHSA-mg66-mrh9-m8jx", "shortDescription": {"text": "next: GHSA-mg66-mrh9-m8jx"}, "fullDescription": {"text": "Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-h25m-26qc-wcjf", "name": "next: GHSA-h25m-26qc-wcjf", "shortDescription": {"text": "next: GHSA-h25m-26qc-wcjf"}, "fullDescription": {"text": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-c4j6-fc7j-m34r", "name": "next: GHSA-c4j6-fc7j-m34r", "shortDescription": {"text": "next: GHSA-c4j6-fc7j-m34r"}, "fullDescription": {"text": "Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-8h8q-6873-q5fj", "name": "next: GHSA-8h8q-6873-q5fj", "shortDescription": {"text": "next: GHSA-8h8q-6873-q5fj"}, "fullDescription": {"text": "Next.js Vulnerable to Denial of Service with Server Components"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-492v-c6pp-mqqv", "name": "next: GHSA-492v-c6pp-mqqv", "shortDescription": {"text": "next: GHSA-492v-c6pp-mqqv"}, "fullDescription": {"text": "Next.js has a Middleware / Proxy bypass through dynamic route parameter injection"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-36qx-fr4f-26g5", "name": "next: GHSA-36qx-fr4f-26g5", "shortDescription": {"text": "next: GHSA-36qx-fr4f-26g5"}, "fullDescription": {"text": "Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-26hh-7cqf-hhc6", "name": "next: GHSA-26hh-7cqf-hhc6", "shortDescription": {"text": "next: GHSA-26hh-7cqf-hhc6"}, "fullDescription": {"text": "Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "GHSA-267c-6grr-h53f", "name": "next: GHSA-267c-6grr-h53f", "shortDescription": {"text": "next: GHSA-267c-6grr-h53f"}, "fullDescription": {"text": "Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes"}, "properties": {"scanner": "osv-scanner", "category": "dependency", "severity": "high", "confidence": 0.88, "cwe": "", "owasp": ""}}, {"id": "SEC029", "name": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input: Outbound HTTP request to a user-controlled ", "shortDescription": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input: Outbound HTTP request to a user-controlled URL without allowlist validation. Attackers can probe internal services (169.254.169.254 metadata, internal Kubernetes e"}, "fullDescription": {"text": "Validate the URL against an allowlist BEFORE fetching:\n  ALLOWED = {'images.example.com', 'cdn.example.com'}\n  host = urlparse(url).hostname\n  if host not in ALLOWED: abort(400)\nOr use a server-side proxy (Imgproxy / serve-files-only-from-S3) that isolates outbound network access from the request handler.\nBlock private CIDRs explicitly: 10/8, 172.16/12, 192.168/16, 169.254/16."}, "properties": {"scanner": "repobility-threat-engine", "category": "ssrf", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "SEC128", "name": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns", "shortDescription": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, ra"}, "fullDescription": {"text": "Add `await` before each async call, or chain with `.then`. If you intentionally want fire-and-forget, prefix with `void` (TS) or assign to `_` (Python with `asyncio.create_task`) to make the intent explicit and survive lint."}, "properties": {"scanner": "repobility-threat-engine", "category": "quality", "severity": "high", "confidence": 1.0, "cwe": "", "owasp": ""}}, {"id": "scanner-ed87f19c8d35a1de", "name": "TODO/FIXME marker in shipping code \u2014 app/(app)/flames/page.tsx:14", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 app/(app)/flames/page.tsx:14"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bcb83a2db0d1a6bf", "name": "TODO/FIXME marker in shipping code \u2014 app/(app)/flames/schedule/components/DayRow.tsx:122", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 app/(app)/flames/schedule/components/DayRow.tsx:122"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ebbbefa71e8807ee", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(app)/flames/manage/components/ManageFlamesList.tsx:184", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(app)/flames/manage/components/ManageFlamesList.tsx:184"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c2d48f23299b005c", "name": "`truncate` class without `title=` for hover reveal \u2014 app/(app)/components/ProfileBadge.tsx:209", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(app)/components/ProfileBadge.tsx:209"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e0752433d3e01f58", "name": "TODO/FIXME marker in shipping code \u2014 app/(auth)/actions.ts:15", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 app/(auth)/actions.ts:15"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-41fe6d19b1080c38", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 app/(marketing)/page.tsx:48", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/(marketing)/page.tsx:48"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3d4230927f34c65", "name": "Insecure pattern 'dangerous_innerhtml' in app/(marketing)/page.tsx:48", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in app/(marketing)/page.tsx:48"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f8cdfffd70600cb1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "supabase/setup-cli@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b29822c26e17a384", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "supabase/setup-cli@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-653563205380dba5", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "supabase/setup-cli@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb639d9a10a47b23", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "6 test file(s) for 157 source file(s) (ratio 0.04). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 21 placeholder/mock markers across 11 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc55229a7a3c078d", "name": "Agent authority lacks a verifier contract: .mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bea357a6497a2d5d", "name": "Agent authority lacks a verifier contract: CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba682c95f80fa405", "name": "Agent authority lacks a verifier contract: .claude/agents/playwright-test-generator.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/agents/playwright-test-generator.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd114fe20b67675d", "name": "Commented-code block (6 lines) in app/(app)/flames/components/CompletionSummaryModal.tsx:309", "shortDescription": {"text": "Commented-code block (6 lines) in app/(app)/flames/components/CompletionSummaryModal.tsx:309"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b783fa009ddbc192", "name": "Commented-code block (5 lines) in lib/supabase/proxy.ts:37", "shortDescription": {"text": "Commented-code block (5 lines) in lib/supabase/proxy.ts:37"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23761"}, "properties": {"repository": "0Calories/hibana", "repoUrl": "https://github.com/0Calories/hibana", "branch": "master"}, "results": [{"ruleId": "WEB003", "level": "warning", "message": {"text": "Public web service has no security.txt"}, "properties": {"repobilityId": 223592, "scanner": "repobility-web-presence", "fingerprint": "5cd26606c5a53c9f403ff7a92a6917c19cf440a23ce03e2b90e8c493312ef8cd", "category": "quality", "severity": "medium", "confidence": 0.78, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Repository looks like a public web app/API but no security.txt file or route was discovered.", "evidence": {"rule_id": "WEB003", "scanner": "repobility-web-presence", "references": ["https://www.rfc-editor.org/rfc/rfc9116", "https://github.com/Lissy93/web-check"], "correlation_key": "fp|5cd26606c5a53c9f403ff7a92a6917c19cf440a23ce03e2b90e8c493312ef8cd"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".well-known/security.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB015", "level": "warning", "message": {"text": "Public web app has no Content Security Policy"}, "properties": {"repobilityId": 223591, "scanner": "repobility-web-presence", "fingerprint": "7eb70cae3ff63d8ed7c31706185d32b37655333b40b58ca826d740b08fb1ad63", "category": "quality", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Repository looks like a public web app but no CSP header, framework header config, Helmet policy, or CSP meta tag was discovered.", "evidence": {"rule_id": "WEB015", "scanner": "repobility-web-presence", "references": ["https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP", "https://github.com/Lissy93/web-check"], "correlation_key": "fp|7eb70cae3ff63d8ed7c31706185d32b37655333b40b58ca826d740b08fb1ad63"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "index.html"}, "region": {"startLine": 1}}}]}, {"ruleId": "AUC001", "level": "warning", "message": {"text": "[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks but does not define .repobility/access.yml or equivalent authorization documentation."}, "properties": {"repobilityId": 223586, "scanner": "repobility-access-control", "fingerprint": "f1305052c3ba1e6c1cdb5dccc19e58a8168cf78b176658f32b1fc823df3e9d10", "category": "auth", "severity": "medium", "confidence": 0.92, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"scanner": "repobility-access-control", "frameworks": ["Next.js"], "expected_files": [".repobility/access.yml", ".repobility/access.yaml", ".repobility/access.json", ".repobility/authorization.yml"], "correlation_key": "fp|f1305052c3ba1e6c1cdb5dccc19e58a8168cf78b176658f32b1fc823df3e9d10"}}}, {"ruleId": "GHSA-58qx-3vcg-4xpx", "level": "warning", "message": {"text": "ws: GHSA-58qx-3vcg-4xpx"}, "properties": {"repobilityId": 223584, "scanner": "osv-scanner", "fingerprint": "d698c0969dae25e950d4f8b65b021df28bdeb91476dcc255cdcc9ca9ba3ee73e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-45736"], "package": "ws", "rule_id": "GHSA-58qx-3vcg-4xpx", "scanner": "osv-scanner", "correlation_key": "vuln|ws|CVE-2026-45736|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vmf3-w455-68vh", "level": "warning", "message": {"text": "tar: GHSA-vmf3-w455-68vh"}, "properties": {"repobilityId": 223583, "scanner": "osv-scanner", "fingerprint": "dc740d962ef200999a9a1d6fa83b02cf9577767fc52d92f1ed73db0793c77090", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-53655"], "package": "tar", "rule_id": "GHSA-vmf3-w455-68vh", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-53655|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q8mj-m7cp-5q26", "level": "warning", "message": {"text": "qs: GHSA-q8mj-m7cp-5q26"}, "properties": {"repobilityId": 223549, "scanner": "osv-scanner", "fingerprint": "0727364e57c088dabd2840fd21980edb99b147969b7db2965e7188703dcea5f1", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-8723"], "package": "qs", "rule_id": "GHSA-q8mj-m7cp-5q26", "scanner": "osv-scanner", "correlation_key": "vuln|qs|CVE-2026-8723|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6rw7-vpxm-498p", "level": "warning", "message": {"text": "qs: GHSA-6rw7-vpxm-498p"}, "properties": {"repobilityId": 223547, "scanner": "osv-scanner", "fingerprint": "6d22fb6d155cd92273923764c4a42ac64c943a3e96e9afc41e845a7b5d2f24b9", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-15284"], "package": "qs", "rule_id": "GHSA-6rw7-vpxm-498p", "scanner": "osv-scanner", "correlation_key": "vuln|qs|CVE-2025-15284|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qx2v-qp2m-jg93", "level": "warning", "message": {"text": "postcss: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": 223545, "scanner": "osv-scanner", "fingerprint": "0b1dff5c952a767b7990e67b0d60cc580116a9b63b14cf0d44b920a59028efbf", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41305"], "package": "postcss", "rule_id": "GHSA-qx2v-qp2m-jg93", "scanner": "osv-scanner", "correlation_key": "vuln|postcss|CVE-2026-41305|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3v7f-55p6-f55p", "level": "warning", "message": {"text": "picomatch: GHSA-3v7f-55p6-f55p"}, "properties": {"repobilityId": 223542, "scanner": "osv-scanner", "fingerprint": "d9d26d972991fffb51a1613b08ac1e8e722be1c10191fb43cced54b770250e8d", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33672"], "package": "picomatch", "rule_id": "GHSA-3v7f-55p6-f55p", "scanner": "osv-scanner", "correlation_key": "vuln|picomatch|CVE-2026-33672|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-27v5-c462-wpq7", "level": "warning", "message": {"text": "path-to-regexp: GHSA-27v5-c462-wpq7"}, "properties": {"repobilityId": 223539, "scanner": "osv-scanner", "fingerprint": "5cf58924872fce28303cdda7647e6a181c0b46d2ba36332c6b52fa7cbbbf3169", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-4923"], "package": "path-to-regexp", "rule_id": "GHSA-27v5-c462-wpq7", "scanner": "osv-scanner", "correlation_key": "vuln|path-to-regexp|CVE-2026-4923|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8f24-v5vv-gm5j", "level": "warning", "message": {"text": "next-intl: GHSA-8f24-v5vv-gm5j"}, "properties": {"repobilityId": 223534, "scanner": "osv-scanner", "fingerprint": "8a11ca8284aadf2ac0eebef3db378d5087cd3296af99d795b282ad1f20a6fcfc", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-40299"], "package": "next-intl", "rule_id": "GHSA-8f24-v5vv-gm5j", "scanner": "osv-scanner", "correlation_key": "vuln|next-intl|CVE-2026-40299|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4c35-wcg5-mm9h", "level": "warning", "message": {"text": "next-intl: GHSA-4c35-wcg5-mm9h"}, "properties": {"repobilityId": 223533, "scanner": "osv-scanner", "fingerprint": "3e1b34af8ab7b68a3e241b0bc274e86b1c822f39e2076dbe9f32cc4a3d1aa59a", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "next-intl", "rule_id": "GHSA-4c35-wcg5-mm9h", "scanner": "osv-scanner", "correlation_key": "vuln|next-intl|GHSA-4C35-WCG5-MM9H|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-h67p-54hq-rp68", "level": "warning", "message": {"text": "js-yaml: GHSA-h67p-54hq-rp68"}, "properties": {"repobilityId": 223529, "scanner": "osv-scanner", "fingerprint": "63f0ea25c68b9a69ea942144a267e08da7bba509f52d9409c45e86f70e8b7d57", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-53550"], "package": "js-yaml", "rule_id": "GHSA-h67p-54hq-rp68", "scanner": "osv-scanner", "correlation_key": "vuln|js-yaml|CVE-2026-53550|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-xrhx-7g5j-rcj5", "level": "warning", "message": {"text": "hono: GHSA-xrhx-7g5j-rcj5"}, "properties": {"repobilityId": 223528, "scanner": "osv-scanner", "fingerprint": "00bc496edb613ec402ac6d8d8cfe96cc08bcc97644f9ea2395620de72362a06e", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-47674"], "package": "hono", "rule_id": "GHSA-xrhx-7g5j-rcj5", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-47674|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-xpcf-pg52-r92g", "level": "warning", "message": {"text": "hono: GHSA-xpcf-pg52-r92g"}, "properties": {"repobilityId": 223527, "scanner": "osv-scanner", "fingerprint": "3879085545b4d7b2571a8ee2a97d250bb3d9c113e71e7e1301464ccbe66166ac", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39409"], "package": "hono", "rule_id": "GHSA-xpcf-pg52-r92g", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-39409|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-xf4j-xp2r-rqqx", "level": "warning", "message": {"text": "hono: GHSA-xf4j-xp2r-rqqx"}, "properties": {"repobilityId": 223521, "scanner": "osv-scanner", "fingerprint": "bdffe3a2dc5829fb1afe38da51bdf92242247f49604d97fbcbaf0f26a951e163", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39408"], "package": "hono", "rule_id": "GHSA-xf4j-xp2r-rqqx", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-39408|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-wmmm-f939-6g9c", "level": "warning", "message": {"text": "hono: GHSA-wmmm-f939-6g9c"}, "properties": {"repobilityId": 223520, "scanner": "osv-scanner", "fingerprint": "c77b82a60375096dacf2cf7ee222622af311e0ae11424c14f9aa45dcad3fa154", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39407"], "package": "hono", "rule_id": "GHSA-wmmm-f939-6g9c", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-39407|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-w332-q679-j88p", "level": "warning", "message": {"text": "hono: GHSA-w332-q679-j88p"}, "properties": {"repobilityId": 223519, "scanner": "osv-scanner", "fingerprint": "0340d82f75eb99fe272cd21fe513ab107f9be5516fe2422b3ccfe0a95fb2fdc4", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24473"], "package": "hono", "rule_id": "GHSA-w332-q679-j88p", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-24473|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-v8w9-8mx6-g223", "level": "warning", "message": {"text": "hono: GHSA-v8w9-8mx6-g223"}, "properties": {"repobilityId": 223518, "scanner": "osv-scanner", "fingerprint": "8a81b5c5489155c3991a8cfd28d4e22ef27dcf4fdd6f75055efac3f4bb914bea", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "hono", "rule_id": "GHSA-v8w9-8mx6-g223", "scanner": "osv-scanner", "correlation_key": "vuln|hono|GHSA-V8W9-8MX6-G223|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r5rp-j6wh-rvv4", "level": "warning", "message": {"text": "hono: GHSA-r5rp-j6wh-rvv4"}, "properties": {"repobilityId": 223517, "scanner": "osv-scanner", "fingerprint": "dd3b1b37c7562561dc589af48bd2dcabc82559f640f46797a2cc854973bab190", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39410"], "package": "hono", "rule_id": "GHSA-r5rp-j6wh-rvv4", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-39410|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r354-f388-2fhh", "level": "warning", "message": {"text": "hono: GHSA-r354-f388-2fhh"}, "properties": {"repobilityId": 223514, "scanner": "osv-scanner", "fingerprint": "1c5e190c78b92fbbd9666341e04211294440a4f230a3e02d30ec13a25add8b58", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24398"], "package": "hono", "rule_id": "GHSA-r354-f388-2fhh", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-24398|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qp7p-654g-cw7p", "level": "warning", "message": {"text": "hono: GHSA-qp7p-654g-cw7p"}, "properties": {"repobilityId": 223513, "scanner": "osv-scanner", "fingerprint": "36b6d52ad6da58f0ea59be15733c0fbf8556a0970c284daa6278b0f7f4417274", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44458"], "package": "hono", "rule_id": "GHSA-qp7p-654g-cw7p", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-44458|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-p77w-8qqv-26rm", "level": "warning", "message": {"text": "hono: GHSA-p77w-8qqv-26rm"}, "properties": {"repobilityId": 223511, "scanner": "osv-scanner", "fingerprint": "7bc3f88c5d70fe72bc2f4e3891b9cdcadf15632869e7b9c4d30dd741a32a910a", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44457"], "package": "hono", "rule_id": "GHSA-p77w-8qqv-26rm", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-44457|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-p6xx-57qc-3wxr", "level": "warning", "message": {"text": "hono: GHSA-p6xx-57qc-3wxr"}, "properties": {"repobilityId": 223509, "scanner": "osv-scanner", "fingerprint": "ec554988a246d680ecf3de0b84b0d1f11af9c34fd3459105116dc41d97045e59", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-29085"], "package": "hono", "rule_id": "GHSA-p6xx-57qc-3wxr", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-29085|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f577-qrjj-4474", "level": "warning", "message": {"text": "hono: GHSA-f577-qrjj-4474"}, "properties": {"repobilityId": 223496, "scanner": "osv-scanner", "fingerprint": "e208e70fa87227fbe53da3f61fe2ac217a8f9277ac8c866372d70757d173a82a", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-47673"], "package": "hono", "rule_id": "GHSA-f577-qrjj-4474", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-47673|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9vqf-7f2p-gf9v", "level": "warning", "message": {"text": "hono: GHSA-9vqf-7f2p-gf9v"}, "properties": {"repobilityId": 223495, "scanner": "osv-scanner", "fingerprint": "f968051640d4b009cb2d9424b8282eca45c8c6e9109d8d7fb0f97d0befebb3dd", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44456"], "package": "hono", "rule_id": "GHSA-9vqf-7f2p-gf9v", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-44456|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9r54-q6cx-xmh5", "level": "warning", "message": {"text": "hono: GHSA-9r54-q6cx-xmh5"}, "properties": {"repobilityId": 223494, "scanner": "osv-scanner", "fingerprint": "ba034d736595f1179ac6a38e826db42139e91283f80b43ab81d568f31ac8dfe7", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24771"], "package": "hono", "rule_id": "GHSA-9r54-q6cx-xmh5", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-24771|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-6wqw-2p9w-4vw4", "level": "warning", "message": {"text": "hono: GHSA-6wqw-2p9w-4vw4"}, "properties": {"repobilityId": 223493, "scanner": "osv-scanner", "fingerprint": "5f4cf8e65ae0b3f74010a5f38e8399ee854fada78653ab188c6548e3c3d40486", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24472"], "package": "hono", "rule_id": "GHSA-6wqw-2p9w-4vw4", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-24472|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-69xw-7hcm-h432", "level": "warning", "message": {"text": "hono: GHSA-69xw-7hcm-h432"}, "properties": {"repobilityId": 223492, "scanner": "osv-scanner", "fingerprint": "b9015a2006b4b8877139a0a84e28714702bf9e7ab7003879ec3b08713dc911b0", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44455"], "package": "hono", "rule_id": "GHSA-69xw-7hcm-h432", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-44455|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5pq2-9x2x-5p6w", "level": "warning", "message": {"text": "hono: GHSA-5pq2-9x2x-5p6w"}, "properties": {"repobilityId": 223491, "scanner": "osv-scanner", "fingerprint": "d2d79312fa3fb0f485b452b0a07acd4a6fe57f6d19f069db145b23944da7ecca", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-29086"], "package": "hono", "rule_id": "GHSA-5pq2-9x2x-5p6w", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-29086|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-458j-xx4x-4375", "level": "warning", "message": {"text": "hono: GHSA-458j-xx4x-4375"}, "properties": {"repobilityId": 223490, "scanner": "osv-scanner", "fingerprint": "e54929094efcc9c71ed2bea47d7a2efe72a47913e3cbf6518bd9706d19056dc6", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "hono", "rule_id": "GHSA-458j-xx4x-4375", "scanner": "osv-scanner", "correlation_key": "vuln|hono|GHSA-458J-XX4X-4375|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3hrh-pfw6-9m5x", "level": "warning", "message": {"text": "hono: GHSA-3hrh-pfw6-9m5x"}, "properties": {"repobilityId": 223484, "scanner": "osv-scanner", "fingerprint": "e0310fecceaa1b185e84974a0e921e9246e915ec57dc03dd475b24154a382bb8", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-47675"], "package": "hono", "rule_id": "GHSA-3hrh-pfw6-9m5x", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-47675|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-2gcr-mfcq-wcc3", "level": "warning", "message": {"text": "hono: GHSA-2gcr-mfcq-wcc3"}, "properties": {"repobilityId": 223481, "scanner": "osv-scanner", "fingerprint": "82be9ca729a9b377be787e2a4870ae0fe637910fd7001804d481802695279c06", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-47676"], "package": "hono", "rule_id": "GHSA-2gcr-mfcq-wcc3", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-47676|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-26pp-8wgv-hjvm", "level": "warning", "message": {"text": "hono: GHSA-26pp-8wgv-hjvm"}, "properties": {"repobilityId": 223479, "scanner": "osv-scanner", "fingerprint": "58b4203660be5a4cdb5a1cbe81f209fc96a940ee90dd2aef542f80e8d17c9555", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "hono", "rule_id": "GHSA-26pp-8wgv-hjvm", "scanner": "osv-scanner", "correlation_key": "vuln|hono|GHSA-26PP-8WGV-HJVM|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jxxr-4gwj-5jf2", "level": "warning", "message": {"text": "brace-expansion: GHSA-jxxr-4gwj-5jf2"}, "properties": {"repobilityId": 223465, "scanner": "osv-scanner", "fingerprint": "df9432682f1efa01d242974fb7d6c679d3a112195415b0ccdedda1d7decb9db5", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-45149"], "package": "brace-expansion", "rule_id": "GHSA-jxxr-4gwj-5jf2", "scanner": "osv-scanner", "correlation_key": "vuln|brace-expansion|CVE-2026-45149|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-2g4f-4pwh-qvx6", "level": "warning", "message": {"text": "ajv: GHSA-2g4f-4pwh-qvx6"}, "properties": {"repobilityId": 223464, "scanner": "osv-scanner", "fingerprint": "0b4075edd70eccc9e81ce84656b8a0c1040ecc83769ba1ed4fe7ce3796321c93", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-69873"], "package": "ajv", "rule_id": "GHSA-2g4f-4pwh-qvx6", "scanner": "osv-scanner", "correlation_key": "vuln|ajv|CVE-2025-69873|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8988-4f7v-96qf", "level": "warning", "message": {"text": "@opentelemetry/core: GHSA-8988-4f7v-96qf"}, "properties": {"repobilityId": 223463, "scanner": "osv-scanner", "fingerprint": "5f0e69ad39cd4868b1723a0ee5ec08a1158e82bc9ca213dec11cf9b43dcf7354", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-54285"], "package": "@opentelemetry/core", "rule_id": "GHSA-8988-4f7v-96qf", "scanner": "osv-scanner", "correlation_key": "vuln|opentelemetry/core|CVE-2026-54285|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-92pp-h63x-v22m", "level": "warning", "message": {"text": "@hono/node-server: GHSA-92pp-h63x-v22m"}, "properties": {"repobilityId": 223455, "scanner": "osv-scanner", "fingerprint": "9dc4af0ce4e69cd302c18a60fee266d778f63bfd65f3810d1ed3661496fd5f32", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-39406"], "package": "@hono/node-server", "rule_id": "GHSA-92pp-h63x-v22m", "scanner": "osv-scanner", "correlation_key": "vuln|hono/node-server|CVE-2026-39406|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qx2v-qp2m-jg93", "level": "warning", "message": {"text": "postcss: GHSA-qx2v-qp2m-jg93"}, "properties": {"repobilityId": 223451, "scanner": "osv-scanner", "fingerprint": "33aa829b4458c5ef73d832c9e568cf3032217bd31f4b18cc6a572d90111a50bb", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-41305"], "package": "postcss", "rule_id": "GHSA-qx2v-qp2m-jg93", "scanner": "osv-scanner", "correlation_key": "vuln|postcss|CVE-2026-41305|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-wfc6-r584-vfw7", "level": "warning", "message": {"text": "next: GHSA-wfc6-r584-vfw7"}, "properties": {"repobilityId": 223450, "scanner": "osv-scanner", "fingerprint": "b135063ee03824d6cf1e30a6a6aac40f574e1115e9b4b1c66c5e989952dc04fb", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44576"], "package": "next", "rule_id": "GHSA-wfc6-r584-vfw7", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44576|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mq59-m269-xvcx", "level": "warning", "message": {"text": "next: GHSA-mq59-m269-xvcx"}, "properties": {"repobilityId": 223445, "scanner": "osv-scanner", "fingerprint": "9f429329769ffcf4be2c21cd106265a7b0733c3d852097844d0bc0441ea90da4", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27978"], "package": "next", "rule_id": "GHSA-mq59-m269-xvcx", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-27978|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-h64f-5h5j-jqjh", "level": "warning", "message": {"text": "next: GHSA-h64f-5h5j-jqjh"}, "properties": {"repobilityId": 223436, "scanner": "osv-scanner", "fingerprint": "a1dfd0945a57e11c2bef9ff1a367d8e3717d6f85b2d9c963a9923283f4130bda", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44577"], "package": "next", "rule_id": "GHSA-h64f-5h5j-jqjh", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44577|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-h27x-g6w4-24gq", "level": "warning", "message": {"text": "next: GHSA-h27x-g6w4-24gq"}, "properties": {"repobilityId": 223435, "scanner": "osv-scanner", "fingerprint": "ddfb7bea7625f556f57c59924ee16282e11df66da96be3a81794fce231bf63ac", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27979"], "package": "next", "rule_id": "GHSA-h27x-g6w4-24gq", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-27979|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gx5p-jg67-6x7h", "level": "warning", "message": {"text": "next: GHSA-gx5p-jg67-6x7h"}, "properties": {"repobilityId": 223433, "scanner": "osv-scanner", "fingerprint": "90ba648bcec3971ebd91627a1eab941850d4e6fd16d341d52fd70c8994d30530", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44580"], "package": "next", "rule_id": "GHSA-gx5p-jg67-6x7h", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44580|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-ggv3-7p47-pfv8", "level": "warning", "message": {"text": "next: GHSA-ggv3-7p47-pfv8"}, "properties": {"repobilityId": 223432, "scanner": "osv-scanner", "fingerprint": "6d9bb335a8f5e9f9435ace6347fd98e0df3601efa1b88e34a3ed4850c3200123", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-29057"], "package": "next", "rule_id": "GHSA-ggv3-7p47-pfv8", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-29057|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-ffhc-5mcf-pf4q", "level": "warning", "message": {"text": "next: GHSA-ffhc-5mcf-pf4q"}, "properties": {"repobilityId": 223431, "scanner": "osv-scanner", "fingerprint": "92be124c35f21e4a1f71e03937b28d99993213a328a38f184cbc4723c7bf0fd8", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44581"], "package": "next", "rule_id": "GHSA-ffhc-5mcf-pf4q", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44581|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9g9p-9gw9-jx7f", "level": "warning", "message": {"text": "next: GHSA-9g9p-9gw9-jx7f"}, "properties": {"repobilityId": 223429, "scanner": "osv-scanner", "fingerprint": "f8a00943da541498cf7d1651274f627cd957f17d8cd01c58149ca57a69d72f70", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-59471"], "package": "next", "rule_id": "GHSA-9g9p-9gw9-jx7f", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2025-59471|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-5f7q-jpqc-wp7h", "level": "warning", "message": {"text": "next: GHSA-5f7q-jpqc-wp7h"}, "properties": {"repobilityId": 223427, "scanner": "osv-scanner", "fingerprint": "59746009347b39fd8b6d9f7f32c58bf0fa5474c696782bdcb0613f69bb169081", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2025-59472"], "package": "next", "rule_id": "GHSA-5f7q-jpqc-wp7h", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2025-59472|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3x4c-7xq6-9pq8", "level": "warning", "message": {"text": "next: GHSA-3x4c-7xq6-9pq8"}, "properties": {"repobilityId": 223422, "scanner": "osv-scanner", "fingerprint": "9695b74d580d0559aa92621bb451e796987ab996cc4791024990a23849942658", "category": "dependency", "severity": "medium", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27980"], "package": "next", "rule_id": "GHSA-3x4c-7xq6-9pq8", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-27980|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `lint-staged` is 1 major version(s) behind (^16.4.0 -> 17.0.7)"}, "properties": {"repobilityId": 223374, "scanner": "repobility-dependency-currency", "fingerprint": "f36983bb482b184333db0f655e2c3fa020c2729534b12614f7e5c4d523c9f882", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "lint-staged", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "17.0.7", "correlation_key": "fp|f36983bb482b184333db0f655e2c3fa020c2729534b12614f7e5c4d523c9f882", "current_version": "^16.4.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `shadcn` is 1 major version(s) behind (^3.6.2 -> 4.11.0)"}, "properties": {"repobilityId": 223363, "scanner": "repobility-dependency-currency", "fingerprint": "12453234ceaa617a3cd0bc0ae1274b76b5dc834e7847a5c09ee736466b3b2610", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "shadcn", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "4.11.0", "correlation_key": "fp|12453234ceaa617a3cd0bc0ae1274b76b5dc834e7847a5c09ee736466b3b2610", "current_version": "^3.6.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `@vercel/speed-insights` is 1 major version(s) behind (^1.3.1 -> 2.0.0)"}, "properties": {"repobilityId": 223340, "scanner": "repobility-dependency-currency", "fingerprint": "c8646d164f55a7240a283a25bdd3c0a1d3feceb5ad4a6e9740372ff253c5150e", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@vercel/speed-insights", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "2.0.0", "correlation_key": "fp|c8646d164f55a7240a283a25bdd3c0a1d3feceb5ad4a6e9740372ff253c5150e", "current_version": "^1.3.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "warning", "message": {"text": "npm package `@vercel/analytics` is 1 major version(s) behind (^1.6.1 -> 2.0.1)"}, "properties": {"repobilityId": 223339, "scanner": "repobility-dependency-currency", "fingerprint": "ded12b41a32270739748620e48cdeb66b6f6fb95f37eeaa566f69d51355ce5be", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "1 major version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@vercel/analytics", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "2.0.1", "correlation_key": "fp|ded12b41a32270739748620e48cdeb66b6f6fb95f37eeaa566f69d51355ce5be", "current_version": "^1.6.1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED115", "level": "warning", "message": {"text": "Action `supabase/setup-cli` pinned to mutable ref `@v2`"}, "properties": {"repobilityId": 223321, "scanner": "repobility-supply-chain", "fingerprint": "defeaeab83393cd2b482fcd2a488354b838d7168911a48e095900780f50535d6", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|defeaeab83393cd2b482fcd2a488354b838d7168911a48e095900780f50535d6"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/migrations-deploy.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "MINED115", "level": "warning", "message": {"text": "Action `supabase/setup-cli` pinned to mutable ref `@v2`"}, "properties": {"repobilityId": 223307, "scanner": "repobility-supply-chain", "fingerprint": "62132e95278d0b78efe7b7a599162955887801abaebff3af1437ecb52a2dfde4", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|62132e95278d0b78efe7b7a599162955887801abaebff3af1437ecb52a2dfde4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/migrations-ci.yml"}, "region": {"startLine": 58}}}]}, {"ruleId": "MINED115", "level": "warning", "message": {"text": "Action `supabase/setup-cli` pinned to mutable ref `@v2`"}, "properties": {"repobilityId": 223293, "scanner": "repobility-supply-chain", "fingerprint": "abb222c1bf858770e39263dba8103f646b9deeb5a515b00f9dde8175c8647a55", "category": "dependency", "severity": "medium", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|abb222c1bf858770e39263dba8103f646b9deeb5a515b00f9dde8175c8647a55"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 63}}}]}, {"ruleId": "WEB011", "level": "note", "message": {"text": "Public web app has no humans.txt"}, "properties": {"repobilityId": 223590, "scanner": "repobility-web-presence", "fingerprint": "bdd551fbe1ab6405480e0d5755632562c2096cb9e9a6a071ef60e4c27a6873f1", "category": "quality", "severity": "low", "confidence": 0.5, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Repository looks like a public web app but no humans.txt file or route was discovered.", "evidence": {"rule_id": "WEB011", "scanner": "repobility-web-presence", "references": ["https://github.com/Lissy93/web-check"], "correlation_key": "fp|bdd551fbe1ab6405480e0d5755632562c2096cb9e9a6a071ef60e4c27a6873f1"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "humans.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB008", "level": "note", "message": {"text": "Public docs site has no llms.txt"}, "properties": {"repobilityId": 223589, "scanner": "repobility-web-presence", "fingerprint": "cdce8ed8706710d39c3e7272dad572dd639cff74fd3d2ac62d8f6f522b891d76", "category": "quality", "severity": "low", "confidence": 0.64, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Repository looks public and documentation-heavy but no llms.txt file or route was discovered.", "evidence": {"rule_id": "WEB008", "scanner": "repobility-web-presence", "references": ["https://llmstxt.org/"], "correlation_key": "fp|cdce8ed8706710d39c3e7272dad572dd639cff74fd3d2ac62d8f6f522b891d76"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "llms.txt"}, "region": {"startLine": 1}}}]}, {"ruleId": "WEB002", "level": "note", "message": {"text": "Public web app has no sitemap"}, "properties": {"repobilityId": 223588, "scanner": "repobility-web-presence", "fingerprint": "fccbe72d13ca3ba9197ec37b0daa0802fb6d5ebff54b3eb9f09b59b0f8d0acdf", "category": "quality", "severity": "low", "confidence": 0.72, "triageState": "open", "verdict": "likely", "isResolved": false, "reason": "Repository looks like a public web app but no sitemap file or route was discovered.", "evidence": {"rule_id": "WEB002", "scanner": "repobility-web-presence", "references": ["https://www.sitemaps.org/protocol.html", "https://github.com/Lissy93/web-check"], "correlation_key": "fp|fccbe72d13ca3ba9197ec37b0daa0802fb6d5ebff54b3eb9f09b59b0f8d0acdf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sitemap.xml"}, "region": {"startLine": 1}}}]}, {"ruleId": "AUC005", "level": "note", "message": {"text": "[AUC005] No authorization-focused tests detected: No test files with common authorization, ownership, 403, admin, or super_admin assertions were found."}, "properties": {"repobilityId": 223587, "scanner": "repobility-access-control", "fingerprint": "c58bb88e6682225dc480b3036f30153044953a3d94f500396678a77324e8d30e", "category": "auth", "severity": "low", "confidence": 0.76, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Static route and framework evidence require project-owner confirmation.", "evidence": {"scanner": "repobility-access-control", "frameworks": ["Next.js"], "correlation_key": "fp|c58bb88e6682225dc480b3036f30153044953a3d94f500396678a77324e8d30e"}}}, {"ruleId": "GHSA-w7fw-mjwx-w883", "level": "note", "message": {"text": "qs: GHSA-w7fw-mjwx-w883"}, "properties": {"repobilityId": 223572, "scanner": "osv-scanner", "fingerprint": "a8ebfae1708877f4dd9d37cacb9e0f82aeb99b56d968b81a86d1302c6d3af0c2", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-2391"], "package": "qs", "rule_id": "GHSA-w7fw-mjwx-w883", "scanner": "osv-scanner", "correlation_key": "vuln|qs|CVE-2026-2391|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-hm8q-7f3q-5f36", "level": "note", "message": {"text": "hono: GHSA-hm8q-7f3q-5f36"}, "properties": {"repobilityId": 223499, "scanner": "osv-scanner", "fingerprint": "7fd3c15228d52b639071c13076b2a0652a502eeed6bebe74b270a7d297575d68", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44459"], "package": "hono", "rule_id": "GHSA-hm8q-7f3q-5f36", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-44459|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-gq3j-xvxp-8hrf", "level": "note", "message": {"text": "hono: GHSA-gq3j-xvxp-8hrf"}, "properties": {"repobilityId": 223498, "scanner": "osv-scanner", "fingerprint": "48d4cd4f3ad1c765b608da163b2ae37ce9e2bfb7a92a2047bb5b06bea80d0ce6", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "hono", "rule_id": "GHSA-gq3j-xvxp-8hrf", "scanner": "osv-scanner", "correlation_key": "vuln|hono|GHSA-GQ3J-XVXP-8HRF|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-73rr-hh4g-fpgx", "level": "note", "message": {"text": "diff: GHSA-73rr-hh4g-fpgx"}, "properties": {"repobilityId": 223468, "scanner": "osv-scanner", "fingerprint": "8c668fba000790b63076d59a9979b7c2de72c5f84d365e64fc242ae039652734", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24001"], "package": "diff", "rule_id": "GHSA-73rr-hh4g-fpgx", "scanner": "osv-scanner", "correlation_key": "vuln|diff|CVE-2026-24001|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-4x5r-pxfx-6jf8", "level": "note", "message": {"text": "@babel/core: GHSA-4x5r-pxfx-6jf8"}, "properties": {"repobilityId": 223453, "scanner": "osv-scanner", "fingerprint": "4e4715f00ebfad070b78f6aecc8ad8714c6be17d7c27376ee9c197705f854a92", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-49356"], "package": "@babel/core", "rule_id": "GHSA-4x5r-pxfx-6jf8", "scanner": "osv-scanner", "correlation_key": "vuln|babel/core|CVE-2026-49356|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-vfv6-92ff-j949", "level": "note", "message": {"text": "next: GHSA-vfv6-92ff-j949"}, "properties": {"repobilityId": 223449, "scanner": "osv-scanner", "fingerprint": "020875b224996bae0292b1c4c40a8f42cbf22211fc1f510c40b8efc0ebefd7f5", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44582"], "package": "next", "rule_id": "GHSA-vfv6-92ff-j949", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44582|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-jcc7-9wpm-mj36", "level": "note", "message": {"text": "next: GHSA-jcc7-9wpm-mj36"}, "properties": {"repobilityId": 223437, "scanner": "osv-scanner", "fingerprint": "ca689a4e09876def8df077fb6e8eb7830c4d32fc72e28ec1a2e8a79e727ecb9c", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27977"], "package": "next", "rule_id": "GHSA-jcc7-9wpm-mj36", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-27977|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3g8h-86w9-wvmq", "level": "note", "message": {"text": "next: GHSA-3g8h-86w9-wvmq"}, "properties": {"repobilityId": 223410, "scanner": "osv-scanner", "fingerprint": "38510533c287efb9e7623096f4a697e2ff4c505d6885330e9cd14b714b201040", "category": "dependency", "severity": "low", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44572"], "package": "next", "rule_id": "GHSA-3g8h-86w9-wvmq", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44572|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@biomejs/biome` is minor version(s) behind (2.2.0 -> 2.5.0)"}, "properties": {"repobilityId": 223367, "scanner": "repobility-dependency-currency", "fingerprint": "1d4df7aff7231b009b372851b9bfd1fbce5a3adfae1f918ecf6391645af9deb2", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@biomejs/biome", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "2.5.0", "correlation_key": "fp|1d4df7aff7231b009b372851b9bfd1fbce5a3adfae1f918ecf6391645af9deb2", "current_version": "2.2.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `tailwind-merge` is minor version(s) behind (^3.4.0 -> 3.6.0)"}, "properties": {"repobilityId": 223364, "scanner": "repobility-dependency-currency", "fingerprint": "1066fee45ae7f3ec7567ac443913aea7fb87d59c9c046be529fa11a631737a82", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "tailwind-merge", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "3.6.0", "correlation_key": "fp|1066fee45ae7f3ec7567ac443913aea7fb87d59c9c046be529fa11a631737a82", "current_version": "^3.4.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `radix-ui` is minor version(s) behind (^1.4.3 -> 1.6.0)"}, "properties": {"repobilityId": 223354, "scanner": "repobility-dependency-currency", "fingerprint": "01d75d0dd64107453d685a35dc0e3334b546e185866af80c3047c9d8dcc37a82", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "radix-ui", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.6.0", "correlation_key": "fp|01d75d0dd64107453d685a35dc0e3334b546e185866af80c3047c9d8dcc37a82", "current_version": "^1.4.3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `next-intl` is minor version(s) behind (^4.7.0 -> 4.13.0)"}, "properties": {"repobilityId": 223353, "scanner": "repobility-dependency-currency", "fingerprint": "4f904cab2ec0e47f1a2f81461a7721aeec54dd29ca038085ba2ca763d07a25ce", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "next-intl", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "4.13.0", "correlation_key": "fp|4f904cab2ec0e47f1a2f81461a7721aeec54dd29ca038085ba2ca763d07a25ce", "current_version": "^4.7.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@supabase/ssr` is minor version(s) behind (^0.8.0 -> 0.12.0)"}, "properties": {"repobilityId": 223337, "scanner": "repobility-dependency-currency", "fingerprint": "0b4061350ba9bb8903c7e84f711a0e51a3a0a15f0266cea33570a3d6e35ef32c", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@supabase/ssr", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "0.12.0", "correlation_key": "fp|0b4061350ba9bb8903c7e84f711a0e51a3a0a15f0266cea33570a3d6e35ef32c", "current_version": "^0.8.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@hookform/resolvers` is minor version(s) behind (^5.2.2 -> 5.4.0)"}, "properties": {"repobilityId": 223333, "scanner": "repobility-dependency-currency", "fingerprint": "75d0aeea42ca62f7dae905aba1fb775d48f2e28c5c235ca6cd652c69b8460687", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@hookform/resolvers", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "5.4.0", "correlation_key": "fp|75d0aeea42ca62f7dae905aba1fb775d48f2e28c5c235ca6cd652c69b8460687", "current_version": "^5.2.2"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "DEPCUR-NPM", "level": "note", "message": {"text": "npm package `@base-ui/react` is minor version(s) behind (^1.0.0 -> 1.5.0)"}, "properties": {"repobilityId": 223326, "scanner": "repobility-dependency-currency", "fingerprint": "0280d3a13bceda95684a4152e11d151aa6c5fae1f2f081d9446412857e4b9cf5", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "minor version(s) behind", "signal": "currency", "cwe_ids": [], "package": "@base-ui/react", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "1.5.0", "correlation_key": "fp|0280d3a13bceda95684a4152e11d151aa6c5fae1f2f081d9446412857e4b9cf5", "current_version": "^1.0.0"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 223319, "scanner": "repobility-supply-chain", "fingerprint": "9fdf1c23c1f2fbd25d160962ca52c2f29fb3cd402ec41543a0560ca5a789b542", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|9fdf1c23c1f2fbd25d160962ca52c2f29fb3cd402ec41543a0560ca5a789b542"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/migrations-deploy.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 223314, "scanner": "repobility-supply-chain", "fingerprint": "f419c06cda9c001148265576eafdcb60db98ccbaf58390c01b7ffcdca10fa890", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|f419c06cda9c001148265576eafdcb60db98ccbaf58390c01b7ffcdca10fa890"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/lint.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 223308, "scanner": "repobility-supply-chain", "fingerprint": "36f9263a058bb279428824602590bd967c35cff3f0ff6b70c5ae9f23aed42fc3", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|36f9263a058bb279428824602590bd967c35cff3f0ff6b70c5ae9f23aed42fc3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/lint.yml"}, "region": {"startLine": 14}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 223306, "scanner": "repobility-supply-chain", "fingerprint": "235358e77934479f53b42006dd0763ee679458182b8a622fbf5768308cfd3d85", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|235358e77934479f53b42006dd0763ee679458182b8a622fbf5768308cfd3d85"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/migrations-ci.yml"}, "region": {"startLine": 19}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/upload-artifact` pinned to mutable ref `@v7`"}, "properties": {"repobilityId": 223304, "scanner": "repobility-supply-chain", "fingerprint": "a0c5cf82372f217d7feb13fa1ee2962bf010d6a7b37f9a267f03b56f32fffc1b", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|a0c5cf82372f217d7feb13fa1ee2962bf010d6a7b37f9a267f03b56f32fffc1b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 108}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 223299, "scanner": "repobility-supply-chain", "fingerprint": "3377e34670d0d0ff344a0594044a81f6a39db2608331e9ccc318c27ad4367e0b", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|3377e34670d0d0ff344a0594044a81f6a39db2608331e9ccc318c27ad4367e0b"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 93}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/cache` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 223298, "scanner": "repobility-supply-chain", "fingerprint": "9d6df9e3d1cf755511a5da88d99f7725d7805fa5f03ef4c6b6fa3275f2b4abc5", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|9d6df9e3d1cf755511a5da88d99f7725d7805fa5f03ef4c6b6fa3275f2b4abc5"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 77}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/setup-node` pinned to mutable ref `@v4`"}, "properties": {"repobilityId": 223292, "scanner": "repobility-supply-chain", "fingerprint": "3dfed40865cdfde226acdd865429891ab79cb99d4bdbe0777ffb80b4d08118d9", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|3dfed40865cdfde226acdd865429891ab79cb99d4bdbe0777ffb80b4d08118d9"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 53}}}]}, {"ruleId": "MINED115", "level": "note", "message": {"text": "Action `actions/checkout` pinned to mutable ref `@v6`"}, "properties": {"repobilityId": 223287, "scanner": "repobility-supply-chain", "fingerprint": "46e5467a3e9b181be15c866401b396d8ba55805f3e5be8811aa515ed98dbc1bf", "category": "dependency", "severity": "low", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"mined": true, "mining": {"slug": "gha-mutable-ref", "owasp": "A08:2021", "cwe_ids": ["CWE-829"], "languages": ["yaml"], "observations_count": 0}, "scanner": "repobility-supply-chain", "correlation_key": "fp|46e5467a3e9b181be15c866401b396d8ba55805f3e5be8811aa515ed98dbc1bf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 49}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 223285, "scanner": "repobility-ai-code-hygiene", "fingerprint": "cd31778d7ea2c728afbfb24412624ab49079ac4f38f551319e8b636dc1b3872f", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "app/(marketing)/opengraph-image.tsx", "duplicate_line": 1, "correlation_key": "fp|cd31778d7ea2c728afbfb24412624ab49079ac4f38f551319e8b636dc1b3872f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(marketing)/twitter-image.tsx"}, "region": {"startLine": 1}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 223284, "scanner": "repobility-ai-code-hygiene", "fingerprint": "54283aebfe92d0a2ddd24fd952166fc83a3935999c624dced2192dd90951af07", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "app/(app)/flames/components/FuelMeter.tsx", "duplicate_line": 168, "correlation_key": "fp|54283aebfe92d0a2ddd24fd952166fc83a3935999c624dced2192dd90951af07"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(marketing)/components/ShowcaseFuelBar.tsx"}, "region": {"startLine": 97}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 223280, "scanner": "repobility-ai-code-hygiene", "fingerprint": "df492fd979a9975082bcd7a27a205bf1ded49ac680b42c6726339221759587af", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "app/(auth)/login/form.tsx", "duplicate_line": 6, "correlation_key": "fp|df492fd979a9975082bcd7a27a205bf1ded49ac680b42c6726339221759587af"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(auth)/signup/form.tsx"}, "region": {"startLine": 6}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 223268, "scanner": "repobility-ai-code-hygiene", "fingerprint": "4f54f01533e2fb805817fbb75f0b3be4be1b3d333b6f6e246a397f492d006b1c", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "app/(app)/flames/components/FuelMeter.tsx", "duplicate_line": 113, "correlation_key": "fp|4f54f01533e2fb805817fbb75f0b3be4be1b3d333b6f6e246a397f492d006b1c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/flames/schedule/components/dialog/FuelSlider.tsx"}, "region": {"startLine": 210}}}]}, {"ruleId": "AIC003", "level": "note", "message": {"text": "Duplicated implementation block across source files"}, "properties": {"repobilityId": 223248, "scanner": "repobility-ai-code-hygiene", "fingerprint": "93bb12957d0a0c7899f2bccb71fc6bcd3c7d60190072ed7c753d671b38a240a3", "category": "quality", "severity": "low", "confidence": 0.86, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "A normalized source-code window appears in two different non-test files.", "evidence": {"lines": 12, "rule_id": "AIC003", "scanner": "repobility-ai-code-hygiene", "references": ["https://jscpd.dev/"], "duplicate_file": "app/(app)/flames/components/flame-card/flames/Star.tsx", "duplicate_line": 1, "correlation_key": "fp|93bb12957d0a0c7899f2bccb71fc6bcd3c7d60190072ed7c753d671b38a240a3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/flames/components/flame-card/flames/Supernova.tsx"}, "region": {"startLine": 1}}}]}, {"ruleId": "CORE_NO_LICENSE", "level": "note", "message": {"text": "No LICENSE file"}, "properties": {"repobilityId": 223246, "scanner": "repobility-core", "fingerprint": "9314e9238cd99885865b92490d1aaa96ca62b1390c9377878d5f3d99227e1c3c", "category": "documentation", "severity": "low", "confidence": null, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"rule_id": "CORE_NO_LICENSE", "scanner": "repobility-core", "correlation_key": "repo|documentation|core_no_license"}}}, {"ruleId": "MINED058", "level": "none", "message": {"text": "[MINED058] React Dangerously Set Html: dangerouslySetInnerHTML bypasses Reacts JSX escaping. Pair with DOMPurify or never use with user data."}, "properties": {"repobilityId": 223383, "scanner": "repobility-threat-engine", "fingerprint": "a69a32807867a5c7e2f4beda7816f30089c23e6e931abac2fbfa43222338b0cf", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-dangerously-set-html", "owasp": "A03:2021", "cwe_ids": ["CWE-79"], "languages": ["javascript", "typescript"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348037+00:00", "triaged_in_corpus": 12, "observations_count": 255650, "ai_coder_pattern_id": 49}, "scanner": "repobility-threat-engine", "correlation_key": "fp|a69a32807867a5c7e2f4beda7816f30089c23e6e931abac2fbfa43222338b0cf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(marketing)/page.tsx"}, "region": {"startLine": 48}}}]}, {"ruleId": "MINED056", "level": "none", "message": {"text": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order."}, "properties": {"repobilityId": 223381, "scanner": "repobility-threat-engine", "fingerprint": "5803ee28546372e8a98306fb151090279d29175d2fb339ded3ae5c282181df9e", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-key-as-index", "owasp": null, "cwe_ids": ["CWE-682"], "languages": ["typescript", "tsx", "javascript", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348032+00:00", "triaged_in_corpus": 12, "observations_count": 299917, "ai_coder_pattern_id": 135}, "scanner": "repobility-threat-engine", "correlation_key": "fp|5803ee28546372e8a98306fb151090279d29175d2fb339ded3ae5c282181df9e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "components/ui/field.tsx"}, "region": {"startLine": 204}}}]}, {"ruleId": "MINED056", "level": "none", "message": {"text": "[MINED056] React Key As Index: key={index} in map() \u2014 re-renders the wrong elements on re-order."}, "properties": {"repobilityId": 223380, "scanner": "repobility-threat-engine", "fingerprint": "a1bc714b7eba6a1012f87e4c6822119bf2a4b1777e890a81d365bcd9a348472f", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "react-key-as-index", "owasp": null, "cwe_ids": ["CWE-682"], "languages": ["typescript", "tsx", "javascript", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348032+00:00", "triaged_in_corpus": 12, "observations_count": 299917, "ai_coder_pattern_id": 135}, "scanner": "repobility-threat-engine", "correlation_key": "fp|a1bc714b7eba6a1012f87e4c6822119bf2a4b1777e890a81d365bcd9a348472f"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/flames/loading.tsx"}, "region": {"startLine": 17}}}]}, {"ruleId": "MINED044", "level": "none", "message": {"text": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed."}, "properties": {"repobilityId": 223379, "scanner": "repobility-threat-engine", "fingerprint": "8f06c5fa2bbec663702c7a1a2a71ede667e1ab6eb74b18d18cfce4e1de7b2a82", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "js-console-log-prod", "owasp": null, "cwe_ids": ["CWE-532"], "languages": ["javascript", "typescript", "tsx", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348003+00:00", "triaged_in_corpus": 10, "observations_count": 1940833, "ai_coder_pattern_id": 102}, "scanner": "repobility-threat-engine", "correlation_key": "fp|8f06c5fa2bbec663702c7a1a2a71ede667e1ab6eb74b18d18cfce4e1de7b2a82"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/layout.tsx"}, "region": {"startLine": 28}}}]}, {"ruleId": "MINED044", "level": "none", "message": {"text": "[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger or removed."}, "properties": {"repobilityId": 223378, "scanner": "repobility-threat-engine", "fingerprint": "b5395bda8147b09a95dcf999b8b85abb244ed1a43ef00b84d10a42a47f5f6a5c", "category": "quality", "severity": "info", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"mined": true, "mining": {"slug": "js-console-log-prod", "owasp": null, "cwe_ids": ["CWE-532"], "languages": ["javascript", "typescript", "tsx", "jsx"], "precision": 1.0, "promoted_at": "2026-05-18T14:01:32.348003+00:00", "triaged_in_corpus": 10, "observations_count": 1940833, "ai_coder_pattern_id": 102}, "scanner": "repobility-threat-engine", "correlation_key": "fp|b5395bda8147b09a95dcf999b8b85abb244ed1a43ef00b84d10a42a47f5f6a5c"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/dashboard/components/CreationDialog.tsx"}, "region": {"startLine": 125}}}]}, {"ruleId": "DEPCUR-NPM", "level": "none", "message": {"text": "npm package `resend` is patch version(s) behind (^6.12.3 -> 6.12.4)"}, "properties": {"repobilityId": 223355, "scanner": "repobility-dependency-currency", "fingerprint": "e4ffd3220416409b403b87a944da93f8803b40060304d00f4d051318428a3372", "category": "dependency", "severity": "info", "confidence": 0.9, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"gap": "patch version(s) behind", "signal": "currency", "cwe_ids": [], "package": "resend", "scanner": "repobility-dependency-currency", "ecosystem": "npm", "languages": ["javascript"], "latest_version": "6.12.4", "correlation_key": "fp|e4ffd3220416409b403b87a944da93f8803b40060304d00f4d051318428a3372", "current_version": "^6.12.3"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-96hv-2xvq-fx4p", "level": "error", "message": {"text": "ws: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": 223585, "scanner": "osv-scanner", "fingerprint": "3b355713e3791cbcf217dbe879b25c8b5f111e2a452e7d73d42f1f2ea389c695", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-48779"], "package": "ws", "rule_id": "GHSA-96hv-2xvq-fx4p", "scanner": "osv-scanner", "correlation_key": "vuln|ws|CVE-2026-48779|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-r6q2-hw4h-h46w", "level": "error", "message": {"text": "tar: GHSA-r6q2-hw4h-h46w"}, "properties": {"repobilityId": 223582, "scanner": "osv-scanner", "fingerprint": "a506cfec32bc23a52abb3358a13699dbb757b022e3c233283203353a8826b593", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-23950"], "package": "tar", "rule_id": "GHSA-r6q2-hw4h-h46w", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-23950|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-qffp-2rhf-9h96", "level": "error", "message": {"text": "tar: GHSA-qffp-2rhf-9h96"}, "properties": {"repobilityId": 223581, "scanner": "osv-scanner", "fingerprint": "f8fa987aa9acadbb491ed96885533ab55d2a0afc9f4623918e86fa3756ca851f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-29786"], "package": "tar", "rule_id": "GHSA-qffp-2rhf-9h96", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-29786|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-9ppj-qmqm-q256", "level": "error", "message": {"text": "tar: GHSA-9ppj-qmqm-q256"}, "properties": {"repobilityId": 223579, "scanner": "osv-scanner", "fingerprint": "69b2c0b2d95567c9d3ec0e13212c39d24902dceb82922feb24047ba7dfb846b6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-31802"], "package": "tar", "rule_id": "GHSA-9ppj-qmqm-q256", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-31802|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8qq5-rm4j-mr97", "level": "error", "message": {"text": "tar: GHSA-8qq5-rm4j-mr97"}, "properties": {"repobilityId": 223578, "scanner": "osv-scanner", "fingerprint": "4f89d9b810881688457b80c49ab868f006943a84374041c9ede83f89d8996e2f", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-23745"], "package": "tar", "rule_id": "GHSA-8qq5-rm4j-mr97", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-23745|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-83g3-92jg-28cx", "level": "error", "message": {"text": "tar: GHSA-83g3-92jg-28cx"}, "properties": {"repobilityId": 223577, "scanner": "osv-scanner", "fingerprint": "f024e3a8dade0f899aad4e013def341d786ed8b27d0ff31b6c56f7767e17e900", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-26960"], "package": "tar", "rule_id": "GHSA-83g3-92jg-28cx", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-26960|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-34x7-hfp2-rc4v", "level": "error", "message": {"text": "tar: GHSA-34x7-hfp2-rc4v"}, "properties": {"repobilityId": 223573, "scanner": "osv-scanner", "fingerprint": "b6245b99f855ef4f5327cea1040dc6abd2e19916475c6aa3696f274c7c921329", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-24842"], "package": "tar", "rule_id": "GHSA-34x7-hfp2-rc4v", "scanner": "osv-scanner", "correlation_key": "vuln|tar|CVE-2026-24842|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-c2c7-rcm5-vvqj", "level": "error", "message": {"text": "picomatch: GHSA-c2c7-rcm5-vvqj"}, "properties": {"repobilityId": 223544, "scanner": "osv-scanner", "fingerprint": "a3dd2390244022d96de63689cdd673fb906d1165f495d6a42a0980e956db632d", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-33671"], "package": "picomatch", "rule_id": "GHSA-c2c7-rcm5-vvqj", "scanner": "osv-scanner", "correlation_key": "vuln|picomatch|CVE-2026-33671|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-j3q9-mxjg-w52f", "level": "error", "message": {"text": "path-to-regexp: GHSA-j3q9-mxjg-w52f"}, "properties": {"repobilityId": 223540, "scanner": "osv-scanner", "fingerprint": "7430ad422b469928b240b563ae546401b374bbe16856d03d234e7895b9d8d7d3", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-4926"], "package": "path-to-regexp", "rule_id": "GHSA-j3q9-mxjg-w52f", "scanner": "osv-scanner", "correlation_key": "vuln|path-to-regexp|CVE-2026-4926|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7r86-cg39-jmmj", "level": "error", "message": {"text": "minimatch: GHSA-7r86-cg39-jmmj"}, "properties": {"repobilityId": 223532, "scanner": "osv-scanner", "fingerprint": "c3482c8b051b710219b686b962c8edfcc83babb0e1e54a2b470ae7782dd0b574", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27903"], "package": "minimatch", "rule_id": "GHSA-7r86-cg39-jmmj", "scanner": "osv-scanner", "correlation_key": "vuln|minimatch|CVE-2026-27903|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3ppc-4f35-3m26", "level": "error", "message": {"text": "minimatch: GHSA-3ppc-4f35-3m26"}, "properties": {"repobilityId": 223531, "scanner": "osv-scanner", "fingerprint": "2fd5e24a94dfd2116cfc5d9aeb4e4f584669c9b76d1795010331a7b69b3682a6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-26996"], "package": "minimatch", "rule_id": "GHSA-3ppc-4f35-3m26", "scanner": "osv-scanner", "correlation_key": "vuln|minimatch|CVE-2026-26996|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-23c5-xmqv-rm74", "level": "error", "message": {"text": "minimatch: GHSA-23c5-xmqv-rm74"}, "properties": {"repobilityId": 223530, "scanner": "osv-scanner", "fingerprint": "af7663e4c51288986bfb4927d06e33aa650fed364bb14d31804c3d4da5638193", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-27904"], "package": "minimatch", "rule_id": "GHSA-23c5-xmqv-rm74", "scanner": "osv-scanner", "correlation_key": "vuln|minimatch|CVE-2026-27904|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q5qw-h33p-qvwr", "level": "error", "message": {"text": "hono: GHSA-q5qw-h33p-qvwr"}, "properties": {"repobilityId": 223512, "scanner": "osv-scanner", "fingerprint": "5b1470b0861d3e120fa6219e303e8da9e819c78941c76e1925bf30e4cec648d1", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-29045"], "package": "hono", "rule_id": "GHSA-q5qw-h33p-qvwr", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-29045|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-f67f-6cw9-8mq4", "level": "error", "message": {"text": "hono: GHSA-f67f-6cw9-8mq4"}, "properties": {"repobilityId": 223497, "scanner": "osv-scanner", "fingerprint": "dd83c327b1ad810e0be3b07008d2da3729b0dff92af9fc72d7c0f0e1dfc78f75", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-22817"], "package": "hono", "rule_id": "GHSA-f67f-6cw9-8mq4", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-22817|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-3vhc-576x-3qv4", "level": "error", "message": {"text": "hono: GHSA-3vhc-576x-3qv4"}, "properties": {"repobilityId": 223486, "scanner": "osv-scanner", "fingerprint": "78b73c2bf9f83a5ee5940ba64a12db39b7eb93b2408c7c9c37c9a3cafe8d45ef", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-22818"], "package": "hono", "rule_id": "GHSA-3vhc-576x-3qv4", "scanner": "osv-scanner", "correlation_key": "vuln|hono|CVE-2026-22818|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-v39h-62p7-jpjc", "level": "error", "message": {"text": "fast-uri: GHSA-v39h-62p7-jpjc"}, "properties": {"repobilityId": 223472, "scanner": "osv-scanner", "fingerprint": "757ca37fe4ebddf5cdaa5c162265d6a31d93aef1fb513c46093294c58d5112ab", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-6322"], "package": "fast-uri", "rule_id": "GHSA-v39h-62p7-jpjc", "scanner": "osv-scanner", "correlation_key": "vuln|fast-uri|CVE-2026-6322|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q3j6-qgpj-74h6", "level": "error", "message": {"text": "fast-uri: GHSA-q3j6-qgpj-74h6"}, "properties": {"repobilityId": 223470, "scanner": "osv-scanner", "fingerprint": "25bb35258c39d7fb16dad079b84e7a9b4b5253e8dee49c1760d88494d1e449a6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-6321"], "package": "fast-uri", "rule_id": "GHSA-q3j6-qgpj-74h6", "scanner": "osv-scanner", "correlation_key": "vuln|fast-uri|CVE-2026-6321|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8r9q-7v3j-jr4g", "level": "error", "message": {"text": "@modelcontextprotocol/sdk: GHSA-8r9q-7v3j-jr4g"}, "properties": {"repobilityId": 223460, "scanner": "osv-scanner", "fingerprint": "739fd086f49d8e5846b9373e32f72a4ef98c1d467645ddb5fc621b0f99f39944", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-0621"], "package": "@modelcontextprotocol/sdk", "rule_id": "GHSA-8r9q-7v3j-jr4g", "scanner": "osv-scanner", "correlation_key": "vuln|modelcontextprotocol/sdk|CVE-2026-0621|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-345p-7cg4-v4c7", "level": "error", "message": {"text": "@modelcontextprotocol/sdk: GHSA-345p-7cg4-v4c7"}, "properties": {"repobilityId": 223458, "scanner": "osv-scanner", "fingerprint": "2668776d2d45fa4ecedace73bc83a4576f40f2aed9f57e0eca28d2663f3a751b", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-25536"], "package": "@modelcontextprotocol/sdk", "rule_id": "GHSA-345p-7cg4-v4c7", "scanner": "osv-scanner", "correlation_key": "vuln|modelcontextprotocol/sdk|CVE-2026-25536|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-7h2j-956f-4vf2", "level": "error", "message": {"text": "@isaacs/brace-expansion: GHSA-7h2j-956f-4vf2"}, "properties": {"repobilityId": 223457, "scanner": "osv-scanner", "fingerprint": "63eb410576f22db1a0dd24583d6ca991f153d5945b295fb1267361a0daa04b57", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-25547"], "package": "@isaacs/brace-expansion", "rule_id": "GHSA-7h2j-956f-4vf2", "scanner": "osv-scanner", "correlation_key": "vuln|isaacs/brace-expansion|CVE-2026-25547|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-wc8c-qw6v-h7f6", "level": "error", "message": {"text": "@hono/node-server: GHSA-wc8c-qw6v-h7f6"}, "properties": {"repobilityId": 223456, "scanner": "osv-scanner", "fingerprint": "775d923f133344f7cde205bcd6d6a950042712373e2d4fbe3e57bce0f541ac44", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-29087"], "package": "@hono/node-server", "rule_id": "GHSA-wc8c-qw6v-h7f6", "scanner": "osv-scanner", "correlation_key": "vuln|hono/node-server|CVE-2026-29087|pnpm-lock.yaml"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-q4gf-8mx6-v5v3", "level": "error", "message": {"text": "next: GHSA-q4gf-8mx6-v5v3"}, "properties": {"repobilityId": 223447, "scanner": "osv-scanner", "fingerprint": "da8b53df5895ed40a19febe52afb2d18a839dccf701e02fc3d50edf4d33cc0b0", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "next", "rule_id": "GHSA-q4gf-8mx6-v5v3", "scanner": "osv-scanner", "correlation_key": "vuln|next|GHSA-Q4GF-8MX6-V5V3|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-mg66-mrh9-m8jx", "level": "error", "message": {"text": "next: GHSA-mg66-mrh9-m8jx"}, "properties": {"repobilityId": 223442, "scanner": "osv-scanner", "fingerprint": "e1c0b57c4691bd55051dcc27f3ca4a26439aef2dc39ff13b828e829584b4a6ae", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44579"], "package": "next", "rule_id": "GHSA-mg66-mrh9-m8jx", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44579|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-h25m-26qc-wcjf", "level": "error", "message": {"text": "next: GHSA-h25m-26qc-wcjf"}, "properties": {"repobilityId": 223434, "scanner": "osv-scanner", "fingerprint": "3dca699f288814db9faa4c21ab6075f7191535c0a7d0a4bb007d3d11d095a448", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "next", "rule_id": "GHSA-h25m-26qc-wcjf", "scanner": "osv-scanner", "correlation_key": "vuln|next|GHSA-H25M-26QC-WCJF|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-c4j6-fc7j-m34r", "level": "error", "message": {"text": "next: GHSA-c4j6-fc7j-m34r"}, "properties": {"repobilityId": 223430, "scanner": "osv-scanner", "fingerprint": "0a54f4cd5b76bccd059af56553760a1f50a3286bc36bcaded036ef36ae7ec3e6", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44578"], "package": "next", "rule_id": "GHSA-c4j6-fc7j-m34r", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44578|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-8h8q-6873-q5fj", "level": "error", "message": {"text": "next: GHSA-8h8q-6873-q5fj"}, "properties": {"repobilityId": 223428, "scanner": "osv-scanner", "fingerprint": "1d6b5734f8709c48c82d64fd23dd05b727b7b6aec52424e0787cfb1086cb47b8", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "package": "next", "rule_id": "GHSA-8h8q-6873-q5fj", "scanner": "osv-scanner", "correlation_key": "vuln|next|GHSA-8H8Q-6873-Q5FJ|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-492v-c6pp-mqqv", "level": "error", "message": {"text": "next: GHSA-492v-c6pp-mqqv"}, "properties": {"repobilityId": 223424, "scanner": "osv-scanner", "fingerprint": "8c549cd0bcc75567b39779ee35dc1dbf7d32479989afbdeb6a44f75ca9ed5777", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44574"], "package": "next", "rule_id": "GHSA-492v-c6pp-mqqv", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44574|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-36qx-fr4f-26g5", "level": "error", "message": {"text": "next: GHSA-36qx-fr4f-26g5"}, "properties": {"repobilityId": 223394, "scanner": "osv-scanner", "fingerprint": "bb3fe10cb390a6ea557cd455f29985b3d1f2cb255161f44e9e0d26f9abaeeddc", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44573"], "package": "next", "rule_id": "GHSA-36qx-fr4f-26g5", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44573|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-26hh-7cqf-hhc6", "level": "error", "message": {"text": "next: GHSA-26hh-7cqf-hhc6"}, "properties": {"repobilityId": 223387, "scanner": "osv-scanner", "fingerprint": "3f81a2f571f36f0c5b9663a798ce9c1c12fa6b3ad5f35cd604e3d1c76ec2c5ce", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-45109"], "package": "next", "rule_id": "GHSA-26hh-7cqf-hhc6", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-45109|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "GHSA-267c-6grr-h53f", "level": "error", "message": {"text": "next: GHSA-267c-6grr-h53f"}, "properties": {"repobilityId": 223385, "scanner": "osv-scanner", "fingerprint": "db0a48544c830b2ce031153d65e173d9f13810926f1560b66b44efa2d72fece1", "category": "dependency", "severity": "high", "confidence": 0.88, "triageState": "open", "verdict": "", "isResolved": false, "reason": "", "evidence": {"match": "", "aliases": ["CVE-2026-44575"], "package": "next", "rule_id": "GHSA-267c-6grr-h53f", "scanner": "osv-scanner", "correlation_key": "vuln|next|CVE-2026-44575|package-lock.json"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "SEC029", "level": "error", "message": {"text": "[SEC029] Server-Side Request Forgery (SSRF) \u2014 outbound HTTP from user input: Outbound HTTP request to a user-controlled URL without allowlist validation. Attackers can probe internal services (169.254.169.254 metadata, internal Kubernetes endpoints, file:// URIs), exfiltrate data, or pivot through your network. SSRF is OWASP A10:2021 and a frequent foothold in cloud breaches."}, "properties": {"repobilityId": 223384, "scanner": "repobility-threat-engine", "fingerprint": "5553ee7f1cfc27490199c2de88c4092dc3932831bdbb682295b5b36f8aa07a8e", "category": "ssrf", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "new URL(\n    p", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC029", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|5553ee7f1cfc27490199c2de88c4092dc3932831bdbb682295b5b36f8aa07a8e"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/layout.tsx"}, "region": {"startLine": 25}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 223376, "scanner": "repobility-threat-engine", "fingerprint": "8f2c64d7c7bd14fde08696cd0c64e8e7ff633c0d3fb3d50a70fa5a86a5abb4cf", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "removingIds.current.delete(completedId);", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|8f2c64d7c7bd14fde08696cd0c64e8e7ff633c0d3fb3d50a70fa5a86a5abb4cf"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/flames/components/particles/FlameParticles.tsx"}, "region": {"startLine": 143}}}]}, {"ruleId": "SEC128", "level": "error", "message": {"text": "[SEC128] Async function without await \u2014 fire-and-forget Promise (AI mistake): Async call invoked without `await` returns an unhandled Promise. The outer function resolves before the inner work completes \u2014 DB writes lost, emails not sent, race conditions. This is one of the top-3 errors AI coders make: they understand async-shape but drop the await keyword when chaining multiple ops. Surfaces as flaky tests or silently dropped data in production."}, "properties": {"repobilityId": 223375, "scanner": "repobility-threat-engine", "fingerprint": "9cb0893e66432456a385f3d2461a1fce0013a75f97e35727e28299e6e3d403b4", "category": "quality", "severity": "high", "confidence": 1.0, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Pattern matched with no mitigating context found", "evidence": {"match": "targetsRef.current.delete(el);", "reason": "Pattern matched with no mitigating context found", "rule_id": "SEC128", "scanner": "repobility-threat-engine", "confidence": 1.0, "correlation_key": "fp|9cb0893e66432456a385f3d2461a1fce0013a75f97e35727e28299e6e3d403b4"}}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(app)/components/SparkFlyover.tsx"}, "region": {"startLine": 261}}}]}, {"ruleId": "scanner-ed87f19c8d35a1de", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 app/(app)/flames/page.tsx:14"}, "properties": {"repobilityId": "700b2cdaa61df02a", "scanner": "scanner-primary", "fingerprint": "ed87f19c8d35a1de", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-bcb83a2db0d1a6bf", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 app/(app)/flames/schedule/components/DayRow.tsx:122"}, "properties": {"repobilityId": "8ef53cca9877c647", "scanner": "scanner-primary", "fingerprint": "bcb83a2db0d1a6bf", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-ebbbefa71e8807ee", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(app)/flames/manage/components/ManageFlamesList.tsx:184"}, "properties": {"repobilityId": "e36e1414c81f7ffb", "scanner": "scanner-primary", "fingerprint": "ebbbefa71e8807ee", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c2d48f23299b005c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 app/(app)/components/ProfileBadge.tsx:209"}, "properties": {"repobilityId": "43b7f71a219aa115", "scanner": "scanner-primary", "fingerprint": "c2d48f23299b005c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-e0752433d3e01f58", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 app/(auth)/actions.ts:15"}, "properties": {"repobilityId": "c6242e2e638229e4", "scanner": "scanner-primary", "fingerprint": "e0752433d3e01f58", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-41fe6d19b1080c38", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 app/(marketing)/page.tsx:48"}, "properties": {"repobilityId": "81c689f157d1fab8", "scanner": "scanner-primary", "fingerprint": "41fe6d19b1080c38", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-e3d4230927f34c65", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in app/(marketing)/page.tsx:48"}, "properties": {"repobilityId": "c4d549f52dccdc8e", "scanner": "scanner-primary", "fingerprint": "e3d4230927f34c65", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/(marketing)/page.tsx"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-f8cdfffd70600cb1", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9d16476d98dbe2ef", "scanner": "scanner-primary", "fingerprint": "f8cdfffd70600cb1", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-f8cdfffd70600cb1", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0b96295926bb9236", "scanner": "scanner-primary", "fingerprint": "f8cdfffd70600cb1", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-f8cdfffd70600cb1", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0b96295926bb9236", "scanner": "scanner-primary", "fingerprint": "f8cdfffd70600cb1", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playwright.yml"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-b29822c26e17a384", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "063868470a9cbe05", "scanner": "scanner-primary", "fingerprint": "b29822c26e17a384", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/migrations-ci.yml"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-653563205380dba5", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6df0472a47975beb", "scanner": "scanner-primary", "fingerprint": "653563205380dba5", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/migrations-deploy.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-cb639d9a10a47b23", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "b86179956da3a4a8", "scanner": "scanner-primary", "fingerprint": "cb639d9a10a47b23", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "8f8f2b4a8e4e0295", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "5cff7383e47e1636", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "790164e916ec90d9", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "68e70ecb8c6df449", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "af72e8a03c21c979", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "69f590cf3ce0de4c", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-cc55229a7a3c078d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "properties": {"repobilityId": "51942fb3d5b8b5b4", "scanner": "scanner-primary", "fingerprint": "cc55229a7a3c078d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bea357a6497a2d5d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "properties": {"repobilityId": "aae72df3934829ac", "scanner": "scanner-primary", "fingerprint": "bea357a6497a2d5d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ba682c95f80fa405", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/agents/playwright-test-generator.md"}, "properties": {"repobilityId": "e66e201b10fb2935", "scanner": "scanner-primary", "fingerprint": "ba682c95f80fa405", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/playwright-test-generator.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dd114fe20b67675d", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/(app)/flames/components/CompletionSummaryModal.tsx:309"}, "properties": {"repobilityId": "124165bc6f9a426b", "scanner": "scanner-primary", "fingerprint": "dd114fe20b67675d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b783fa009ddbc192", "level": "none", "message": {"text": "Commented-code block (5 lines) in lib/supabase/proxy.ts:37"}, "properties": {"repobilityId": "5f3b0aa19bf72077", "scanner": "scanner-primary", "fingerprint": "b783fa009ddbc192", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}]}]}