{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-563106d063b43803", "name": "Possibly dead Python function: fmt_walk", "shortDescription": {"text": "Possibly dead Python function: fmt_walk"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e7918fd3cd1fe114", "name": "Insecure pattern 'cors_wildcard' in app/main.py:14", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in app/main.py:14"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a8009e85689448df", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/mylist.html:663", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/mylist.html:663"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-59f94eeae888bf52", "name": "Insecure pattern 'local_storage_auth_token' in app/static/login.html:422", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in app/static/login.html:422"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5834c7296da052c", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/auth.js:23", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/auth.js:23"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-554b736d45ab3938", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/index.html:147", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/index.html:147"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-968457bb8f8f7872", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/recommend.html:689", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/recommend.html:689"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1148c4350b29a7dd", "name": "Insecure pattern 'direct_outerhtml_assignment' in app/static/recommend.html:1019", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in app/static/recommend.html:1019"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4238f5596556bb33", "name": "Insecure pattern 'insert_adjacent_html' in app/static/recommend.html:1094", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in app/static/recommend.html:1094"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14dd7ecefd54d38d", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/detail.html:722", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/detail.html:722"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b968326cb28898c", "name": "Insecure pattern 'direct_outerhtml_assignment' in app/static/detail.html:969", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in app/static/detail.html:969"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89785d65b9200db9", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/reviews.html:396", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/reviews.html:396"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2a03ec1186a48a2", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/collections.js:202", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/collections.js:202"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6085fc8b3ef8a3e4", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/home.html:1086", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/home.html:1086"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d10a91e846b331e", "name": "Insecure pattern 'direct_outerhtml_assignment' in app/static/home.html:1175", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in app/static/home.html:1175"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-147449ced2ad9554", "name": "Insecure pattern 'local_storage_auth_token' in app/static/home.html:1201", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in app/static/home.html:1201"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-978ed38a03861084", "name": "Insecure pattern 'direct_innerhtml_assignment' in app/static/search.html:874", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/search.html:874"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 29 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 75 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-aaf2e95c5c869ed4", "name": "Commented-code block (8 lines) in app/services/data_service.py:84", "shortDescription": {"text": "Commented-code block (8 lines) in app/services/data_service.py:84"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/enrich_ratings.py:fetch_rating, scripts/enrich_naver.py:get_google_rating\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/enrich_ratings.py:enrich, scripts/enrich_walking.py:enrich, scripts/geocode.py:process\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c1e65f94574fa1e", "name": "FastAPI POST `refresh` without auth dependency \u2014 app/api/routes.py:50", "shortDescription": {"text": "FastAPI POST `refresh` without auth dependency \u2014 app/api/routes.py:50"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-305f9e37cc9725e4", "name": "FastAPI POST `google_login` without auth dependency \u2014 app/api/auth.py:67", "shortDescription": {"text": "FastAPI POST `google_login` without auth dependency \u2014 app/api/auth.py:67"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-678084c50acc238c", "name": "Dangling fetch: GET /api/reviews/mine (app/static/auth.js:92)", "shortDescription": {"text": "Dangling fetch: GET /api/reviews/mine (app/static/auth.js:92)"}, "fullDescription": {"text": "`app/static/auth.js:92` calls `GET /api/reviews/mine` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/reviews/mine`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c90cc709d66a312", "name": "Dangling fetch: DELETE /api/reviews/${id} (app/static/auth.js:137)", "shortDescription": {"text": "Dangling fetch: DELETE /api/reviews/${id} (app/static/auth.js:137)"}, "fullDescription": {"text": "`app/static/auth.js:137` calls `DELETE /api/reviews/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/reviews/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f606e6eee5ea91a", "name": "Dangling fetch: GET /api/auth/bookmarks (app/static/auth.js:168)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/bookmarks (app/static/auth.js:168)"}, "fullDescription": {"text": "`app/static/auth.js:168` calls `GET /api/auth/bookmarks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/bookmarks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1334d7d7de51ff1", "name": "Dangling fetch: POST /api/auth/bookmarks (app/static/auth.js:183)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/bookmarks (app/static/auth.js:183)"}, "fullDescription": {"text": "`app/static/auth.js:183` calls `POST /api/auth/bookmarks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/bookmarks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b48eef29c9ba5711", "name": "Dangling fetch: GET /api/auth/visited (app/static/auth.js:196)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/visited (app/static/auth.js:196)"}, "fullDescription": {"text": "`app/static/auth.js:196` calls `GET /api/auth/visited` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/visited`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-db7d878cf08a6a2c", "name": "Dangling fetch: POST /api/auth/visited (app/static/auth.js:211)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/visited (app/static/auth.js:211)"}, "fullDescription": {"text": "`app/static/auth.js:211` calls `POST /api/auth/visited` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/visited`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-589617eaf4595f88", "name": "Dangling fetch: GET /api/auth/collections (app/static/auth.js:225)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/collections (app/static/auth.js:225)"}, "fullDescription": {"text": "`app/static/auth.js:225` calls `GET /api/auth/collections` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/collections`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8bb338716abcbf51", "name": "Dangling fetch: POST /api/auth/collections (app/static/auth.js:240)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/collections (app/static/auth.js:240)"}, "fullDescription": {"text": "`app/static/auth.js:240` calls `POST /api/auth/collections` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/collections`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`app/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed0fe929c38b9a74", "name": "Unused endpoint: GET /home", "shortDescription": {"text": "Unused endpoint: GET /home"}, "fullDescription": {"text": "`app/main.py` declares `GET /home` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d16e4fa529c520e9", "name": "Unused endpoint: GET /search", "shortDescription": {"text": "Unused endpoint: GET /search"}, "fullDescription": {"text": "`app/main.py` declares `GET /search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3ef0da5b6adb169", "name": "Unused endpoint: GET /recommend", "shortDescription": {"text": "Unused endpoint: GET /recommend"}, "fullDescription": {"text": "`app/main.py` declares `GET /recommend` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82c4f50e801779fc", "name": "Unused endpoint: GET /mylist", "shortDescription": {"text": "Unused endpoint: GET /mylist"}, "fullDescription": {"text": "`app/main.py` declares `GET /mylist` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a4dfcad3eb1618a", "name": "Unused endpoint: GET /login", "shortDescription": {"text": "Unused endpoint: GET /login"}, "fullDescription": {"text": "`app/main.py` declares `GET /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a7c6163d28f6abb3", "name": "Unused endpoint: GET /detail", "shortDescription": {"text": "Unused endpoint: GET /detail"}, "fullDescription": {"text": "`app/main.py` declares `GET /detail` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81f27a6c6c707add", "name": "Unused endpoint: GET /reviews", "shortDescription": {"text": "Unused endpoint: GET /reviews"}, "fullDescription": {"text": "`app/main.py` declares `GET /reviews` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e33b225edfaec53", "name": "Unused endpoint: GET /food", "shortDescription": {"text": "Unused endpoint: GET /food"}, "fullDescription": {"text": "`app/api/routes.py` declares `GET /food` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e519f3447d35b1cd", "name": "Unused endpoint: GET /cafe", "shortDescription": {"text": "Unused endpoint: GET /cafe"}, "fullDescription": {"text": "`app/api/routes.py` declares `GET /cafe` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3de950d3ecada742", "name": "Unused endpoint: GET /survey", "shortDescription": {"text": "Unused endpoint: GET /survey"}, "fullDescription": {"text": "`app/api/routes.py` declares `GET /survey` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ce17d6b092a81ca", "name": "Unused endpoint: POST /refresh", "shortDescription": {"text": "Unused endpoint: POST /refresh"}, "fullDescription": {"text": "`app/api/routes.py` declares `POST /refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5887f6beb60dee57", "name": "Unused endpoint: POST /google", "shortDescription": {"text": "Unused endpoint: POST /google"}, "fullDescription": {"text": "`app/api/auth.py` declares `POST /google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3e6d08bc47e3a39", "name": "Unused endpoint: GET /bookmarks", "shortDescription": {"text": "Unused endpoint: GET /bookmarks"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /bookmarks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e0f776761091d17", "name": "Unused endpoint: POST /bookmarks", "shortDescription": {"text": "Unused endpoint: POST /bookmarks"}, "fullDescription": {"text": "`app/api/auth.py` declares `POST /bookmarks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f581378cec866ef", "name": "Unused endpoint: GET /visited", "shortDescription": {"text": "Unused endpoint: GET /visited"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /visited` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf7ad66a002ae4d6", "name": "Unused endpoint: POST /visited", "shortDescription": {"text": "Unused endpoint: POST /visited"}, "fullDescription": {"text": "`app/api/auth.py` declares `POST /visited` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d634056604698bd7", "name": "Unused endpoint: GET /collections", "shortDescription": {"text": "Unused endpoint: GET /collections"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /collections` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8eaf81f2b906c3c", "name": "Unused endpoint: POST /collections", "shortDescription": {"text": "Unused endpoint: POST /collections"}, "fullDescription": {"text": "`app/api/auth.py` declares `POST /collections` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43ef2b99d7bb4575", "name": "Unused endpoint: GET /google/url", "shortDescription": {"text": "Unused endpoint: GET /google/url"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /google/url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-424854ab10436e86", "name": "Unused endpoint: GET /google/callback", "shortDescription": {"text": "Unused endpoint: GET /google/callback"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0a4dcbf116199db", "name": "Unused endpoint: GET /kakao/url", "shortDescription": {"text": "Unused endpoint: GET /kakao/url"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /kakao/url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-695902336d75beb5", "name": "Unused endpoint: GET /kakao/callback", "shortDescription": {"text": "Unused endpoint: GET /kakao/callback"}, "fullDescription": {"text": "`app/api/auth.py` declares `GET /kakao/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8456eca76070a1a7", "name": "Unused endpoint: GET /mine", "shortDescription": {"text": "Unused endpoint: GET /mine"}, "fullDescription": {"text": "`app/api/reviews.py` declares `GET /mine` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`app/api/reviews.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-493a7d1ba7c0c000", "name": "Unused endpoint: DELETE /{review_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{review_id}"}, "fullDescription": {"text": "`app/api/reviews.py` declares `DELETE /{review_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18104"}, "properties": {"repository": "ribocomu-lab/bnu.zip", "repoUrl": "https://github.com/ribocomu-lab/bnu.zip", "branch": "main"}, "results": [{"ruleId": "scanner-563106d063b43803", "level": "note", "message": {"text": "Possibly dead Python function: fmt_walk"}, "properties": {"repobilityId": "fe55ded49a7b671e", "scanner": "scanner-primary", "fingerprint": "563106d063b43803", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/enrich_walking.py:36"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-e7918fd3cd1fe114", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in app/main.py:14"}, "properties": {"repobilityId": "6e34239fa74e6e6b", "scanner": "scanner-primary", "fingerprint": "e7918fd3cd1fe114", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/main.py"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-a8009e85689448df", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/mylist.html:663"}, "properties": {"repobilityId": "a8f61593dcd8e8e2", "scanner": "scanner-primary", "fingerprint": "a8009e85689448df", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/mylist.html"}, "region": {"startLine": 663}}}]}, {"ruleId": "scanner-59f94eeae888bf52", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in app/static/login.html:422"}, "properties": {"repobilityId": "cf75fdf411bd8f59", "scanner": "scanner-primary", "fingerprint": "59f94eeae888bf52", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/login.html"}, "region": {"startLine": 422}}}]}, {"ruleId": "scanner-f5834c7296da052c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/auth.js:23"}, "properties": {"repobilityId": "ef0316500e3d1f84", "scanner": "scanner-primary", "fingerprint": "f5834c7296da052c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/auth.js"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-554b736d45ab3938", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/index.html:147"}, "properties": {"repobilityId": "a97dfede071e5ef1", "scanner": "scanner-primary", "fingerprint": "554b736d45ab3938", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/index.html"}, "region": {"startLine": 147}}}]}, {"ruleId": "scanner-968457bb8f8f7872", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/recommend.html:689"}, "properties": {"repobilityId": "75af6f681656a2f4", "scanner": "scanner-primary", "fingerprint": "968457bb8f8f7872", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/recommend.html"}, "region": {"startLine": 689}}}]}, {"ruleId": "scanner-1148c4350b29a7dd", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in app/static/recommend.html:1019"}, "properties": {"repobilityId": "e419e7ae4be7768d", "scanner": "scanner-primary", "fingerprint": "1148c4350b29a7dd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/recommend.html"}, "region": {"startLine": 1019}}}]}, {"ruleId": "scanner-4238f5596556bb33", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in app/static/recommend.html:1094"}, "properties": {"repobilityId": "1b12a5c344f7eef0", "scanner": "scanner-primary", "fingerprint": "4238f5596556bb33", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/recommend.html"}, "region": {"startLine": 1094}}}]}, {"ruleId": "scanner-14dd7ecefd54d38d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/detail.html:722"}, "properties": {"repobilityId": "d6d15dafab759a77", "scanner": "scanner-primary", "fingerprint": "14dd7ecefd54d38d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/detail.html"}, "region": {"startLine": 722}}}]}, {"ruleId": "scanner-5b968326cb28898c", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in app/static/detail.html:969"}, "properties": {"repobilityId": "19219f50ba11863e", "scanner": "scanner-primary", "fingerprint": "5b968326cb28898c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/detail.html"}, "region": {"startLine": 969}}}]}, {"ruleId": "scanner-89785d65b9200db9", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/reviews.html:396"}, "properties": {"repobilityId": "823c6e1dc5557e1a", "scanner": "scanner-primary", "fingerprint": "89785d65b9200db9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/reviews.html"}, "region": {"startLine": 396}}}]}, {"ruleId": "scanner-a2a03ec1186a48a2", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/collections.js:202"}, "properties": {"repobilityId": "f19947c40852dbe9", "scanner": "scanner-primary", "fingerprint": "a2a03ec1186a48a2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/collections.js"}, "region": {"startLine": 202}}}]}, {"ruleId": "scanner-6085fc8b3ef8a3e4", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/home.html:1086"}, "properties": {"repobilityId": "a940c72859b52cb5", "scanner": "scanner-primary", "fingerprint": "6085fc8b3ef8a3e4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/home.html"}, "region": {"startLine": 1086}}}]}, {"ruleId": "scanner-8d10a91e846b331e", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in app/static/home.html:1175"}, "properties": {"repobilityId": "1504cdfa79bfba0d", "scanner": "scanner-primary", "fingerprint": "8d10a91e846b331e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/home.html"}, "region": {"startLine": 1175}}}]}, {"ruleId": "scanner-147449ced2ad9554", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in app/static/home.html:1201"}, "properties": {"repobilityId": "6498b7452d0a5886", "scanner": "scanner-primary", "fingerprint": "147449ced2ad9554", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/home.html"}, "region": {"startLine": 1201}}}]}, {"ruleId": "scanner-978ed38a03861084", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in app/static/search.html:874"}, "properties": {"repobilityId": "1a6d4609899696f7", "scanner": "scanner-primary", "fingerprint": "978ed38a03861084", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/static/search.html"}, "region": {"startLine": 874}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "bc5d2ebe65cfd7c6", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "6f3112186ca20da9", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "31c3c639a48653b9", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "e893bcb2cd37153f", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "df810b328389cb9f", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "f91e7853c6b76175", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-aaf2e95c5c869ed4", "level": "none", "message": {"text": "Commented-code block (8 lines) in app/services/data_service.py:84"}, "properties": {"repobilityId": "2960b644051ae9be", "scanner": "scanner-primary", "fingerprint": "aaf2e95c5c869ed4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "e9c99cabf02413ca", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "eac6d173f9f3876b", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "3e9fe0873e3fe83a", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-9c1e65f94574fa1e", "level": "error", "message": {"text": "FastAPI POST `refresh` without auth dependency \u2014 app/api/routes.py:50"}, "properties": {"repobilityId": "d8d429705c96ed64", "scanner": "scanner-primary", "fingerprint": "9c1e65f94574fa1e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/api/routes.py"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-305f9e37cc9725e4", "level": "error", "message": {"text": "FastAPI POST `google_login` without auth dependency \u2014 app/api/auth.py:67"}, "properties": {"repobilityId": "933dafe9c703795e", "scanner": "scanner-primary", "fingerprint": "305f9e37cc9725e4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/api/auth.py"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-678084c50acc238c", "level": "error", "message": {"text": "Dangling fetch: GET /api/reviews/mine (app/static/auth.js:92)"}, "properties": {"repobilityId": "4c9404979a5981d5", "scanner": "scanner-primary", "fingerprint": "678084c50acc238c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4c90cc709d66a312", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/reviews/${id} (app/static/auth.js:137)"}, "properties": {"repobilityId": "d13d3b271417921e", "scanner": "scanner-primary", "fingerprint": "4c90cc709d66a312", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6f606e6eee5ea91a", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/bookmarks (app/static/auth.js:168)"}, "properties": {"repobilityId": "d8c408c13a5a9fa5", "scanner": "scanner-primary", "fingerprint": "6f606e6eee5ea91a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c1334d7d7de51ff1", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/bookmarks (app/static/auth.js:183)"}, "properties": {"repobilityId": "5ef073b941d3904e", "scanner": "scanner-primary", "fingerprint": "c1334d7d7de51ff1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b48eef29c9ba5711", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/visited (app/static/auth.js:196)"}, "properties": {"repobilityId": "461642fabf31469b", "scanner": "scanner-primary", "fingerprint": "b48eef29c9ba5711", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-db7d878cf08a6a2c", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/visited (app/static/auth.js:211)"}, "properties": {"repobilityId": "740fbccf6032c8da", "scanner": "scanner-primary", "fingerprint": "db7d878cf08a6a2c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-589617eaf4595f88", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/collections (app/static/auth.js:225)"}, "properties": {"repobilityId": "b9b9b62baf82a24b", "scanner": "scanner-primary", "fingerprint": "589617eaf4595f88", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8bb338716abcbf51", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/collections (app/static/auth.js:240)"}, "properties": {"repobilityId": "f6a46a4c3f7148a6", "scanner": "scanner-primary", "fingerprint": "8bb338716abcbf51", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "d8721f71fae1e2af", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed0fe929c38b9a74", "level": "note", "message": {"text": "Unused endpoint: GET /home"}, "properties": {"repobilityId": "32780fe4df11fb62", "scanner": "scanner-primary", "fingerprint": "ed0fe929c38b9a74", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d16e4fa529c520e9", "level": "note", "message": {"text": "Unused endpoint: GET /search"}, "properties": {"repobilityId": "d32b5568e3d06b41", "scanner": "scanner-primary", "fingerprint": "d16e4fa529c520e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3ef0da5b6adb169", "level": "note", "message": {"text": "Unused endpoint: GET /recommend"}, "properties": {"repobilityId": "aa65a36fdc50fb82", "scanner": "scanner-primary", "fingerprint": "d3ef0da5b6adb169", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-82c4f50e801779fc", "level": "note", "message": {"text": "Unused endpoint: GET /mylist"}, "properties": {"repobilityId": "84476ee9355e9a69", "scanner": "scanner-primary", "fingerprint": "82c4f50e801779fc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6a4dfcad3eb1618a", "level": "note", "message": {"text": "Unused endpoint: GET /login"}, "properties": {"repobilityId": "d1272a99e52060cc", "scanner": "scanner-primary", "fingerprint": "6a4dfcad3eb1618a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a7c6163d28f6abb3", "level": "note", "message": {"text": "Unused endpoint: GET /detail"}, "properties": {"repobilityId": "6c6a9315508b7caf", "scanner": "scanner-primary", "fingerprint": "a7c6163d28f6abb3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-81f27a6c6c707add", "level": "note", "message": {"text": "Unused endpoint: GET /reviews"}, "properties": {"repobilityId": "1cc8c223147df090", "scanner": "scanner-primary", "fingerprint": "81f27a6c6c707add", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9e33b225edfaec53", "level": "note", "message": {"text": "Unused endpoint: GET /food"}, "properties": {"repobilityId": "2411bbc51b82ac97", "scanner": "scanner-primary", "fingerprint": "9e33b225edfaec53", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e519f3447d35b1cd", "level": "note", "message": {"text": "Unused endpoint: GET /cafe"}, "properties": {"repobilityId": "d1519181df5bf917", "scanner": "scanner-primary", "fingerprint": "e519f3447d35b1cd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3de950d3ecada742", "level": "note", "message": {"text": "Unused endpoint: GET /survey"}, "properties": {"repobilityId": "8dff3da1c7d5bb27", "scanner": "scanner-primary", "fingerprint": "3de950d3ecada742", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ce17d6b092a81ca", "level": "note", "message": {"text": "Unused endpoint: POST /refresh"}, "properties": {"repobilityId": "4ad11aa1c40e05a8", "scanner": "scanner-primary", "fingerprint": "7ce17d6b092a81ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5887f6beb60dee57", "level": "note", "message": {"text": "Unused endpoint: POST /google"}, "properties": {"repobilityId": "53a649e3136fe1b3", "scanner": "scanner-primary", "fingerprint": "5887f6beb60dee57", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "e2e206828c3a9472", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f3e6d08bc47e3a39", "level": "note", "message": {"text": "Unused endpoint: GET /bookmarks"}, "properties": {"repobilityId": "68f5e557dd1a3cb0", "scanner": "scanner-primary", "fingerprint": "f3e6d08bc47e3a39", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e0f776761091d17", "level": "note", "message": {"text": "Unused endpoint: POST /bookmarks"}, "properties": {"repobilityId": "3e7f30d64f147ad4", "scanner": "scanner-primary", "fingerprint": "5e0f776761091d17", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1f581378cec866ef", "level": "note", "message": {"text": "Unused endpoint: GET /visited"}, "properties": {"repobilityId": "0a5d7c2a27c4900a", "scanner": "scanner-primary", "fingerprint": "1f581378cec866ef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bf7ad66a002ae4d6", "level": "note", "message": {"text": "Unused endpoint: POST /visited"}, "properties": {"repobilityId": "e38ee46c92080428", "scanner": "scanner-primary", "fingerprint": "bf7ad66a002ae4d6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d634056604698bd7", "level": "note", "message": {"text": "Unused endpoint: GET /collections"}, "properties": {"repobilityId": "1ff30711a840b686", "scanner": "scanner-primary", "fingerprint": "d634056604698bd7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8eaf81f2b906c3c", "level": "note", "message": {"text": "Unused endpoint: POST /collections"}, "properties": {"repobilityId": "6260fa7ccde79969", "scanner": "scanner-primary", "fingerprint": "f8eaf81f2b906c3c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43ef2b99d7bb4575", "level": "note", "message": {"text": "Unused endpoint: GET /google/url"}, "properties": {"repobilityId": "ae2b6d24fce61c95", "scanner": "scanner-primary", "fingerprint": "43ef2b99d7bb4575", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-424854ab10436e86", "level": "note", "message": {"text": "Unused endpoint: GET /google/callback"}, "properties": {"repobilityId": "74f7689196641a4f", "scanner": "scanner-primary", "fingerprint": "424854ab10436e86", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c0a4dcbf116199db", "level": "note", "message": {"text": "Unused endpoint: GET /kakao/url"}, "properties": {"repobilityId": "6f7d5779b4f2acc9", "scanner": "scanner-primary", "fingerprint": "c0a4dcbf116199db", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-695902336d75beb5", "level": "note", "message": {"text": "Unused endpoint: GET /kakao/callback"}, "properties": {"repobilityId": "118d52c39dabeefa", "scanner": "scanner-primary", "fingerprint": "695902336d75beb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8456eca76070a1a7", "level": "note", "message": {"text": "Unused endpoint: GET /mine"}, "properties": {"repobilityId": "04cddb63fd1682d7", "scanner": "scanner-primary", "fingerprint": "8456eca76070a1a7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "b173d6b6464d81f6", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-493a7d1ba7c0c000", "level": "note", "message": {"text": "Unused endpoint: DELETE /{review_id}"}, "properties": {"repobilityId": "49270f0156135b22", "scanner": "scanner-primary", "fingerprint": "493a7d1ba7c0c000", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}