{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-2918b141b6c3a94b", "name": "TODO/FIXME marker in shipping code \u2014 tests/frontend/MacroParser.e2e.js:313", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 tests/frontend/MacroParser.e2e.js:313"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-4fd89cf0d6379f5c", "name": "TODO/FIXME marker in shipping code \u2014 tests/frontend/MacroLexer.e2e.js:510", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 tests/frontend/MacroLexer.e2e.js:510"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-71aeed7ec59d7080", "name": "TODO/FIXME marker in shipping code \u2014 public/script.js:2411", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/script.js:2411"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-d6969ae2d61fa40d", "name": "Debug `console.log` remains in browser-facing code \u2014 public/script.js:4117", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 public/script.js:4117"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0313d3f8b1568664", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/itemized-prompts.js:122", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/itemized-prompts.js:122"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-e861afd764a2341f", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/power-user.js:1942", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/power-user.js:1942"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-572c2607fc49fe8c", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/macros.js:745", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/macros.js:745"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-5c1c96c4a8f407b3", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/events.js:20", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/events.js:20"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-3cab0c32a2c0cf42", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/world-info.js:955", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/world-info.js:955"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-6ef2579b3c5049b7", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/slash-commands.js:4692", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/slash-commands.js:4692"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-8a5af97b14c96574", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/PromptManager.js:1138", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/PromptManager.js:1138"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-b00ddfad23c60df5", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/textgen-models.js:1013", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/textgen-models.js:1013"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f409e0c8d6e1a287", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/instruct-mode.js:491", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/instruct-mode.js:491"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-382948e05b522ae8", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/cfg-scale.js:113", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/cfg-scale.js:113"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ce11e20fdcad2570", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/personas.js:1021", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/personas.js:1021"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-5d6168723359c307", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/authors-note.js:605", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/authors-note.js:605"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ed417964809f3c84", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/openai.js:2632", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/openai.js:2632"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-3d8ddeee40b3130d", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions.js:2281", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions.js:2281"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f32318d63aa662c6", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/slash-commands/SlashCommandParser.js:197", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/slash-commands/SlashCommandParser.js:197"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-e9eb420471bf85f2", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/util/stream-fadein.js:24", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/util/stream-fadein.js:24"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-866e0b1664e35347", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/autocomplete/AutoComplete.js:277", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/autocomplete/AutoComplete.js:277"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-27259a777890bd94", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/macros/definitions/core-macros.js:367", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/macros/definitions/core-macros.js:367"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-411ac99b9d2853b7", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/tts/pollinations.js:12", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/tts/pollinations.js:12"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-28f7a54eef335c8d", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/tts/coqui.js:245", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/tts/coqui.js:245"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-040b44a8cfe27703", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/regex/index.js:1373", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/regex/index.js:1373"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-c89dbdfaa563b7d5", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/memory/index.js:1126", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/memory/index.js:1126"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-363e8c66f432e726", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/quick-reply/src/QuickReply.js:290", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/quick-reply/src/QuickReply.js:290"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f236434c49760fa2", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/quick-reply/src/ui/SettingsUi.js:310", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/quick-reply/src/ui/SettingsUi.js:310"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-c55108a5953fcd79", "name": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/stable-diffusion/index.js:3942", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/stable-diffusion/index.js:3942"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f449aafe021e47aa", "name": "Debug `console.log` remains in browser-facing code \u2014 public/lib/toastr.min.js:6", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 public/lib/toastr.min.js:6"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-abbbf23076a672d6", "name": "Debug `console.log` remains in browser-facing code \u2014 public/lib/epub.min.js:1", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 public/lib/epub.min.js:1"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-307fb1307a9578b6", "name": "TODO/FIXME marker in shipping code \u2014 public/lib/dialog-polyfill.esm.js:132", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 public/lib/dialog-polyfill.esm.js:132"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-37148ca29593e1b6", "name": "TODO/FIXME marker in shipping code \u2014 src/server-main.js:368", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/server-main.js:368"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-86a7c45d4dd95199", "name": "TODO/FIXME marker in shipping code \u2014 src/constants.js:221", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/constants.js:221"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-558750ddf501aa27", "name": "TODO/FIXME marker in shipping code \u2014 src/endpoints/search.js:370", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/endpoints/search.js:370"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ab106d9c86a935df", "name": "TODO/FIXME marker in shipping code \u2014 src/endpoints/backends/chat-completions.js:772", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/endpoints/backends/chat-completions.js:772"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-6ff786ea1e993a28", "name": "unquoted attribute var \u2014 public/scripts/extensions/connection-manager/edit.html:6", "shortDescription": {"text": "unquoted attribute var \u2014 public/scripts/extensions/connection-manager/edit.html:6"}, "fullDescription": {"text": "Detected a unquoted template variable as an attribute. If unquoted, a malicious actor could inject custom JavaScript handlers. To fix this, add quotes around the template expression, like this: \"{{ expr }}\".\n\nRule: generic.html-templates.security.unquoted-attribute-var.unquoted-attribute-var\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.55}}, {"id": "scanner-d0f3a6624ab9e7e7", "name": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: @protobufjs/utf8\nInstalled: 1.1.0\nFixed in: 1.1.1\nSeverity: MEDIUM\nFix: Upgrade @protobufjs/utf8 to 1.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ed62e18b85d56ac", "name": "CVE-2026-44486: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44486: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via HTTP redirects\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019 Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. T\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-61dd25804f1550ff", "name": "CVE-2026-44487: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44487: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure of proxy credentials via redirect flows\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios\u2019s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was in\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d982114f0172043", "name": "CVE-2026-44488: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44488: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Denial of Service due to unenforced request and response size limits\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usag\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5479a2218c7e0b2a", "name": "CVE-2026-44492: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44492: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vuln\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e135324a6015c309", "name": "CVE-2026-44494: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44494: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack \u2014 intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, whic\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e9cc3c301e071e86", "name": "CVE-2026-44496: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44496: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name\n\nAxios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0, 0.32.0\nSeverity: HIGH\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d091e23f5e160179", "name": "GHSA-gcfj-64vw-6mp9: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-gcfj-64vw-6mp9: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning\n\n## Summary\n\nAxios\u2019 Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and request configuration is materialized as a regular object before dispatch.\n\nRecent axios releases harden merged request config by creating a null-prototype object. However, request interceptors run after that merge and may return a replacement config. A common immutable interceptor pattern such as `{...config}` or `Object.assign({}, config)` converts the h\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 0.33.0, 1.18.0\nSeverity: HIGH\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-78d2f0d242b01650", "name": "CVE-2026-44490: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44490: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure and denial of service due to prototype pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the mer\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0, 0.32.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.16.0, 0.32.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42fd6e6e830e6582", "name": "GHSA-42h9-826w-cgv3: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-42h9-826w-cgv3: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: Excessive recursion in formDataToJSON can cause denial of service\n\n## Summary\nAxios versions `0.28.0` and later contain uncontrolled recursion in `formDataToJSON`, the helper behind the public `axios.formToJSON()` / named `formToJSON` API and the default request transform used when FormData is sent with an `application/json` content type.\n\nApplications are affected when they pass attacker-controlled `FormData` field names into this functionality. A field name with thousands of nested bracket segments can exhaust the JavaScript call stack and throw `RangeError: \n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a59fccd12f0837b", "name": "GHSA-7q8q-rj6j-mhjq: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: Nested axios option objects can consume polluted prototype values\n\n## Summary\n\nAxios can consume inherited properties from nested request option objects when the JavaScript process already has a polluted `Object.prototype`.\n\nThe top-level merged config is protected with a null prototype, but nested plain objects such as `auth` and `paramsSerializer` are cloned into ordinary objects. If application code passes placeholders such as `auth: {}` or `paramsSerializer: {}`, inherited `username`, `password`, `encode`, or `serialize` properties can influence outbound re\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b00be6728d44c9ee", "name": "GHSA-f4gw-2p7v-4548: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-f4gw-2p7v-4548: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios\n\n## Summary\n\nAxios versions containing `lib/helpers/shouldBypassProxy.js` do not treat `0.0.0.0` as a local address when evaluating `NO_PROXY` rules. In Node.js applications that use `HTTP_PROXY` or `HTTPS_PROXY` together with `NO_PROXY=localhost,127.0.0.1,::1` or similar, a request to `http://0.0.0.0:<port>/` can be routed through the configured proxy instead of bypassing it.\n\nThe issue is exploitable when an attacker can influence the axios request URL or a followed redirect target, and when th\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65103a713c87b1c5", "name": "GHSA-hcpx-6fm6-wx23: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-hcpx-6fm6-wx23: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios form serializer maxDepth bypass via {} metatoken\n\n## Summary\n\nAxios versions in the fixed lines for GHSA-62hf-57xw-28j9 still contain an incomplete depth-limit bypass in `lib/helpers/toFormData.js`. When serializing an object with a top-level key ending in `{}`, axios calls `JSON.stringify()` on that value before the `formSerializer.maxDepth` guard can inspect the nested structure.\n\nAn attacker who can control object keys and nested values passed by an application into axios form or parameter serialization can trigger a raw `RangeError: Maximum\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-850b1e79fefb4d95", "name": "GHSA-jqh4-m9w3-8hp9: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`\n\n## Summary\n\naxios\u2019 fetch adapter does not enforce `maxBodyLength` for live WHATWG `ReadableStream` request bodies whose size cannot be determined before dispatch. Applications that use `adapter: \"fetch\"` and rely on `maxBodyLength` to cap untrusted upload/proxy streams can send the full stream even when it exceeds the configured limit.\n\nThis affects fetch-adapter usage in edge runtimes where fetch is selected, and in Node.js or browser environments where the fetch adapter is explicitly selected.\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6339a926059b783", "name": "GHSA-mmx7-hfxf-jppx: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: Prototype pollution gadgets can alter axios request construction\n\n## Summary\n\naxios is vulnerable to read-side prototype-pollution gadgets when `Object.prototype` has already been polluted by another vulnerability or dependency. The most broadly reachable issue is in the bodyless method aliases: `axios.get()`, `axios.delete()`, `axios.head()`, and `axios.options()` read inherited `data` before config normalization, causing attacker-controlled body data to be sent on requests that did not explicitly set a body.\n\nAdditional low-level paths affect consumers that \n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.18.0, 0.33.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0, 0.33.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-75b167f9b67ee705", "name": "GHSA-mwf2-3pr3-8698: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-mwf2-3pr3-8698: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: HTTP/2 streamed uploads bypass `maxBodyLength`\n\n## Summary\n\nAxios versions with Node.js HTTP/2 support allow streamed request bodies to bypass `maxBodyLength` enforcement when requests are sent with `httpVersion: 2`.\n\nThis affects applications that rely on `maxBodyLength` as a hard cap while forwarding attacker-controlled streams, such as upload endpoints proxying user data to an upstream HTTP/2 service. Buffered request bodies are still checked before the request is sent.\n\n## Impact\n\nAn attacker who can control a stream passed to axios can c\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f7fb47273149cc6", "name": "GHSA-pmv8-rq9r-6j72: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: Deep formToJSON Key Recursion Can Cause Denial of Service\n\n## Summary\n\nAxios versions starting with `0.28.0` contain uncontrolled recursion in `formDataToJSON`, which is exposed as `axios.formToJSON()` and used internally when axios serialises `FormData` with `Content-Type: application/json`.\n\nIf an application passes attacker-controlled `FormData` field names to this functionality, a field name with thousands of nested bracket segments can exhaust the JavaScript call stack and cause denial of service for that request or, in applications without appropr\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 0.33.0, 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 0.33.0, 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb4818328e2c81e7", "name": "GHSA-xj6q-8x83-jv6g: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-xj6q-8x83-jv6g: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "Axios: Prototype pollution auth subfields can inject Basic auth\n\n## Summary\n\nAxios versions after the `GHSA-q8qp-cvcw-x6jj` fix still contain prototype-pollution read-side gadgets in Basic auth subfield handling. If a host application is already affected by prototype pollution and then makes an axios request with an own `auth` object that omits `username` or `password`, axios reads inherited `Object.prototype.username` and `Object.prototype.password` values and uses them to construct an outbound `Authorization: Basic ...` header.\n\nThis does not mean axios its\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.18.0\nSeverity: MEDIUM\nFix: Upgrade axios to 1.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d76402dfaa4deebc", "name": "CVE-2026-44489: axios 1.15.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44489: axios 1.15.2 \u2014 package-lock.json"}, "fullDescription": {"text": "axios: Axios: Information disclosure via Prototype Pollution\n\nAxios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.username, proxy.password, and proxy.auth without hasOwnProperty checks. When Object.prototype.username is polluted, setProxy() constructs a Proxy-Authorization header with attacker-controlled credentials\n\nPackage: axios\nInstalled: 1.15.2\nFixed in: 1.16.0\nSeverity: LOW\nFix: Upgrade axios to 1.16.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4584e5503768a719", "name": "CVE-2026-12590: body-parser 1.20.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 package-lock.json"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 1.20.4\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2323def9108d33da", "name": "CVE-2026-13149: brace-expansion 2.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 2.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 2.1.0\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5e05ea97a125c972", "name": "CVE-2026-14257: brace-expansion 2.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-14257: brace-expansion 2.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "brace-expansion through 5.0.7 is vulnerable to denial of service via m ...\n\nbrace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of i\n\nPackage: brace-expansion\nInstalled: 2.1.0\nFixed in: 5.0.8\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e556a14b2f71fdd9", "name": "CVE-2026-49458: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-49458: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting due to improper sanitization of DOM nodes\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DOM nodes while follow-on checks used parent-realm constructors, causing instanceof checks for forms, named node maps, document fragments, and elements to fail and skip clobber, template-content, and shadow-DOM sanitization branches so executable markup could survive. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-07ebf19b8a7f09f9", "name": "CVE-2026-49459: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-49459: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting bypass allows arbitrary script execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could preserve event-handler attributes on an attacker-controlled <form> root when a descendant name clobbered properties checked by _isClobbered, because _forceRemove no-opped on the parent-less root and _sanitizeAttributes returned early. This issue is fixed in version 3.4.6.\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.6\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fc0ae253213e444", "name": "CVE-2026-49978: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-49978: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution\n\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.7, DOMPurify IN_PLACE sanitization could skip shadow contents attached to an element inside <template>.content, allowing attacker-controlled markup such as event handlers, JavaScript URLs, or scripts to survive and execute when an application cloned and inserted the sanitized template. This issue is fixed in version 3.4.7.\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d4c8406978feb84d", "name": "CVE-2026-65898: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-65898: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when ...\n\nDOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS.\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.11\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.11"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74534431657a4599", "name": "CVE-2026-65902: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-65902: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct refe ...\n\nDOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS and DEFAULT_ALLOWED_ATTR sets to the uponSanitizeElement and uponSanitizeAttribute hooks via data.allowedTags / data.allowedAttributes when sanitize is called without an explicit cfg.ALLOWED_TAGS / cfg.ALLOWED_ATTR array. A hook that mutates these fields permanently widens the default allow-lists for the lifetime of the DOMPurify instance, so all subsequent default-config sanitiz\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.7\nSeverity: MEDIUM\nFix: Upgrade dompurify to 3.4.7"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0894aba2c3f41dbb", "name": "CVE-2026-65899: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-65899: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types ...\n\nDOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a previously supplied TRUSTED_TYPES_POLICY. A later caller that requests RETURN_TRUSTED_TYPE output receives a TrustedHTML object created by the old (potentially unsafe) policy rather than a clean default, which can lead to script execution at a Trusted Types sink. Passing TRUSTED_TYPES_POLICY: null on the later call als\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.9\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.9"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a99523bad6d0da0", "name": "CVE-2026-65900: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-65900: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE ...\n\nDOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub pass (_scrubTemplateExpressions) uses a NodeIterator and node.normalize() that do not descend into template.content, so expressions that only form after adjacent text nodes merge survive sanitization.\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.8\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fa4a6f3ffd21ef0", "name": "CVE-2026-65901: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-65901: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "DOMPurify through 3.4.6 contains a cross-site scripting vulnerability  ...\n\nDOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causing scripts to execute when the sanitized tree is inserted into a live document.\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01f6de830a4b100c", "name": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.2 \u2014 package-lock.json", "shortDescription": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.2 \u2014 package-lock.json"}, "fullDescription": {"text": "DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\n## Summary\n\nThere is a possible hook-policy inconsistency in DOMPurify 3.4.11 involving `CUSTOM_ELEMENT_HANDLING`.\n\nWhen a custom element is allowed via `CUSTOM_ELEMENT_HANDLING.tagNameCheck`, it appears that the element does not go through `afterSanitizeElements` in the same way as a normal element. As a result, an application that relies on `afterSanitizeElements` as a security policy layer to strip sensitive attributes from all elements may see those attributes removed from normal elements bu\n\nPackage: dompurify\nInstalled: 3.4.2\nFixed in: 3.4.12\nSeverity: LOW\nFix: Upgrade dompurify to 3.4.12"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4adf6d36ffd584f8", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bf5bc3c980b78418", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-795a1c1a931b0551", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cf47d36fffbc9566", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ad924ae57f20cce", "name": "CVE-2026-31808: file-type 16.5.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-31808: file-type 16.5.4 \u2014 package-lock.json"}, "fullDescription": {"text": "file-type: file-type: Denial of Service due to infinite loop in ASF file parsing\n\nfile-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a size field of zero, the parser enters an infinite loop. The payload value becomes negative (-24), causing tokenizer.ignore(payload) to move the read position backwards, so the same sub-header is read repeatedly forever. Any application that uses file-type to detect the type\n\nPackage: file-type\nInstalled: 16.5.4\nFixed in: 21.3.1\nSeverity: MEDIUM\nFix: Upgrade file-type to 21.3.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eab1e85fb715d773", "name": "CVE-2026-12143: form-data 4.0.5 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 package-lock.json"}, "fullDescription": {"text": "form-data: form-data: Form field override via CRLF injection\n\nform-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the atta\n\nPackage: form-data\nInstalled: 4.0.5\nFixed in: 2.5.6, 3.0.5, 4.0.6\nSeverity: HIGH\nFix: Upgrade form-data to 2.5.6, 3.0.5, 4.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4d821f6f21084ff1", "name": "CVE-2026-42338: ip-address 9.0.5 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-42338: ip-address 9.0.5 \u2014 package-lock.json"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 9.0.5\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9b3eec5255d3fc1", "name": "CVE-2026-4800: lodash-es 4.17.23 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 package-lock.json"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-941ed3f6c02743e5", "name": "CVE-2026-2950: lodash-es 4.17.23 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 package-lock.json"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.23\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eac9e36649ceed78", "name": "CVE-2026-5079: multer 2.1.1 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-5079: multer 2.1.1 \u2014 package-lock.json"}, "fullDescription": {"text": "multer: Multer: Denial of Service via deeply nested field names in multipart form data\n\nImpact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multipart body is sufficient to exploit this.\n\nPatches: Users should upgrade to multer 2.2.0 (2.x line) o\n\nPackage: multer\nInstalled: 2.1.1\nFixed in: 2.2.0, 3.0.0-alpha.2\nSeverity: HIGH\nFix: Upgrade multer to 2.2.0, 3.0.0-alpha.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9dac0055dc63b735", "name": "CVE-2026-5038: multer 2.1.1 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-5038: multer 2.1.1 \u2014 package-lock.json"}, "fullDescription": {"text": "multer: Multer: Denial of Service via aborted or malformed multipart uploads\n\nImpact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave orphaned partial files on disk because the Readable.pipe() call does not propagate the stream destroy signal to \nthe underlying fs.WriteStream. An attacker can exhaust disk space by triggering many aborted uploads, with no application bug required.\n\nPatches: Users should upgrade to multer 2.2.0 (2.x line) or 3.0.0-alpha.2\n\nPackage: multer\nInstalled: 2.1.1\nFixed in: 2.2.0, 3.0.0-alpha.2\nSeverity: MEDIUM\nFix: Upgrade multer to 2.2.0, 3.0.0-alpha.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd5a75413103f67a", "name": "CVE-2026-41242: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-41242: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the \"type\" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 8.0.1, 7.5.5\nSeverity: CRITICAL\nFix: Upgrade protobufjs to 8.0.1, 7.5.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-97dc43230b30fb1b", "name": "CVE-2026-44289: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44289: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields. A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41386cd14033e7a0", "name": "CVE-2026-44290: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44290: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in functionality. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4e723f0f1b7ec96", "name": "CVE-2026-44291: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44291: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript code. This vulnerabilit\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b8857ba08f5e49a", "name": "CVE-2026-44293: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44293: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ca5ad009d815e919", "name": "CVE-2026-48712: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-48712: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.6.1, 8.4.1\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.6.1, 8.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2815a2c45be1156", "name": "CVE-2026-44288: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44288: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Security control bypass due to improper handling of overlong UTF-8 sequences\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them. An attacker who can provide protobuf binary data decoded through the affected UTF-8 path may be able to bypass application-level checks that inspect raw bytes before protobuf string decoding. For example, bytes that do not contain certain \n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-178802405f548bd2", "name": "CVE-2026-44292: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44292: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Data integrity impact due to prototype pollution\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the __proto__ key. If an application constructed a message from an attacker-controlled plain object, an own enumerable __proto__ property could alter the prototype of that individual message instance. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73654be544eed6ae", "name": "CVE-2026-44294: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-44294: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service due to unescaped control characters in field names\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted schema or JSON descriptor could therefore cause generated encode, decode, verify, or conversion functions to fail during compilation. This vulnerability is fixed in 7.5.6 and 8.0.2.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.6, 8.0.2\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.6, 8.0.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2b436fd91c94abbc", "name": "CVE-2026-45740: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-45740: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted JSON descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.5.8, 8.2.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.8, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5c6f77d9c843c9a", "name": "CVE-2026-54269: protobufjs 6.11.4 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-54269: protobufjs 6.11.4 \u2014 package-lock.json"}, "fullDescription": {"text": "protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could r\n\nPackage: protobufjs\nInstalled: 6.11.4\nFixed in: 7.6.3, 8.6.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.3, 8.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1c0cee138df7df1", "name": "CVE-2026-8723: qs 6.14.2 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 package-lock.json"}, "fullDescription": {"text": "### Summary    `qs.stringify` throws `TypeError` when called with `arr ...\n\n### Summary\n\n\n\n`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).\n\n\n\n### Details\n\n\n\nIn the comma + `encodeValuesOnly` branch, `lib/stringify.js:145` mapped the array through the raw encoder before joining:\n\n\n\n```js\n\n\n\nobj = utils.maybeMap(obj, encoder);\n\n\n\n```\n\n\n\n`utils.encode` (`lib/uti\n\nPackage: qs\nInstalled: 6.14.2\nFixed in: 6.15.2\nSeverity: MEDIUM\nFix: Upgrade qs to 6.15.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0cdbf507bdba99d1", "name": "CVE-2024-1899: showdown 2.1.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2024-1899: showdown 2.1.0 \u2014 package-lock.json"}, "fullDescription": {"text": "Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing\n\nAn issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.\n\nPackage: showdown\nInstalled: 2.1.0\nFixed in: \u2014\nSeverity: MEDIUM\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7f1724bdeeccb121", "name": "CVE-2026-6951: simple-git 3.33.0 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-6951: simple-git 3.33.0 \u2014 package-lock.json"}, "fullDescription": {"text": "simple-git: simple-git: Remote Code Execution due to incomplete fix bypass\n\nVersions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.\n\nPackage: simple-git\nInstalled: 3.33.0\nFixed in: 3.36.0\nSeverity: HIGH\nFix: Upgrade simple-git to 3.36.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ae20d01f1de8a56", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 package-lock.json"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3b41d24d73cf707", "name": "CVE-2026-48779: ws 8.18.3 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-48779: ws 8.18.3 \u2014 package-lock.json"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.18.3\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9f5abd1f03b5df58", "name": "CVE-2026-45736: ws 8.18.3 \u2014 package-lock.json", "shortDescription": {"text": "CVE-2026-45736: ws 8.18.3 \u2014 package-lock.json"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.18.3\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ae996a9275eafe5", "name": "CVE-2026-49356: @babel/core 7.24.7 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-49356: @babel/core 7.24.7 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "@babel/core: @babel/core: Arbitrary file read via sourceMappingURL comment\n\nBabel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile maliciously crafted code can allow an attacker to read any source map from the system that is running Babel, if the attacker controls the input source code, can read the output source code, and knows the path of the source map file that they want to read. This vulnerability is fixed in 8.0.0-rc.6 an\n\nPackage: @babel/core\nInstalled: 7.24.7\nFixed in: 8.0.0-rc.6, 7.29.6\nSeverity: LOW\nFix: Upgrade @babel/core to 8.0.0-rc.6, 7.29.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-175faf060975f12c", "name": "CVE-2026-13149: brace-expansion 1.1.13 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 1.1.13 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 1.1.13\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40e8daee701f4340", "name": "CVE-2026-14257: brace-expansion 1.1.13 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-14257: brace-expansion 1.1.13 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "brace-expansion through 5.0.7 is vulnerable to denial of service via m ...\n\nbrace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of i\n\nPackage: brace-expansion\nInstalled: 1.1.13\nFixed in: 5.0.8\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.8"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2840674e6a6dceb9", "name": "CVE-2026-59869: js-yaml 3.14.2 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 3.14.2 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 3.14.2\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-346651f3145a6d29", "name": "CVE-2026-53550: js-yaml 3.14.2 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 3.14.2 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 3.14.2\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-39c00fc1bc04f773", "name": "CVE-2026-59869: js-yaml 4.1.1 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML documents\n\njs-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 3.15.0, 4.3.0\nSeverity: HIGH\nFix: Upgrade js-yaml to 3.15.0, 4.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e75b99201bb6d05b", "name": "CVE-2026-53550: js-yaml 4.1.1 \u2014 tests/package-lock.json", "shortDescription": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 tests/package-lock.json"}, "fullDescription": {"text": "js-yaml: js-yaml: Denial of Service via crafted YAML merge keys\n\njs-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerabil\n\nPackage: js-yaml\nInstalled: 4.1.1\nFixed in: 4.2.0, 3.15.0\nSeverity: MEDIUM\nFix: Upgrade js-yaml to 4.2.0, 3.15.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a3527e70129fb18", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c4041c454cda88e", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d026cbfac9c2e95a", "name": "Docker base image is tag-pinned but not digest-pinned: node:lts-alpine3.23", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:lts-alpine3.23"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1461dea687c6007", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/script.js:3669", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/script.js:3669"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-57fef5225c3fc086", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/power-user.js:1157", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/power-user.js:1157"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-9f222b6710ebe11a", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/data-maid.js:106", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/data-maid.js:106"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-f33d6c2ba13b7570", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/utils.js:2581", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/utils.js:2581"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-03bd403ce7aedb9d", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/slash-commands.js:4104", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/slash-commands.js:4104"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-d07ae44a330d531c", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/PromptManager.js:1449", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/PromptManager.js:1449"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-c9c3fdbc3c9d126e", "name": "Insecure pattern 'insert_adjacent_html' in public/scripts/PromptManager.js:1310", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/PromptManager.js:1310"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-5761f9079a123aae", "name": "Insecure pattern 'insert_adjacent_html' in public/scripts/BulkEditOverlay.js:247", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/BulkEditOverlay.js:247"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-b2df5c2272a74ccf", "name": "Insecure pattern 'domparser_html_parse' in public/scripts/i18n.js:251", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in public/scripts/i18n.js:251"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-c7f7e1fece99a90d", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/reasoning.js:560", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/reasoning.js:560"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-9e6656e3e60afc44", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/horde.js:379", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/horde.js:379"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-3469b07b31e1f662", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/chats.js:1944", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/chats.js:1944"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-1b0b4b9f2cbda164", "name": "Insecure pattern 'domparser_html_parse' in public/scripts/chats.js:813", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in public/scripts/chats.js:813"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-ef8700bc42c79d29", "name": "Insecure pattern 'insert_adjacent_html' in public/scripts/openai.js:1823", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/openai.js:1823"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-779b872a13351243", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/util/stream-fadein.js:18", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/util/stream-fadein.js:18"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-f952b58fe686123b", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/autocomplete/MacroAutoCompleteOption.js:39", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/autocomplete/MacroAutoCompleteOption.js:39"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-18c7e07389f60875", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js:349", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js:349"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-eb913f8c1fe2b748", "name": "Insecure pattern 'insert_adjacent_html' in public/scripts/extensions/connection-manager/index.js:709", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/extensions/connection-manager/index.js:709"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-f4317e60cbef99b9", "name": "Insecure pattern 'new_function_used' in public/lib/epub.min.js:1", "shortDescription": {"text": "Insecure pattern 'new_function_used' in public/lib/epub.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c638675bd97b1de", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/epub.min.js:1", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/epub.min.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.85}}, {"id": "scanner-232fd84b1fa8b91b", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/toolcool-color-picker.js:8", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/toolcool-color-picker.js:8"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-e0223893ab316603", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/select2.min.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/select2.min.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-7a9208c6d4bc785b", "name": "Insecure pattern 'new_function_used' in public/lib/jszip.min.js:13", "shortDescription": {"text": "Insecure pattern 'new_function_used' in public/lib/jszip.min.js:13"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0fe2cc8022e468a5", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ff6ace1dc5b194c", "name": "Very large file: tests/prompt-converters.test.js (1263 lines)", "shortDescription": {"text": "Very large file: tests/prompt-converters.test.js (1263 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e01db851f52be3e", "name": "Very large file: tests/frontend/MacroEngine.e2e.js (3411 lines)", "shortDescription": {"text": "Very large file: tests/frontend/MacroEngine.e2e.js (3411 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7e7ad3e0f94bdeb", "name": "Very large file: tests/frontend/MacroLexer.e2e.js (1348 lines)", "shortDescription": {"text": "Very large file: tests/frontend/MacroLexer.e2e.js (1348 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f3cecf6b6ef7cce", "name": "Very large file: public/script.js (12537 lines)", "shortDescription": {"text": "Very large file: public/script.js (12537 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fab33ce4fed07d47", "name": "Very large file: public/scripts/backgrounds.js (1865 lines)", "shortDescription": {"text": "Very large file: public/scripts/backgrounds.js (1865 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f500e9f790880164", "name": "Very large file: public/scripts/power-user.js (4460 lines)", "shortDescription": {"text": "Very large file: public/scripts/power-user.js (4460 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a4067085f58ca01", "name": "Very large file: public/scripts/group-chats.js (2490 lines)", "shortDescription": {"text": "Very large file: public/scripts/group-chats.js (2490 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14965c9153d9cbe5", "name": "Very large file: public/scripts/textgen-settings.js (1849 lines)", "shortDescription": {"text": "Very large file: public/scripts/textgen-settings.js (1849 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23369f4f8f581c9e", "name": "Very large file: public/scripts/variables.js (2348 lines)", "shortDescription": {"text": "Very large file: public/scripts/variables.js (2348 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6fe4ad5eead7ab4", "name": "Very large file: public/scripts/utils.js (3112 lines)", "shortDescription": {"text": "Very large file: public/scripts/utils.js (3112 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-109f7a38a05d7f5d", "name": "Very large file: public/scripts/world-info.js (6289 lines)", "shortDescription": {"text": "Very large file: public/scripts/world-info.js (6289 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f8c6cab8911b818", "name": "Very large file: public/scripts/RossAscends-mods.js (1283 lines)", "shortDescription": {"text": "Very large file: public/scripts/RossAscends-mods.js (1283 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e55aae6973f0237", "name": "Very large file: public/scripts/slash-commands.js (7095 lines)", "shortDescription": {"text": "Very large file: public/scripts/slash-commands.js (7095 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39981c4df5db60cb", "name": "Very large file: public/scripts/PromptManager.js (2144 lines)", "shortDescription": {"text": "Very large file: public/scripts/PromptManager.js (2144 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72a9fa82efc8757a", "name": "Very large file: public/scripts/reasoning.js (1662 lines)", "shortDescription": {"text": "Very large file: public/scripts/reasoning.js (1662 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bfb9f38d4629d6d0", "name": "Very large file: public/scripts/personas.js (3006 lines)", "shortDescription": {"text": "Very large file: public/scripts/personas.js (3006 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-532bf91d5c9c753c", "name": "Very large file: public/scripts/tags.js (2824 lines)", "shortDescription": {"text": "Very large file: public/scripts/tags.js (2824 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9cc91d1621be33ad", "name": "Very large file: public/scripts/secrets.js (1293 lines)", "shortDescription": {"text": "Very large file: public/scripts/secrets.js (1293 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-44c7182981b01c9d", "name": "Very large file: public/scripts/chats.js (2422 lines)", "shortDescription": {"text": "Very large file: public/scripts/chats.js (2422 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-828cfe5a30dab6b4", "name": "Very large file: public/scripts/openai.js (7249 lines)", "shortDescription": {"text": "Very large file: public/scripts/openai.js (7249 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92e5cfde8772d0b5", "name": "Very large file: public/scripts/extensions.js (2315 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions.js (2315 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ffb743f7c642fc3b", "name": "Very large file: public/scripts/slash-commands/SlashCommandParser.js (1356 lines)", "shortDescription": {"text": "Very large file: public/scripts/slash-commands/SlashCommandParser.js (1356 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-94beb7292765d4d9", "name": "Very large file: public/scripts/autocomplete/MacroAutoCompleteHelper.js (1217 lines)", "shortDescription": {"text": "Very large file: public/scripts/autocomplete/MacroAutoCompleteHelper.js (1217 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a374c7b059e718b", "name": "Very large file: public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js (1872 lines)", "shortDescription": {"text": "Very large file: public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js (1872 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-466d8f701103367f", "name": "Very large file: public/scripts/macros/engine/MacroCstWalker.js (1364 lines)", "shortDescription": {"text": "Very large file: public/scripts/macros/engine/MacroCstWalker.js (1364 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-81b93cdff159c8e6", "name": "Very large file: public/scripts/extensions/tts/index.js (1622 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions/tts/index.js (1622 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-400ca2ca45292329", "name": "Very large file: public/scripts/extensions/regex/index.js (2157 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions/regex/index.js (2157 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d654c11cdb44379b", "name": "Very large file: public/scripts/extensions/vectors/index.js (2358 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions/vectors/index.js (2358 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03d6e21ecc3923f7", "name": "Very large file: public/scripts/extensions/quick-reply/src/QuickReply.js (1923 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions/quick-reply/src/QuickReply.js (1923 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7924fd6d637412b", "name": "Very large file: public/scripts/extensions/stable-diffusion/index.js (5998 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions/stable-diffusion/index.js (5998 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c0311934293e44f", "name": "Very large file: public/scripts/extensions/expressions/index.js (2576 lines)", "shortDescription": {"text": "Very large file: public/scripts/extensions/expressions/index.js (2576 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be5b41867e92424b", "name": "Very large file: src/util.js (1577 lines)", "shortDescription": {"text": "Very large file: src/util.js (1577 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef01d17a25df5d80", "name": "Very large file: src/prompt-converters.js (1445 lines)", "shortDescription": {"text": "Very large file: src/prompt-converters.js (1445 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc77222c9d7c8b67", "name": "Very large file: src/endpoints/characters.js (1685 lines)", "shortDescription": {"text": "Very large file: src/endpoints/characters.js (1685 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77c0c9d0b7682407", "name": "Very large file: src/endpoints/stable-diffusion.js (2208 lines)", "shortDescription": {"text": "Very large file: src/endpoints/stable-diffusion.js (2208 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f5409a9d6fbb781", "name": "Very large file: src/endpoints/backends/chat-completions.js (2896 lines)", "shortDescription": {"text": "Very large file: src/endpoints/backends/chat-completions.js (2896 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "19 test file(s) for 336 source file(s) (ratio 0.06). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-102b7802b0cd82cd", "name": "68 TODO/FIXME markers", "shortDescription": {"text": "68 TODO/FIXME markers"}, "fullDescription": {"text": "High count of TODO/FIXME/HACK markers \u2014 track them as issues so they're not forgotten."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 1197 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 219 placeholder/mock markers across 47 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c83e3a92116a1b52", "name": "Legacy-named symbol `substituteParamsLegacy` in public/script.js:2772", "shortDescription": {"text": "Legacy-named symbol `substituteParamsLegacy` in public/script.js:2772"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e0229f49ae4ca81", "name": "Legacy-named symbol `logDeprecated` in public/scripts/macros.js:64", "shortDescription": {"text": "Legacy-named symbol `logDeprecated` in public/scripts/macros.js:64"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3cc84c12736c34d4", "name": "Legacy-named symbol `swipe_picker_copy` in public/scripts/swipe-picker.js:252", "shortDescription": {"text": "Legacy-named symbol `swipe_picker_copy` in public/scripts/swipe-picker.js:252"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be119b3ce77fa458", "name": "Legacy-named symbol `nerdstash_v2` in public/scripts/tokenizers.js:87", "shortDescription": {"text": "Legacy-named symbol `nerdstash_v2` in public/scripts/tokenizers.js:87"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d07c2ec84cff431f", "name": "Legacy-named symbol `mes_reasoning_copy` in public/scripts/reasoning.js:1218", "shortDescription": {"text": "Legacy-named symbol `mes_reasoning_copy` in public/scripts/reasoning.js:1218"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db2fb3349be218ac", "name": "Legacy-named symbol `personas_backup` in public/scripts/personas.js:2944", "shortDescription": {"text": "Legacy-named symbol `personas_backup` in public/scripts/personas.js:2944"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ba3ee0133eedae4", "name": "Legacy-named symbol `tag_view_backup` in public/scripts/tags.js:2793", "shortDescription": {"text": "Legacy-named symbol `tag_view_backup` in public/scripts/tags.js:2793"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2294bc61024f9f11", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 public/scripts/extensions.js:543", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 public/scripts/extensions.js:543"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-63862bb7a3a26345", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 public/scripts/extensions/tts/kokoro.js:163", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 public/scripts/extensions/tts/kokoro.js:163"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-b4cda11b1380a60e", "name": "Legacy-named symbol `eleven_multilingual_v2` in public/scripts/extensions/tts/elevenlabs.js:38", "shortDescription": {"text": "Legacy-named symbol `eleven_multilingual_v2` in public/scripts/extensions/tts/elevenlabs.js:38"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba4deff56ecd1521", "name": "Legacy-named symbol `chara_card_v2` in src/byaf.js:250", "shortDescription": {"text": "Legacy-named symbol `chara_card_v2` in src/byaf.js:250"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7143105ced020619", "name": "Legacy-named symbol `chara_card_v2` in src/types/spec-v2.d.ts:2", "shortDescription": {"text": "Legacy-named symbol `chara_card_v2` in src/types/spec-v2.d.ts:2"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1074c2f9b1605db", "name": "Legacy-named symbol `chara_card_v2` in src/endpoints/content-manager.js:476", "shortDescription": {"text": "Legacy-named symbol `chara_card_v2` in src/endpoints/content-manager.js:476"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b66e1b7bb8bf26f", "name": "Legacy-named symbol `spp_nerd_v2` in src/endpoints/tokenizers.js:254", "shortDescription": {"text": "Legacy-named symbol `spp_nerd_v2` in src/endpoints/tokenizers.js:254"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27481694978b14a9", "name": "Legacy-named symbol `isDeprecated` in src/endpoints/google.js:440", "shortDescription": {"text": "Legacy-named symbol `isDeprecated` in src/endpoints/google.js:440"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24fa99e710b58035", "name": "Legacy-named symbol `chara_card_v2` in src/endpoints/characters.js:596", "shortDescription": {"text": "Legacy-named symbol `chara_card_v2` in src/endpoints/characters.js:596"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5296014038a93308", "name": "Legacy-named symbol `t2a_v2` in src/endpoints/minimax.js:67", "shortDescription": {"text": "Legacy-named symbol `t2a_v2` in src/endpoints/minimax.js:67"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10643b3872ddf5a3", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/stable-diffusion.js:122", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/stable-diffusion.js:122"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9bfa5545c7a96486", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/nanogpt.js:52", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/nanogpt.js:52"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5b6090887e804031", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/backends/kobold.js:163", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/backends/kobold.js:163"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-1bc61d7364459ca2", "name": "Legacy-named symbol `chara_card_v2` in src/validator/TavernCardValidator.js:89", "shortDescription": {"text": "Legacy-named symbol `chara_card_v2` in src/validator/TavernCardValidator.js:89"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7b61ed1590c3b4d", "name": "Vulnerable dependency body-parser 1.20.4: GHSA-v422-hmwv-36x6", "shortDescription": {"text": "Vulnerable dependency body-parser 1.20.4: GHSA-v422-hmwv-36x6"}, "fullDescription": {"text": "OSV.dev reports `body-parser` at version `1.20.4` (resolved in `package-lock.json`) is affected by GHSA-v422-hmwv-36x6.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v422-hmwv-36x6\nFix: upgrade `body-parser` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4bb196091f818041", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-76mc-f452-cxcm", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-76mc-f452-cxcm"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-76mc-f452-cxcm (aka CVE-2026-65902).\n\nDOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`\n\nAliases: CVE-2026-65902\nAdvisory: https://osv.dev/vulnerability/GHSA-76mc-f452-cxcm\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c2ef6b2ef296dc98", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-c2j3-45gr-mqc4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-c2j3-45gr-mqc4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-c2j3-45gr-mqc4.\n\nDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-c2j3-45gr-mqc4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e7db3f8fdb375e0", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-cmwh-pvxp-8882", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-cmwh-pvxp-8882"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-cmwh-pvxp-8882 (aka CVE-2026-65898).\n\nDOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)\n\nAliases: CVE-2026-65898\nAdvisory: https://osv.dev/vulnerability/GHSA-cmwh-pvxp-8882\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d99382dbe7c75cec", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-gvmj-g25r-r7wr", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-gvmj-g25r-r7wr"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-gvmj-g25r-r7wr (aka CVE-2026-65900).\n\nDOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes\n\nAliases: CVE-2026-65900\nAdvisory: https://osv.dev/vulnerability/GHSA-gvmj-g25r-r7wr\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-740a416df111ad12", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-hpcv-96wg-7vj8", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-hpcv-96wg-7vj8"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-hpcv-96wg-7vj8.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hpcv-96wg-7vj8\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-77caf7814614790e", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-r47g-fvhr-h676", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-r47g-fvhr-h676"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-r47g-fvhr-h676.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r47g-fvhr-h676\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10f4f9f0a7919e50", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-rp9w-3fw7-7cwq", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-rp9w-3fw7-7cwq"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-rp9w-3fw7-7cwq.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rp9w-3fw7-7cwq\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1564ac5779d49487", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-vxr8-fq34-vvx9", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-vxr8-fq34-vvx9"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-vxr8-fq34-vvx9.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-vxr8-fq34-vvx9\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b7ad40c79facae70", "name": "Vulnerable dependency dompurify 3.4.2: GHSA-x4vx-rjvf-j5p4", "shortDescription": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-x4vx-rjvf-j5p4"}, "fullDescription": {"text": "OSV.dev reports `dompurify` at version `3.4.2` (resolved in `package-lock.json`) is affected by GHSA-x4vx-rjvf-j5p4.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-x4vx-rjvf-j5p4\nFix: upgrade `dompurify` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef74e3a752b3301b", "name": "Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx", "shortDescription": {"text": "Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx"}, "fullDescription": {"text": "OSV.dev reports `form-data` at version `4.0.5` (resolved in `package-lock.json`) is affected by GHSA-hmw2-7cc7-3qxx.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hmw2-7cc7-3qxx\nFix: upgrade `form-data` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29ff6340e2fbba20", "name": "Vulnerable dependency multer 2.1.1: GHSA-3p4h-7m6x-2hcm", "shortDescription": {"text": "Vulnerable dependency multer 2.1.1: GHSA-3p4h-7m6x-2hcm"}, "fullDescription": {"text": "OSV.dev reports `multer` at version `2.1.1` (resolved in `package-lock.json`) is affected by GHSA-3p4h-7m6x-2hcm (aka CVE-2026-5038).\n\nMulter vulnerable to Denial of Service via incomplete cleanup of aborted uploads\n\nAliases: CVE-2026-5038\nAdvisory: https://osv.dev/vulnerability/GHSA-3p4h-7m6x-2hcm\nFix: upgrade `multer` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-26f2d1e0427ce15c", "name": "Vulnerable dependency multer 2.1.1: GHSA-72gw-mp4g-v24j", "shortDescription": {"text": "Vulnerable dependency multer 2.1.1: GHSA-72gw-mp4g-v24j"}, "fullDescription": {"text": "OSV.dev reports `multer` at version `2.1.1` (resolved in `package-lock.json`) is affected by GHSA-72gw-mp4g-v24j (aka CVE-2026-5079).\n\nMulter vulnerable to Denial of Service via deeply nested field names\n\nAliases: CVE-2026-5079\nAdvisory: https://osv.dev/vulnerability/GHSA-72gw-mp4g-v24j\nFix: upgrade `multer` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5ccaf2b2806595b4", "name": "Vulnerable dependency showdown 2.1.0: GHSA-rmmh-p597-ppvv", "shortDescription": {"text": "Vulnerable dependency showdown 2.1.0: GHSA-rmmh-p597-ppvv"}, "fullDescription": {"text": "OSV.dev reports `showdown` at version `2.1.0` (resolved in `package-lock.json`) is affected by GHSA-rmmh-p597-ppvv.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-rmmh-p597-ppvv\nFix: upgrade `showdown` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bd501872c313f352", "name": "Vulnerable dependency simple-git 3.33.0: GHSA-hffm-xvc3-vprc", "shortDescription": {"text": "Vulnerable dependency simple-git 3.33.0: GHSA-hffm-xvc3-vprc"}, "fullDescription": {"text": "OSV.dev reports `simple-git` at version `3.33.0` (resolved in `package-lock.json`) is affected by GHSA-hffm-xvc3-vprc (aka CVE-2026-6951).\n\nsimple-git is vulnerable to Remote Code Execution\n\nAliases: CVE-2026-6951\nAdvisory: https://osv.dev/vulnerability/GHSA-hffm-xvc3-vprc\nFix: upgrade `simple-git` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-b01d57d7856e6524", "name": "Vulnerable dependency ws 8.18.3: GHSA-58qx-3vcg-4xpx", "shortDescription": {"text": "Vulnerable dependency ws 8.18.3: GHSA-58qx-3vcg-4xpx"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.18.3` (resolved in `package-lock.json`) is affected by GHSA-58qx-3vcg-4xpx (aka CVE-2026-45736).\n\nws: Uninitialized memory disclosure\n\nAliases: CVE-2026-45736\nAdvisory: https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b0d4480a2767b41", "name": "Vulnerable dependency ws 8.18.3: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "Vulnerable dependency ws 8.18.3: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.18.3` (resolved in `package-lock.json`) is affected by GHSA-96hv-2xvq-fx4p (aka CVE-2026-48779).\n\nws: Memory exhaustion DoS from tiny fragments and data chunks\n\nAliases: CVE-2026-48779\nAdvisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6b57935db5767b7a", "name": "Vulnerable dependency @protobufjs/utf8 1.1.0: GHSA-q6x5-8v7m-xcrf", "shortDescription": {"text": "Vulnerable dependency @protobufjs/utf8 1.1.0: GHSA-q6x5-8v7m-xcrf"}, "fullDescription": {"text": "OSV.dev reports `@protobufjs/utf8` at version `1.1.0` (resolved in `package-lock.json`) is affected by GHSA-q6x5-8v7m-xcrf.\nNote: `@protobufjs/utf8` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q6x5-8v7m-xcrf\nFix: upgrade `@protobufjs/utf8` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-defb820e44bef396", "name": "Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.1.0` (resolved in `package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7b0e4e4a3d45273d", "name": "Vulnerable dependency brace-expansion 2.1.0: GHSA-mh99-v99m-4gvg", "shortDescription": {"text": "Vulnerable dependency brace-expansion 2.1.0: GHSA-mh99-v99m-4gvg"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `2.1.0` (resolved in `package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash\n\nAliases: CVE-2026-14257\nAdvisory: https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-fd33e4098759ac02", "name": "Vulnerable dependency axios 1.15.2: GHSA-35jp-ww65-95wh", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-35jp-ww65-95wh"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-35jp-ww65-95wh (aka CVE-2026-44494).\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\naxios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`\n\nAliases: CVE-2026-44494\nAdvisory: https://osv.dev/vulnerability/GHSA-35jp-ww65-95wh\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1aa7ed4a82fe7515", "name": "Vulnerable dependency axios 1.15.2: GHSA-42h9-826w-cgv3", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-42h9-826w-cgv3"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-42h9-826w-cgv3.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAxios: Excessive recursion in formDataToJSON can cause denial of service\n\nAdvisory: https://osv.dev/vulnerability/GHSA-42h9-826w-cgv3\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-81312e858274a322", "name": "Vulnerable dependency axios 1.15.2: GHSA-654m-c8p4-x5fp", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-654m-c8p4-x5fp"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-654m-c8p4-x5fp (aka CVE-2026-44489).\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAxios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution \u2014 Incomplete Null-Prototype Fix\n\nAliases: CVE-2026-44489\nAdvisory: https://osv.dev/vulnerability/GHSA-654m-c8p4-x5fp\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-40a634b30cbd5de2", "name": "Vulnerable dependency axios 1.15.2: GHSA-777c-7fjr-54vf", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-777c-7fjr-54vf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-777c-7fjr-54vf (aka CVE-2026-44488).\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAllocation of Resources Without Limits or Throttling in Axios\n\nAliases: CVE-2026-44488\nAdvisory: https://osv.dev/vulnerability/GHSA-777c-7fjr-54vf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-74ad15603f7358f5", "name": "Vulnerable dependency axios 1.15.2: GHSA-7q8q-rj6j-mhjq", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-7q8q-rj6j-mhjq"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-7q8q-rj6j-mhjq.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAxios: Nested axios option objects can consume polluted prototype values\n\nAdvisory: https://osv.dev/vulnerability/GHSA-7q8q-rj6j-mhjq\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-8f762b5f040227fb", "name": "Vulnerable dependency axios 1.15.2: GHSA-898c-q2cr-xwhg", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-898c-q2cr-xwhg"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-898c-q2cr-xwhg (aka CVE-2026-44490).\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\naxios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions\n\nAliases: CVE-2026-44490\nAdvisory: https://osv.dev/vulnerability/GHSA-898c-q2cr-xwhg\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-72826426f0f6a976", "name": "Vulnerable dependency axios 1.15.2: GHSA-f4gw-2p7v-4548", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-f4gw-2p7v-4548"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-f4gw-2p7v-4548.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAxios: NO_PROXY bypass for 0.0.0.0 local addresses in axios\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f4gw-2p7v-4548\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-28c92ad35b58a75e", "name": "Vulnerable dependency axios 1.15.2: GHSA-gcfj-64vw-6mp9", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-gcfj-64vw-6mp9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-gcfj-64vw-6mp9.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAxios Node HTTP adapter can use an inherited proxy after interceptor config cloning\n\nAdvisory: https://osv.dev/vulnerability/GHSA-gcfj-64vw-6mp9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e922b32c9f06ffae", "name": "Vulnerable dependency axios 1.15.2: GHSA-hcpx-6fm6-wx23", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-hcpx-6fm6-wx23"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-hcpx-6fm6-wx23.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nAxios form serializer maxDepth bypass via {} metatoken\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hcpx-6fm6-wx23\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-86de01609079ef31", "name": "Vulnerable dependency axios 1.15.2: GHSA-hfxv-24rg-xrqf", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-hfxv-24rg-xrqf"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-hfxv-24rg-xrqf.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-hfxv-24rg-xrqf\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-83e70aedbecd3a4a", "name": "Vulnerable dependency axios 1.15.2: GHSA-j5f8-grm9-p9fc", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-j5f8-grm9-p9fc"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-j5f8-grm9-p9fc.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-j5f8-grm9-p9fc\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-3324ea3aeea87300", "name": "Vulnerable dependency axios 1.15.2: GHSA-jqh4-m9w3-8hp9", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-jqh4-m9w3-8hp9"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-jqh4-m9w3-8hp9.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-jqh4-m9w3-8hp9\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-641ee58bb6dd7e96", "name": "Vulnerable dependency axios 1.15.2: GHSA-mmx7-hfxf-jppx", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-mmx7-hfxf-jppx"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-mmx7-hfxf-jppx.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mmx7-hfxf-jppx\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e2e4c135ada645dd", "name": "Vulnerable dependency axios 1.15.2: GHSA-mwf2-3pr3-8698", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-mwf2-3pr3-8698"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-mwf2-3pr3-8698.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-mwf2-3pr3-8698\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2ec3dd9182de19cd", "name": "Vulnerable dependency axios 1.15.2: GHSA-p92q-9vqr-4j8v", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-p92q-9vqr-4j8v"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-p92q-9vqr-4j8v.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-p92q-9vqr-4j8v\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2d992b673b9ca0ea", "name": "Vulnerable dependency axios 1.15.2: GHSA-pjwm-pj3p-43mv", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-pjwm-pj3p-43mv"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-pjwm-pj3p-43mv.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pjwm-pj3p-43mv\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-521c33c009330cca", "name": "Vulnerable dependency axios 1.15.2: GHSA-pmv8-rq9r-6j72", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-pmv8-rq9r-6j72"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-pmv8-rq9r-6j72.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-pmv8-rq9r-6j72\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4742e1711949d040", "name": "Vulnerable dependency axios 1.15.2: GHSA-xj6q-8x83-jv6g", "shortDescription": {"text": "Vulnerable dependency axios 1.15.2: GHSA-xj6q-8x83-jv6g"}, "fullDescription": {"text": "OSV.dev reports `axios` at version `1.15.2` (resolved in `package-lock.json`) is affected by GHSA-xj6q-8x83-jv6g.\nNote: `axios` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-xj6q-8x83-jv6g\nFix: upgrade `axios` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e5adfb4de22b5dfc", "name": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.14` (resolved in `package-lock.json`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c5b3747f6ac6c380", "name": "Vulnerable dependency brace-expansion 1.1.14: GHSA-mh99-v99m-4gvg", "shortDescription": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-mh99-v99m-4gvg"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `1.1.14` (resolved in `package-lock.json`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash\n\nAliases: CVE-2026-14257\nAdvisory: https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e0bcc5916af91f27", "name": "Vulnerable dependency fast-uri 3.1.0: GHSA-4c8g-83qw-93j6", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-4c8g-83qw-93j6"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-4c8g-83qw-93j6 (aka CVE-2026-13676).\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nfast-uri vulnerable to host confusion via failed IDN canonicalization\n\nAliases: CVE-2026-13676\nAdvisory: https://osv.dev/vulnerability/GHSA-4c8g-83qw-93j6\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-41060e7beb571855", "name": "Vulnerable dependency fast-uri 3.1.0: GHSA-q3j6-qgpj-74h6", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-q3j6-qgpj-74h6"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-q3j6-qgpj-74h6.\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-q3j6-qgpj-74h6\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-e668e6737d5d8a0d", "name": "Vulnerable dependency fast-uri 3.1.0: GHSA-v2hh-gcrm-f6hx", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-v2hh-gcrm-f6hx"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-v2hh-gcrm-f6hx (aka CVE-2026-16221).\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nfast-uri vulnerable to host confusion via literal backslash authority delimiter\n\nAliases: CVE-2026-16221\nAdvisory: https://osv.dev/vulnerability/GHSA-v2hh-gcrm-f6hx\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c15f421d52222fa8", "name": "Vulnerable dependency fast-uri 3.1.0: GHSA-v39h-62p7-jpjc", "shortDescription": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-v39h-62p7-jpjc"}, "fullDescription": {"text": "OSV.dev reports `fast-uri` at version `3.1.0` (resolved in `package-lock.json`) is affected by GHSA-v39h-62p7-jpjc.\nNote: `fast-uri` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNo summary published yet.\n\nAdvisory: https://osv.dev/vulnerability/GHSA-v39h-62p7-jpjc\nFix: upgrade `fast-uri` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5fa51cb1b6ee6b23", "name": "Vulnerable dependency file-type 16.5.4: GHSA-5v7r-6r5c-r473", "shortDescription": {"text": "Vulnerable dependency file-type 16.5.4: GHSA-5v7r-6r5c-r473"}, "fullDescription": {"text": "OSV.dev reports `file-type` at version `16.5.4` (resolved in `package-lock.json`) is affected by GHSA-5v7r-6r5c-r473 (aka CVE-2026-31808).\nNote: `file-type` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nfile-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header\n\nAliases: CVE-2026-31808\nAdvisory: https://osv.dev/vulnerability/GHSA-5v7r-6r5c-r473\nFix: upgrade `file-type` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d8e96978dfe3a202", "name": "Dependency @iconfu/svg-inject is a major version behind", "shortDescription": {"text": "Dependency @iconfu/svg-inject is a major version behind"}, "fullDescription": {"text": "`@iconfu/svg-inject` is pinned at `1.2.3` in `package.json` while the latest release on the npm registry is `2.0.1` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@iconfu/svg-inject` to `2.0.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-b6e35c071b354366", "name": "Dependency @types/jest is a major version behind", "shortDescription": {"text": "Dependency @types/jest is a major version behind"}, "fullDescription": {"text": "`@types/jest` is pinned at `29.5.12` in `tests/package.json` while the latest release on the npm registry is `30.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@types/jest` to `30.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-3a8277f2b7fcb654", "name": "Dependency @zeldafan0225/ai_horde is a major version behind", "shortDescription": {"text": "Dependency @zeldafan0225/ai_horde is a major version behind"}, "fullDescription": {"text": "`@zeldafan0225/ai_horde` is pinned at `5.2.0` in `package.json` while the latest release on the npm registry is `6.0.2` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@zeldafan0225/ai_horde` to `6.0.2`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-9001556669c1d1ed", "name": "Dependency agent-base is two or more major versions behind", "shortDescription": {"text": "Dependency agent-base is two or more major versions behind"}, "fullDescription": {"text": "`agent-base` is pinned at `7.1.3` in `package.json` while the latest release on the npm registry is `9.0.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `agent-base` to `9.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-c88813e0aac9bfc8", "name": "Dependency archiver is a major version behind", "shortDescription": {"text": "Dependency archiver is a major version behind"}, "fullDescription": {"text": "`archiver` is pinned at `7.0.1` in `package.json` while the latest release on the npm registry is `8.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `archiver` to `8.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-ede9f24cb8869f4c", "name": "Dependency body-parser is a major version behind", "shortDescription": {"text": "Dependency body-parser is a major version behind"}, "fullDescription": {"text": "`body-parser` is pinned at `1.20.2` in `package.json` while the latest release on the npm registry is `2.3.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `body-parser` to `2.3.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-3a3f5a11c4e5f33a", "name": "Dependency chalk is a major version behind", "shortDescription": {"text": "Dependency chalk is a major version behind"}, "fullDescription": {"text": "`chalk` is pinned at `5.6.0` in `package.json` while the latest release on the npm registry is `6.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `chalk` to `6.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-2b239381395a9cf9", "name": "Dependency chevrotain is two or more major versions behind", "shortDescription": {"text": "Dependency chevrotain is two or more major versions behind"}, "fullDescription": {"text": "`chevrotain` is pinned at `11.2.0` in `package.json` while the latest release on the npm registry is `13.0.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `chevrotain` to `13.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-9d088778cea208f2", "name": "Dangling fetch: POST /api/characters/get (public/script.js:1222)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/get (public/script.js:1222)"}, "fullDescription": {"text": "`public/script.js:1222` calls `POST /api/characters/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1a764ff54b653030", "name": "Dangling fetch: POST /api/characters/all (public/script.js:1293)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/all (public/script.js:1293)"}, "fullDescription": {"text": "`public/script.js:1293` calls `POST /api/characters/all` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/all`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0dbaa3a0f201a2e4", "name": "Dangling fetch: POST /api/chats/delete (public/script.js:1337)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/delete (public/script.js:1337)"}, "fullDescription": {"text": "`public/script.js:1337` calls `POST /api/chats/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9b3801bccff6844b", "name": "Dangling fetch: POST /api/characters/chats (public/script.js:1388)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/chats (public/script.js:1388)"}, "fullDescription": {"text": "`public/script.js:1388` calls `POST /api/characters/chats` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/chats`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9878b2ff595137a3", "name": "Dangling fetch: POST /api/characters/duplicate (public/script.js:6005)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/duplicate (public/script.js:6005)"}, "fullDescription": {"text": "`public/script.js:6005` calls `POST /api/characters/duplicate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/duplicate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-271e0dd2fcd69641", "name": "Dangling fetch: POST /api/characters/rename (public/script.js:7149)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/rename (public/script.js:7149)"}, "fullDescription": {"text": "`public/script.js:7149` calls `POST /api/characters/rename` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/rename`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ca93eb283b013587", "name": "Dangling fetch: POST /api/chats/get (public/script.js:7252)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/get (public/script.js:7252)"}, "fullDescription": {"text": "`public/script.js:7252` calls `POST /api/chats/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-40aba23e8774a450", "name": "Dangling fetch: GET /characters/${avatarKey} (public/script.js:7464)", "shortDescription": {"text": "Dangling fetch: GET /characters/${avatarKey} (public/script.js:7464)"}, "fullDescription": {"text": "`public/script.js:7464` calls `GET /characters/${avatarKey}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/<p>`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9ad56ff84503b822", "name": "Dangling fetch: POST /api/settings/get (public/script.js:7855)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/get (public/script.js:7855)"}, "fullDescription": {"text": "`public/script.js:7855` calls `POST /api/settings/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7299ec9734a8eb13", "name": "Dangling fetch: POST /api/chats/search (public/script.js:8523)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/search (public/script.js:8523)"}, "fullDescription": {"text": "`public/script.js:8523` calls `POST /api/chats/search` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/search`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-201c3b8c7c2feac5", "name": "Dangling fetch: POST /api/chats/import (public/script.js:9389)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/import (public/script.js:9389)"}, "fullDescription": {"text": "`public/script.js:9389` calls `POST /api/chats/import` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/import`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-cc5dfe3110bdae4d", "name": "Dangling fetch: POST /api/characters/import (public/script.js:10492)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/import (public/script.js:10492)"}, "fullDescription": {"text": "`public/script.js:10492` calls `POST /api/characters/import` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/import`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f39f976ed6587cbc", "name": "Dangling fetch: POST /api/chats/rename (public/script.js:10624)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/rename (public/script.js:10624)"}, "fullDescription": {"text": "`public/script.js:10624` calls `POST /api/chats/rename` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/rename`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b4ec5cee76c2ed05", "name": "Dangling fetch: POST /api/characters/merge-attributes (public/script.js:10725)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/script.js:10725)"}, "fullDescription": {"text": "`public/script.js:10725` calls `POST /api/characters/merge-attributes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/merge-attributes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a91d4c217b3b2555", "name": "Dangling fetch: POST /api/characters/delete (public/script.js:10803)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/delete (public/script.js:10803)"}, "fullDescription": {"text": "`public/script.js:10803` calls `POST /api/characters/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-149bb36b201cae37", "name": "Dangling fetch: POST /api/chats/export (public/script.js:11456)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/export (public/script.js:11456)"}, "fullDescription": {"text": "`public/script.js:11456` calls `POST /api/chats/export` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/export`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4138462aceb22218", "name": "Dangling fetch: POST /api/characters/export (public/script.js:11991)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/export (public/script.js:11991)"}, "fullDescription": {"text": "`public/script.js:11991` calls `POST /api/characters/export` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/export`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-efb6a2bec7c82e6c", "name": "Dangling fetch: POST /api/backgrounds/rename (public/scripts/backgrounds.js:512)", "shortDescription": {"text": "Dangling fetch: POST /api/backgrounds/rename (public/scripts/backgrounds.js:512)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:512` calls `POST /api/backgrounds/rename` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backgrounds/rename`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2071a9ef69b80beb", "name": "Dangling fetch: POST /api/backgrounds/all (public/scripts/backgrounds.js:709)", "shortDescription": {"text": "Dangling fetch: POST /api/backgrounds/all (public/scripts/backgrounds.js:709)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:709` calls `POST /api/backgrounds/all` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backgrounds/all`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-655f76e1a69cbe13", "name": "Dangling fetch: POST /api/image-metadata/all (public/scripts/backgrounds.js:742)", "shortDescription": {"text": "Dangling fetch: POST /api/image-metadata/all (public/scripts/backgrounds.js:742)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:742` calls `POST /api/image-metadata/all` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/image-metadata/all`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d08129f6b565bf32", "name": "Dangling fetch: POST /api/backgrounds/folders (public/scripts/backgrounds.js:766)", "shortDescription": {"text": "Dangling fetch: POST /api/backgrounds/folders (public/scripts/backgrounds.js:766)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:766` calls `POST /api/backgrounds/folders` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backgrounds/folders`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-86190c0bc7f50740", "name": "Dangling fetch: POST /api/image-metadata/folders/set-thumbnails (public/scripts/backgrounds.js:793)", "shortDescription": {"text": "Dangling fetch: POST /api/image-metadata/folders/set-thumbnails (public/scripts/backgrounds.js:793)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:793` calls `POST /api/image-metadata/folders/set-thumbnails` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/image-metadata/folders/set-thumbnails`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9433cfadb44fce8c", "name": "Dangling fetch: POST /api/image-metadata/folders/create (public/scripts/backgrounds.js:1168)", "shortDescription": {"text": "Dangling fetch: POST /api/image-metadata/folders/create (public/scripts/backgrounds.js:1168)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:1168` calls `POST /api/image-metadata/folders/create` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/image-metadata/folders/create`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-54add3b7df934733", "name": "Dangling fetch: POST /api/image-metadata/folders/update (public/scripts/backgrounds.js:1197)", "shortDescription": {"text": "Dangling fetch: POST /api/image-metadata/folders/update (public/scripts/backgrounds.js:1197)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:1197` calls `POST /api/image-metadata/folders/update` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/image-metadata/folders/update`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e8c68c744e370527", "name": "Dangling fetch: POST /api/image-metadata/folders/delete (public/scripts/backgrounds.js:1225)", "shortDescription": {"text": "Dangling fetch: POST /api/image-metadata/folders/delete (public/scripts/backgrounds.js:1225)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:1225` calls `POST /api/image-metadata/folders/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/image-metadata/folders/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-26e38d7c2d7fae9b", "name": "Dangling fetch: POST /api/backgrounds/delete (public/scripts/backgrounds.js:1450)", "shortDescription": {"text": "Dangling fetch: POST /api/backgrounds/delete (public/scripts/backgrounds.js:1450)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:1450` calls `POST /api/backgrounds/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backgrounds/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1dc70e37c2221dd4", "name": "Dangling fetch: POST /api/backgrounds/upload (public/scripts/backgrounds.js:1554)", "shortDescription": {"text": "Dangling fetch: POST /api/backgrounds/upload (public/scripts/backgrounds.js:1554)"}, "fullDescription": {"text": "`public/scripts/backgrounds.js:1554` calls `POST /api/backgrounds/upload` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backgrounds/upload`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-64d5073710634ed1", "name": "Dangling fetch: POST /api/themes/delete (public/scripts/power-user.js:2404)", "shortDescription": {"text": "Dangling fetch: POST /api/themes/delete (public/scripts/power-user.js:2404)"}, "fullDescription": {"text": "`public/scripts/power-user.js:2404` calls `POST /api/themes/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/themes/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8a0df228e7cc20c5", "name": "Dangling fetch: POST /api/themes/save (public/scripts/power-user.js:2499)", "shortDescription": {"text": "Dangling fetch: POST /api/themes/save (public/scripts/power-user.js:2499)"}, "fullDescription": {"text": "`public/scripts/power-user.js:2499` calls `POST /api/themes/save` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/themes/save`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3fc5241387768122", "name": "Dangling fetch: POST /api/moving-ui/save (public/scripts/power-user.js:2610)", "shortDescription": {"text": "Dangling fetch: POST /api/moving-ui/save (public/scripts/power-user.js:2610)"}, "fullDescription": {"text": "`public/scripts/power-user.js:2610` calls `POST /api/moving-ui/save` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/moving-ui/save`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8c7ce635184d9b2a", "name": "Dangling fetch: POST /api/groups/edit (public/scripts/group-chats.js:156)", "shortDescription": {"text": "Dangling fetch: POST /api/groups/edit (public/scripts/group-chats.js:156)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:156` calls `POST /api/groups/edit` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/groups/edit`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-48bd363507647517", "name": "Dangling fetch: POST /api/chats/group/get (public/scripts/group-chats.js:196)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/group/get (public/scripts/group-chats.js:196)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:196` calls `POST /api/chats/group/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/group/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-023599a1fd6d639b", "name": "Dangling fetch: POST /api/groups/all (public/scripts/group-chats.js:759)", "shortDescription": {"text": "Dangling fetch: POST /api/groups/all (public/scripts/group-chats.js:759)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:759` calls `POST /api/groups/all` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/groups/all`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3a54a69ecfcf8700", "name": "Dangling fetch: POST /api/groups/delete (public/scripts/group-chats.js:1326)", "shortDescription": {"text": "Dangling fetch: POST /api/groups/delete (public/scripts/group-chats.js:1326)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:1326` calls `POST /api/groups/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/groups/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6d34f54ef02f3825", "name": "Dangling fetch: POST /api/groups/create (public/scripts/group-chats.js:2119)", "shortDescription": {"text": "Dangling fetch: POST /api/groups/create (public/scripts/group-chats.js:2119)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:2119` calls `POST /api/groups/create` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/groups/create`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-86596925b1c17d17", "name": "Dangling fetch: POST /api/chats/group/info (public/scripts/group-chats.js:2172)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/group/info (public/scripts/group-chats.js:2172)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:2172` calls `POST /api/chats/group/info` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/group/info`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bda6ae519e0f9127", "name": "Dangling fetch: POST /api/chats/group/delete (public/scripts/group-chats.js:2249)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/group/delete (public/scripts/group-chats.js:2249)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:2249` calls `POST /api/chats/group/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/group/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-65b780381faa6cf4", "name": "Dangling fetch: POST /api/chats/group/import (public/scripts/group-chats.js:2319)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/group/import (public/scripts/group-chats.js:2319)"}, "fullDescription": {"text": "`public/scripts/group-chats.js:2319` calls `POST /api/chats/group/import` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/group/import`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c645a42208c33ec0", "name": "Dangling fetch: POST /api/data-maid/report (public/scripts/data-maid.js:69)", "shortDescription": {"text": "Dangling fetch: POST /api/data-maid/report (public/scripts/data-maid.js:69)"}, "fullDescription": {"text": "`public/scripts/data-maid.js:69` calls `POST /api/data-maid/report` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/data-maid/report`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-40bc44268198bc34", "name": "Dangling fetch: POST /api/data-maid/finalize (public/scripts/data-maid.js:87)", "shortDescription": {"text": "Dangling fetch: POST /api/data-maid/finalize (public/scripts/data-maid.js:87)"}, "fullDescription": {"text": "`public/scripts/data-maid.js:87` calls `POST /api/data-maid/finalize` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/data-maid/finalize`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ec0475fc37eaa273", "name": "Dangling fetch: POST /api/data-maid/delete (public/scripts/data-maid.js:332)", "shortDescription": {"text": "Dangling fetch: POST /api/data-maid/delete (public/scripts/data-maid.js:332)"}, "fullDescription": {"text": "`public/scripts/data-maid.js:332` calls `POST /api/data-maid/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/data-maid/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c02d03057ff31c14", "name": "Dangling fetch: POST /api/characters/chats (public/scripts/bookmarks.js:71)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/chats (public/scripts/bookmarks.js:71)"}, "fullDescription": {"text": "`public/scripts/bookmarks.js:71` calls `POST /api/characters/chats` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/chats`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2e69463f24bbdb38", "name": "Dangling fetch: POST /api/groups/create (public/scripts/bookmarks.js:378)", "shortDescription": {"text": "Dangling fetch: POST /api/groups/create (public/scripts/bookmarks.js:378)"}, "fullDescription": {"text": "`public/scripts/bookmarks.js:378` calls `POST /api/groups/create` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/groups/create`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-18801a44e3f33081", "name": "Dangling fetch: POST /api/files/sanitize-filename (public/scripts/utils.js:1619)", "shortDescription": {"text": "Dangling fetch: POST /api/files/sanitize-filename (public/scripts/utils.js:1619)"}, "fullDescription": {"text": "`public/scripts/utils.js:1619` calls `POST /api/files/sanitize-filename` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/files/sanitize-filename`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b817fce404beb767", "name": "Dangling fetch: POST /api/images/upload (public/scripts/utils.js:1662)", "shortDescription": {"text": "Dangling fetch: POST /api/images/upload (public/scripts/utils.js:1662)"}, "fullDescription": {"text": "`public/scripts/utils.js:1662` calls `POST /api/images/upload` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/images/upload`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-38d6cf4b463d243e", "name": "Dangling fetch: POST /api/plugins/office/probe (public/scripts/utils.js:2106)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/office/probe (public/scripts/utils.js:2106)"}, "fullDescription": {"text": "`public/scripts/utils.js:2106` calls `POST /api/plugins/office/probe` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/office/probe`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c2f7d12853aa4a02", "name": "Dangling fetch: POST /api/plugins/office/parse (public/scripts/utils.js:2125)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/office/parse (public/scripts/utils.js:2125)"}, "fullDescription": {"text": "`public/scripts/utils.js:2125` calls `POST /api/plugins/office/parse` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/office/parse`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-cac5a176b69ffba5", "name": "Dangling fetch: GET /css/${name} (public/scripts/utils.js:2581)", "shortDescription": {"text": "Dangling fetch: GET /css/${name} (public/scripts/utils.js:2581)"}, "fullDescription": {"text": "`public/scripts/utils.js:2581` calls `GET /css/${name}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/css/<p>`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0bba926017144658", "name": "Dangling fetch: POST /api/content/importURL (public/scripts/utils.js:2982)", "shortDescription": {"text": "Dangling fetch: POST /api/content/importURL (public/scripts/utils.js:2982)"}, "fullDescription": {"text": "`public/scripts/utils.js:2982` calls `POST /api/content/importURL` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/content/importurl`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f8bc1bd8ca84efe9", "name": "Dangling fetch: POST /api/content/importUUID (public/scripts/utils.js:2989)", "shortDescription": {"text": "Dangling fetch: POST /api/content/importUUID (public/scripts/utils.js:2989)"}, "fullDescription": {"text": "`public/scripts/utils.js:2989` calls `POST /api/content/importUUID` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/content/importuuid`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c36d1a77612c0efc", "name": "Dangling fetch: POST /api/users/list (public/scripts/login.js:24)", "shortDescription": {"text": "Dangling fetch: POST /api/users/list (public/scripts/login.js:24)"}, "fullDescription": {"text": "`public/scripts/login.js:24` calls `POST /api/users/list` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/list`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2cfe8076e142bfda", "name": "Dangling fetch: POST /api/users/recover-step1 (public/scripts/login.js:53)", "shortDescription": {"text": "Dangling fetch: POST /api/users/recover-step1 (public/scripts/login.js:53)"}, "fullDescription": {"text": "`public/scripts/login.js:53` calls `POST /api/users/recover-step1` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/recover-step1`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-615c464b0b4e12fa", "name": "Dangling fetch: POST /api/users/recover-step2 (public/scripts/login.js:84)", "shortDescription": {"text": "Dangling fetch: POST /api/users/recover-step2 (public/scripts/login.js:84)"}, "fullDescription": {"text": "`public/scripts/login.js:84` calls `POST /api/users/recover-step2` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/recover-step2`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b192d96d9708d69f", "name": "Dangling fetch: POST /api/users/login (public/scripts/login.js:115)", "shortDescription": {"text": "Dangling fetch: POST /api/users/login (public/scripts/login.js:115)"}, "fullDescription": {"text": "`public/scripts/login.js:115` calls `POST /api/users/login` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/login`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-50d32f895c58e254", "name": "Dangling fetch: POST /api/worldinfo/get (public/scripts/world-info.js:2045)", "shortDescription": {"text": "Dangling fetch: POST /api/worldinfo/get (public/scripts/world-info.js:2045)"}, "fullDescription": {"text": "`public/scripts/world-info.js:2045` calls `POST /api/worldinfo/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/worldinfo/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f9afb473f19068ef", "name": "Dangling fetch: POST /api/settings/get (public/scripts/world-info.js:2062)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/get (public/scripts/world-info.js:2062)"}, "fullDescription": {"text": "`public/scripts/world-info.js:2062` calls `POST /api/settings/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bd1fc503613c0daa", "name": "Dangling fetch: POST /api/worldinfo/edit (public/scripts/world-info.js:4075)", "shortDescription": {"text": "Dangling fetch: POST /api/worldinfo/edit (public/scripts/world-info.js:4075)"}, "fullDescription": {"text": "`public/scripts/world-info.js:4075` calls `POST /api/worldinfo/edit` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/worldinfo/edit`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-263114710f40a27e", "name": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/world-info.js:4187)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/world-info.js:4187)"}, "fullDescription": {"text": "`public/scripts/world-info.js:4187` calls `POST /api/characters/merge-attributes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/merge-attributes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1fef1cc1909be69f", "name": "Dangling fetch: POST /api/worldinfo/delete (public/scripts/world-info.js:4239)", "shortDescription": {"text": "Dangling fetch: POST /api/worldinfo/delete (public/scripts/world-info.js:4239)"}, "fullDescription": {"text": "`public/scripts/world-info.js:4239` calls `POST /api/worldinfo/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/worldinfo/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-fdc59de11e7eb40d", "name": "Dangling fetch: POST /api/worldinfo/import (public/scripts/world-info.js:5785)", "shortDescription": {"text": "Dangling fetch: POST /api/worldinfo/import (public/scripts/world-info.js:5785)"}, "fullDescription": {"text": "`public/scripts/world-info.js:5785` calls `POST /api/worldinfo/import` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/worldinfo/import`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-89c94404088b48b4", "name": "Dangling fetch: POST /api/backups/chat/download (public/scripts/chat-backups.js:29)", "shortDescription": {"text": "Dangling fetch: POST /api/backups/chat/download (public/scripts/chat-backups.js:29)"}, "fullDescription": {"text": "`public/scripts/chat-backups.js:29` calls `POST /api/backups/chat/download` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backups/chat/download`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-76fcea4b021068b2", "name": "Dangling fetch: POST /api/backups/chat/delete (public/scripts/chat-backups.js:128)", "shortDescription": {"text": "Dangling fetch: POST /api/backups/chat/delete (public/scripts/chat-backups.js:128)"}, "fullDescription": {"text": "`public/scripts/chat-backups.js:128` calls `POST /api/backups/chat/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backups/chat/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f54aa36ae78f8cd4", "name": "Dangling fetch: POST /api/backups/chat/get (public/scripts/chat-backups.js:156)", "shortDescription": {"text": "Dangling fetch: POST /api/backups/chat/get (public/scripts/chat-backups.js:156)"}, "fullDescription": {"text": "`public/scripts/chat-backups.js:156` calls `POST /api/backups/chat/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backups/chat/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-fe9fe8eddcf87808", "name": "Dangling fetch: POST /api/backends/text-completions/generate (public/scripts/custom-request.js:147)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/text-completions/generate (public/scripts/custom-request.js:147)"}, "fullDescription": {"text": "`public/scripts/custom-request.js:147` calls `POST /api/backends/text-completions/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/text-completions/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-89ed0bc64355d654", "name": "Dangling fetch: POST /api/backends/chat-completions/generate (public/scripts/custom-request.js:463)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/chat-completions/generate (public/scripts/custom-request.js:463)"}, "fullDescription": {"text": "`public/scripts/custom-request.js:463` calls `POST /api/backends/chat-completions/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/chat-completions/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9e809b4c89906d44", "name": "Dangling fetch: POST /api/stats/get (public/scripts/stats.js:179)", "shortDescription": {"text": "Dangling fetch: POST /api/stats/get (public/scripts/stats.js:179)"}, "fullDescription": {"text": "`public/scripts/stats.js:179` calls `POST /api/stats/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/stats/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4c4a47042f7a2e57", "name": "Dangling fetch: POST /api/stats/recreate (public/scripts/stats.js:202)", "shortDescription": {"text": "Dangling fetch: POST /api/stats/recreate (public/scripts/stats.js:202)"}, "fullDescription": {"text": "`public/scripts/stats.js:202` calls `POST /api/stats/recreate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/stats/recreate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bec448d326a13f97", "name": "Dangling fetch: POST /api/stats/update (public/scripts/stats.js:238)", "shortDescription": {"text": "Dangling fetch: POST /api/stats/update (public/scripts/stats.js:238)"}, "fullDescription": {"text": "`public/scripts/stats.js:238` calls `POST /api/stats/update` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/stats/update`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f1697549d3f6f8f3", "name": "Dangling fetch: POST /api/openrouter/models/providers (public/scripts/textgen-models.js:365)", "shortDescription": {"text": "Dangling fetch: POST /api/openrouter/models/providers (public/scripts/textgen-models.js:365)"}, "fullDescription": {"text": "`public/scripts/textgen-models.js:365` calls `POST /api/openrouter/models/providers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openrouter/models/providers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8500ac9b26e1dfe8", "name": "Dangling fetch: POST /api/nanogpt/models/providers (public/scripts/textgen-models.js:413)", "shortDescription": {"text": "Dangling fetch: POST /api/nanogpt/models/providers (public/scripts/textgen-models.js:413)"}, "fullDescription": {"text": "`public/scripts/textgen-models.js:413` calls `POST /api/nanogpt/models/providers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/nanogpt/models/providers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c6f8de2f23bcc7f7", "name": "Dangling fetch: POST /api/backends/text-completions/ollama/download (public/scripts/textgen-models.js:1182)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/text-completions/ollama/download (public/scripts/textgen-models.js:1182)"}, "fullDescription": {"text": "`public/scripts/textgen-models.js:1182` calls `POST /api/backends/text-completions/ollama/download` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/text-completions/ollama/download`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0cc4f92a90b0fc8a", "name": "Dangling fetch: POST /api/backends/text-completions/tabby/download (public/scripts/textgen-models.js:1252)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/text-completions/tabby/download (public/scripts/textgen-models.js:1252)"}, "fullDescription": {"text": "`public/scripts/textgen-models.js:1252` calls `POST /api/backends/text-completions/tabby/download` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/text-completions/tabby/download`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5f2dbebd8b27fd5c", "name": "Dangling fetch: POST /api/search/visit (public/scripts/scrapers.js:193)", "shortDescription": {"text": "Dangling fetch: POST /api/search/visit (public/scripts/scrapers.js:193)"}, "fullDescription": {"text": "`public/scripts/scrapers.js:193` calls `POST /api/search/visit` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/search/visit`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-18072d162bc52543", "name": "Dangling fetch: POST /api/plugins/fandom/probe-mediawiki (public/scripts/scrapers.js:260)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/fandom/probe-mediawiki (public/scripts/scrapers.js:260)"}, "fullDescription": {"text": "`public/scripts/scrapers.js:260` calls `POST /api/plugins/fandom/probe-mediawiki` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/fandom/probe-mediawiki`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2c299b8a46efba10", "name": "Dangling fetch: POST /api/plugins/fandom/scrape-mediawiki (public/scripts/scrapers.js:301)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/fandom/scrape-mediawiki (public/scripts/scrapers.js:301)"}, "fullDescription": {"text": "`public/scripts/scrapers.js:301` calls `POST /api/plugins/fandom/scrape-mediawiki` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/fandom/scrape-mediawiki`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9be1ecf2a597510c", "name": "Dangling fetch: POST /api/plugins/fandom/probe (public/scripts/scrapers.js:353)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/fandom/probe (public/scripts/scrapers.js:353)"}, "fullDescription": {"text": "`public/scripts/scrapers.js:353` calls `POST /api/plugins/fandom/probe` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/fandom/probe`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-cdc22a8191d0e968", "name": "Dangling fetch: POST /api/plugins/fandom/scrape (public/scripts/scrapers.js:408)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/fandom/scrape (public/scripts/scrapers.js:408)"}, "fullDescription": {"text": "`public/scripts/scrapers.js:408` calls `POST /api/plugins/fandom/scrape` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/fandom/scrape`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-fa848a21a28ec035", "name": "Dangling fetch: POST /api/search/transcript (public/scripts/scrapers.js:558)", "shortDescription": {"text": "Dangling fetch: POST /api/search/transcript (public/scripts/scrapers.js:558)"}, "fullDescription": {"text": "`public/scripts/scrapers.js:558` calls `POST /api/search/transcript` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/search/transcript`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-54d4ee1bc334cbde", "name": "Dangling fetch: POST /api/chats/recent (public/scripts/welcome-screen.js:765)", "shortDescription": {"text": "Dangling fetch: POST /api/chats/recent (public/scripts/welcome-screen.js:765)"}, "fullDescription": {"text": "`public/scripts/welcome-screen.js:765` calls `POST /api/chats/recent` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/chats/recent`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-343925906fe789af", "name": "Dangling fetch: POST /api/characters/create (public/scripts/welcome-screen.js:869)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/create (public/scripts/welcome-screen.js:869)"}, "fullDescription": {"text": "`public/scripts/welcome-screen.js:869` calls `POST /api/characters/create` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/create`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6332eaebf21bb091", "name": "Dangling fetch: POST /api/characters/duplicate (public/scripts/BulkEditOverlay.js:48)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/duplicate (public/scripts/BulkEditOverlay.js:48)"}, "fullDescription": {"text": "`public/scripts/BulkEditOverlay.js:48` calls `POST /api/characters/duplicate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/duplicate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5ad741d21093b932", "name": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/BulkEditOverlay.js:84)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/BulkEditOverlay.js:84)"}, "fullDescription": {"text": "`public/scripts/BulkEditOverlay.js:84` calls `POST /api/characters/merge-attributes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/merge-attributes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8d79b5c6c6a5e6fc", "name": "Dangling fetch: POST /api/avatars/get (public/scripts/personas.js:276)", "shortDescription": {"text": "Dangling fetch: POST /api/avatars/get (public/scripts/personas.js:276)"}, "fullDescription": {"text": "`public/scripts/personas.js:276` calls `POST /api/avatars/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/avatars/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a7f1220b93b5b398", "name": "Dangling fetch: POST /api/avatars/upload (public/scripts/personas.js:370)", "shortDescription": {"text": "Dangling fetch: POST /api/avatars/upload (public/scripts/personas.js:370)"}, "fullDescription": {"text": "`public/scripts/personas.js:370` calls `POST /api/avatars/upload` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/avatars/upload`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-76c7df36add082f3", "name": "Dangling fetch: POST /api/avatars/delete (public/scripts/personas.js:1170)", "shortDescription": {"text": "Dangling fetch: POST /api/avatars/delete (public/scripts/personas.js:1170)"}, "fullDescription": {"text": "`public/scripts/personas.js:1170` calls `POST /api/avatars/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/avatars/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8989f669d7f875b2", "name": "Dangling fetch: POST /api/horde/text-workers (public/scripts/horde.js:42)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/text-workers (public/scripts/horde.js:42)"}, "fullDescription": {"text": "`public/scripts/horde.js:42` calls `POST /api/horde/text-workers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/text-workers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d9dae982e99792e5", "name": "Dangling fetch: POST /api/horde/text-models (public/scripts/horde.js:56)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/text-models (public/scripts/horde.js:56)"}, "fullDescription": {"text": "`public/scripts/horde.js:56` calls `POST /api/horde/text-models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/text-models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c5d939673e306319", "name": "Dangling fetch: POST /api/horde/task-status (public/scripts/horde.js:73)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/task-status (public/scripts/horde.js:73)"}, "fullDescription": {"text": "`public/scripts/horde.js:73` calls `POST /api/horde/task-status` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/task-status`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2fff114372ae1187", "name": "Dangling fetch: POST /api/horde/cancel-task (public/scripts/horde.js:91)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/cancel-task (public/scripts/horde.js:91)"}, "fullDescription": {"text": "`public/scripts/horde.js:91` calls `POST /api/horde/cancel-task` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/cancel-task`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3425a325afcebf88", "name": "Dangling fetch: POST /api/horde/status (public/scripts/horde.js:108)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/status (public/scripts/horde.js:108)"}, "fullDescription": {"text": "`public/scripts/horde.js:108` calls `POST /api/horde/status` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/status`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2cae3f22d51fb7fd", "name": "Dangling fetch: POST /api/horde/generate-text (public/scripts/horde.js:221)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/generate-text (public/scripts/horde.js:221)"}, "fullDescription": {"text": "`public/scripts/horde.js:221` calls `POST /api/horde/generate-text` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/generate-text`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b1b0355626486504", "name": "Dangling fetch: POST /api/horde/user-info (public/scripts/horde.js:328)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/user-info (public/scripts/horde.js:328)"}, "fullDescription": {"text": "`public/scripts/horde.js:328` calls `POST /api/horde/user-info` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/user-info`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-119c299745daf06e", "name": "Dangling fetch: GET /api/users/me (public/scripts/user.js:64)", "shortDescription": {"text": "Dangling fetch: GET /api/users/me (public/scripts/user.js:64)"}, "fullDescription": {"text": "`public/scripts/user.js:64` calls `GET /api/users/me` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/me`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-99c2c8128d19d25b", "name": "Dangling fetch: POST /api/users/get (public/scripts/user.js:85)", "shortDescription": {"text": "Dangling fetch: POST /api/users/get (public/scripts/user.js:85)"}, "fullDescription": {"text": "`public/scripts/user.js:85` calls `POST /api/users/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6c1c8e5287015075", "name": "Dangling fetch: POST /api/users/enable (public/scripts/user.js:108)", "shortDescription": {"text": "Dangling fetch: POST /api/users/enable (public/scripts/user.js:108)"}, "fullDescription": {"text": "`public/scripts/user.js:108` calls `POST /api/users/enable` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/enable`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-365e03545fec76a1", "name": "Dangling fetch: POST /api/users/disable (public/scripts/user.js:128)", "shortDescription": {"text": "Dangling fetch: POST /api/users/disable (public/scripts/user.js:128)"}, "fullDescription": {"text": "`public/scripts/user.js:128` calls `POST /api/users/disable` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/disable`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-42d34bc568c10037", "name": "Dangling fetch: POST /api/users/promote (public/scripts/user.js:154)", "shortDescription": {"text": "Dangling fetch: POST /api/users/promote (public/scripts/user.js:154)"}, "fullDescription": {"text": "`public/scripts/user.js:154` calls `POST /api/users/promote` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/promote`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2fc8dab5fa795ee2", "name": "Dangling fetch: POST /api/users/demote (public/scripts/user.js:179)", "shortDescription": {"text": "Dangling fetch: POST /api/users/demote (public/scripts/user.js:179)"}, "fullDescription": {"text": "`public/scripts/user.js:179` calls `POST /api/users/demote` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/demote`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0fc291cc3effda40", "name": "Dangling fetch: POST /api/users/create (public/scripts/user.js:230)", "shortDescription": {"text": "Dangling fetch: POST /api/users/create (public/scripts/user.js:230)"}, "fullDescription": {"text": "`public/scripts/user.js:230` calls `POST /api/users/create` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/create`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2c89c058f783d076", "name": "Dangling fetch: POST /api/users/backup (public/scripts/user.js:258)", "shortDescription": {"text": "Dangling fetch: POST /api/users/backup (public/scripts/user.js:258)"}, "fullDescription": {"text": "`public/scripts/user.js:258` calls `POST /api/users/backup` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/backup`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-009b47a7667a24bd", "name": "Dangling fetch: POST /api/users/change-password (public/scripts/user.js:322)", "shortDescription": {"text": "Dangling fetch: POST /api/users/change-password (public/scripts/user.js:322)"}, "fullDescription": {"text": "`public/scripts/user.js:322` calls `POST /api/users/change-password` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/change-password`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-dca9e302148c3d0d", "name": "Dangling fetch: POST /api/users/delete (public/scripts/user.js:376)", "shortDescription": {"text": "Dangling fetch: POST /api/users/delete (public/scripts/user.js:376)"}, "fullDescription": {"text": "`public/scripts/user.js:376` calls `POST /api/users/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1e099e0050071db8", "name": "Dangling fetch: POST /api/users/reset-settings (public/scripts/user.js:413)", "shortDescription": {"text": "Dangling fetch: POST /api/users/reset-settings (public/scripts/user.js:413)"}, "fullDescription": {"text": "`public/scripts/user.js:413` calls `POST /api/users/reset-settings` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/reset-settings`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-aa0b1852fe7c31d7", "name": "Dangling fetch: POST /api/users/change-name (public/scripts/user.js:449)", "shortDescription": {"text": "Dangling fetch: POST /api/users/change-name (public/scripts/user.js:449)"}, "fullDescription": {"text": "`public/scripts/user.js:449` calls `POST /api/users/change-name` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/change-name`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-37cf792873a55a61", "name": "Dangling fetch: POST /api/settings/restore-snapshot (public/scripts/user.js:486)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/restore-snapshot (public/scripts/user.js:486)"}, "fullDescription": {"text": "`public/scripts/user.js:486` calls `POST /api/settings/restore-snapshot` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/restore-snapshot`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-feae004a75189e35", "name": "Dangling fetch: POST /api/settings/load-snapshot (public/scripts/user.js:511)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/load-snapshot (public/scripts/user.js:511)"}, "fullDescription": {"text": "`public/scripts/user.js:511` calls `POST /api/settings/load-snapshot` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/load-snapshot`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b178392fd0e2e73c", "name": "Dangling fetch: POST /api/settings/get-snapshots (public/scripts/user.js:539)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/get-snapshots (public/scripts/user.js:539)"}, "fullDescription": {"text": "`public/scripts/user.js:539` calls `POST /api/settings/get-snapshots` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/get-snapshots`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0080040f7936ddeb", "name": "Dangling fetch: POST /api/settings/make-snapshot (public/scripts/user.js:565)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/make-snapshot (public/scripts/user.js:565)"}, "fullDescription": {"text": "`public/scripts/user.js:565` calls `POST /api/settings/make-snapshot` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/make-snapshot`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4a8896798b8dc559", "name": "Dangling fetch: POST /api/users/reset-step1 (public/scripts/user.js:623)", "shortDescription": {"text": "Dangling fetch: POST /api/users/reset-step1 (public/scripts/user.js:623)"}, "fullDescription": {"text": "`public/scripts/user.js:623` calls `POST /api/users/reset-step1` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/reset-step1`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d87ac68eda8a664a", "name": "Dangling fetch: POST /api/users/reset-step2 (public/scripts/user.js:655)", "shortDescription": {"text": "Dangling fetch: POST /api/users/reset-step2 (public/scripts/user.js:655)"}, "fullDescription": {"text": "`public/scripts/user.js:655` calls `POST /api/users/reset-step2` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/reset-step2`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-527ef19beba3239f", "name": "Dangling fetch: POST /api/users/change-avatar (public/scripts/user.js:764)", "shortDescription": {"text": "Dangling fetch: POST /api/users/change-avatar (public/scripts/user.js:764)"}, "fullDescription": {"text": "`public/scripts/user.js:764` calls `POST /api/users/change-avatar` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/change-avatar`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3456249d340d5ae4", "name": "Dangling fetch: POST /api/users/logout (public/scripts/user.js:862)", "shortDescription": {"text": "Dangling fetch: POST /api/users/logout (public/scripts/user.js:862)"}, "fullDescription": {"text": "`public/scripts/user.js:862` calls `POST /api/users/logout` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/logout`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-269d71e40b7b4222", "name": "Dangling fetch: POST /api/users/slugify (public/scripts/user.js:884)", "shortDescription": {"text": "Dangling fetch: POST /api/users/slugify (public/scripts/user.js:884)"}, "fullDescription": {"text": "`public/scripts/user.js:884` calls `POST /api/users/slugify` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/users/slugify`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-343fa191dcb6780b", "name": "Dangling fetch: POST /api/presets/save (public/scripts/preset-manager.js:477)", "shortDescription": {"text": "Dangling fetch: POST /api/presets/save (public/scripts/preset-manager.js:477)"}, "fullDescription": {"text": "`public/scripts/preset-manager.js:477` calls `POST /api/presets/save` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/presets/save`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-36c868f258f99940", "name": "Dangling fetch: POST /api/presets/delete (public/scripts/preset-manager.js:809)", "shortDescription": {"text": "Dangling fetch: POST /api/presets/delete (public/scripts/preset-manager.js:809)"}, "fullDescription": {"text": "`public/scripts/preset-manager.js:809` calls `POST /api/presets/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/presets/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5761ca1fe77bb1de", "name": "Dangling fetch: POST /api/presets/restore (public/scripts/preset-manager.js:824)", "shortDescription": {"text": "Dangling fetch: POST /api/presets/restore (public/scripts/preset-manager.js:824)"}, "fullDescription": {"text": "`public/scripts/preset-manager.js:824` calls `POST /api/presets/restore` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/presets/restore`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c7605e77d7775b93", "name": "Dangling fetch: POST /api/secrets/settings (public/scripts/secrets.js:291)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/settings (public/scripts/secrets.js:291)"}, "fullDescription": {"text": "`public/scripts/secrets.js:291` calls `POST /api/secrets/settings` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/settings`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-af147f213f895e33", "name": "Dangling fetch: POST /api/secrets/view (public/scripts/secrets.js:309)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/view (public/scripts/secrets.js:309)"}, "fullDescription": {"text": "`public/scripts/secrets.js:309` calls `POST /api/secrets/view` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/view`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-66374b37ee77944c", "name": "Dangling fetch: POST /api/secrets/write (public/scripts/secrets.js:361)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/write (public/scripts/secrets.js:361)"}, "fullDescription": {"text": "`public/scripts/secrets.js:361` calls `POST /api/secrets/write` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/write`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-be387eeb9623a3f6", "name": "Dangling fetch: POST /api/secrets/delete (public/scripts/secrets.js:390)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/delete (public/scripts/secrets.js:390)"}, "fullDescription": {"text": "`public/scripts/secrets.js:390` calls `POST /api/secrets/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0f8bd72dfd4f16e6", "name": "Dangling fetch: POST /api/secrets/read (public/scripts/secrets.js:413)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/read (public/scripts/secrets.js:413)"}, "fullDescription": {"text": "`public/scripts/secrets.js:413` calls `POST /api/secrets/read` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/read`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-9ae0dd030db9b248", "name": "Dangling fetch: POST /api/secrets/find (public/scripts/secrets.js:436)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/find (public/scripts/secrets.js:436)"}, "fullDescription": {"text": "`public/scripts/secrets.js:436` calls `POST /api/secrets/find` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/find`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b4f88e133bd77310", "name": "Dangling fetch: POST /api/secrets/rotate (public/scripts/secrets.js:461)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/rotate (public/scripts/secrets.js:461)"}, "fullDescription": {"text": "`public/scripts/secrets.js:461` calls `POST /api/secrets/rotate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/rotate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b72f76719767d492", "name": "Dangling fetch: POST /api/secrets/rename (public/scripts/secrets.js:486)", "shortDescription": {"text": "Dangling fetch: POST /api/secrets/rename (public/scripts/secrets.js:486)"}, "fullDescription": {"text": "`public/scripts/secrets.js:486` calls `POST /api/secrets/rename` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/secrets/rename`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ab0b5e391b0d0d51", "name": "Dangling fetch: POST /api/openrouter/credits (public/scripts/secrets.js:1176)", "shortDescription": {"text": "Dangling fetch: POST /api/openrouter/credits (public/scripts/secrets.js:1176)"}, "fullDescription": {"text": "`public/scripts/secrets.js:1176` calls `POST /api/openrouter/credits` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openrouter/credits`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5d6f2dfad8ed69cf", "name": "Dangling fetch: POST /api/nanogpt/credits (public/scripts/secrets.js:1242)", "shortDescription": {"text": "Dangling fetch: POST /api/nanogpt/credits (public/scripts/secrets.js:1242)"}, "fullDescription": {"text": "`public/scripts/secrets.js:1242` calls `POST /api/nanogpt/credits` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/nanogpt/credits`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-78cde9dfb142f201", "name": "Dangling fetch: POST /api/files/upload (public/scripts/chats.js:276)", "shortDescription": {"text": "Dangling fetch: POST /api/files/upload (public/scripts/chats.js:276)"}, "fullDescription": {"text": "`public/scripts/chats.js:276` calls `POST /api/files/upload` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/files/upload`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-25be55d8c812abf7", "name": "Dangling fetch: POST /api/images/delete (public/scripts/chats.js:1099)", "shortDescription": {"text": "Dangling fetch: POST /api/images/delete (public/scripts/chats.js:1099)"}, "fullDescription": {"text": "`public/scripts/chats.js:1099` calls `POST /api/images/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/images/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5ca70521ba399d15", "name": "Dangling fetch: POST /api/files/delete (public/scripts/chats.js:1130)", "shortDescription": {"text": "Dangling fetch: POST /api/files/delete (public/scripts/chats.js:1130)"}, "fullDescription": {"text": "`public/scripts/chats.js:1130` calls `POST /api/files/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/files/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3daaeec984550dc9", "name": "Dangling fetch: POST /api/files/verify (public/scripts/chats.js:1832)", "shortDescription": {"text": "Dangling fetch: POST /api/files/verify (public/scripts/chats.js:1832)"}, "fullDescription": {"text": "`public/scripts/chats.js:1832` calls `POST /api/files/verify` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/files/verify`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7815171688fe9fdc", "name": "Dangling fetch: POST /api/backends/chat-completions/bias?model=${getTokenizerModel()} (public/scripts/openai.js:3311)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/chat-completions/bias?model=${getTokenizerModel()} (public/scripts/openai.js:3311)"}, "fullDescription": {"text": "`public/scripts/openai.js:3311` calls `POST /api/backends/chat-completions/bias?model=${getTokenizerModel()}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/chat-completions/bias`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-839edef6aeb3b649", "name": "Dangling fetch: POST /api/backends/chat-completions/status (public/scripts/openai.js:4437)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/chat-completions/status (public/scripts/openai.js:4437)"}, "fullDescription": {"text": "`public/scripts/openai.js:4437` calls `POST /api/backends/chat-completions/status` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/chat-completions/status`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-199810519d4637bf", "name": "Dangling fetch: POST /api/presets/save (public/scripts/openai.js:4495)", "shortDescription": {"text": "Dangling fetch: POST /api/presets/save (public/scripts/openai.js:4495)"}, "fullDescription": {"text": "`public/scripts/openai.js:4495` calls `POST /api/presets/save` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/presets/save`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a2f9a0a83ce5d8f8", "name": "Dangling fetch: POST /api/presets/delete (public/scripts/openai.js:4860)", "shortDescription": {"text": "Dangling fetch: POST /api/presets/delete (public/scripts/openai.js:4860)"}, "fullDescription": {"text": "`public/scripts/openai.js:4860` calls `POST /api/presets/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/presets/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2a1c7101ae801e31", "name": "Dangling fetch: GET /api/extensions/discover (public/scripts/extensions.js:300)", "shortDescription": {"text": "Dangling fetch: GET /api/extensions/discover (public/scripts/extensions.js:300)"}, "fullDescription": {"text": "`public/scripts/extensions.js:300` calls `GET /api/extensions/discover` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/discover`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-61379ce63048f0f4", "name": "Dangling fetch: GET /scripts/extensions/${name}/${localeFile} (public/scripts/extensions.js:862)", "shortDescription": {"text": "Dangling fetch: GET /scripts/extensions/${name}/${localeFile} (public/scripts/extensions.js:862)"}, "fullDescription": {"text": "`public/scripts/extensions.js:862` calls `GET /scripts/extensions/${name}/${localeFile}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/scripts/extensions/<p>/<p>`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4ef5d3d429090b3d", "name": "Dangling fetch: POST /api/extensions/update (public/scripts/extensions.js:1360)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/update (public/scripts/extensions.js:1360)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1360` calls `POST /api/extensions/update` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/update`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7c254df773cf6cb6", "name": "Dangling fetch: POST /api/extensions/move (public/scripts/extensions.js:1531)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/move (public/scripts/extensions.js:1531)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1531` calls `POST /api/extensions/move` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/move`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-03065065ddde743b", "name": "Dangling fetch: POST /api/extensions/delete (public/scripts/extensions.js:1571)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/delete (public/scripts/extensions.js:1571)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1571` calls `POST /api/extensions/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0289f5e95345fe70", "name": "Dangling fetch: POST /api/extensions/version (public/scripts/extensions.js:1601)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/version (public/scripts/extensions.js:1601)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1601` calls `POST /api/extensions/version` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/version`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2ad68bdb842552e6", "name": "Dangling fetch: POST /api/extensions/branches (public/scripts/extensions.js:1634)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/branches (public/scripts/extensions.js:1634)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1634` calls `POST /api/extensions/branches` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/branches`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6effcf40a9893366", "name": "Dangling fetch: POST /api/extensions/switch (public/scripts/extensions.js:1666)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/switch (public/scripts/extensions.js:1666)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1666` calls `POST /api/extensions/switch` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/switch`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-45925e1c67a784ea", "name": "Dangling fetch: POST /api/extensions/install (public/scripts/extensions.js:1746)", "shortDescription": {"text": "Dangling fetch: POST /api/extensions/install (public/scripts/extensions.js:1746)"}, "fullDescription": {"text": "`public/scripts/extensions.js:1746` calls `POST /api/extensions/install` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extensions/install`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a021b244c6cd4d81", "name": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/extensions.js:2102)", "shortDescription": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/extensions.js:2102)"}, "fullDescription": {"text": "`public/scripts/extensions.js:2102` calls `POST /api/characters/merge-attributes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/characters/merge-attributes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-64527557e1701b75", "name": "Dangling fetch: POST /api/plugins/edge-tts/probe (public/scripts/extensions/tts/edge.js:260)", "shortDescription": {"text": "Dangling fetch: POST /api/plugins/edge-tts/probe (public/scripts/extensions/tts/edge.js:260)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/edge.js:260` calls `POST /api/plugins/edge-tts/probe` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/plugins/edge-tts/probe`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-738f260a1397907b", "name": "Dangling fetch: POST /api/google/list-native-voices (public/scripts/extensions/tts/google-native.js:96)", "shortDescription": {"text": "Dangling fetch: POST /api/google/list-native-voices (public/scripts/extensions/tts/google-native.js:96)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/google-native.js:96` calls `POST /api/google/list-native-voices` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/google/list-native-voices`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e4fbdd6a83ca88bb", "name": "Dangling fetch: POST /api/google/generate-native-tts (public/scripts/extensions/tts/google-native.js:164)", "shortDescription": {"text": "Dangling fetch: POST /api/google/generate-native-tts (public/scripts/extensions/tts/google-native.js:164)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/google-native.js:164` calls `POST /api/google/generate-native-tts` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/google/generate-native-tts`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-55336261ce244896", "name": "Dangling fetch: POST /api/openai/chutes/generate-voice (public/scripts/extensions/tts/chutes.js:201)", "shortDescription": {"text": "Dangling fetch: POST /api/openai/chutes/generate-voice (public/scripts/extensions/tts/chutes.js:201)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/chutes.js:201` calls `POST /api/openai/chutes/generate-voice` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openai/chutes/generate-voice`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3e5af3add9ae32b1", "name": "Dangling fetch: POST /api/speech/synthesize (public/scripts/extensions/tts/speecht5.js:175)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/synthesize (public/scripts/extensions/tts/speecht5.js:175)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/speecht5.js:175` calls `POST /api/speech/synthesize` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/synthesize`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2c8d9401aa225030", "name": "Dangling fetch: POST /api/azure/list (public/scripts/extensions/tts/azure.js:143)", "shortDescription": {"text": "Dangling fetch: POST /api/azure/list (public/scripts/extensions/tts/azure.js:143)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/azure.js:143` calls `POST /api/azure/list` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/azure/list`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d3a83d925f1eed3b", "name": "Dangling fetch: POST /api/azure/generate (public/scripts/extensions/tts/azure.js:191)", "shortDescription": {"text": "Dangling fetch: POST /api/azure/generate (public/scripts/extensions/tts/azure.js:191)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/azure.js:191` calls `POST /api/azure/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/azure/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c2368cd5c081ff23", "name": "Dangling fetch: POST /api/volcengine/generate-voice (public/scripts/extensions/tts/volcengine.js:297)", "shortDescription": {"text": "Dangling fetch: POST /api/volcengine/generate-voice (public/scripts/extensions/tts/volcengine.js:297)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/volcengine.js:297` calls `POST /api/volcengine/generate-voice` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/volcengine/generate-voice`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3eca027af67cc020", "name": "Dangling fetch: POST /api/openai/electronhub/models (public/scripts/extensions/tts/electronhub.js:188)", "shortDescription": {"text": "Dangling fetch: POST /api/openai/electronhub/models (public/scripts/extensions/tts/electronhub.js:188)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/electronhub.js:188` calls `POST /api/openai/electronhub/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openai/electronhub/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-78289626452477a2", "name": "Dangling fetch: POST /api/openai/electronhub/generate-voice (public/scripts/extensions/tts/electronhub.js:443)", "shortDescription": {"text": "Dangling fetch: POST /api/openai/electronhub/generate-voice (public/scripts/extensions/tts/electronhub.js:443)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/electronhub.js:443` calls `POST /api/openai/electronhub/generate-voice` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openai/electronhub/generate-voice`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-44af6ebc1813d27b", "name": "Dangling fetch: POST /api/speech/elevenlabs/voices (public/scripts/extensions/tts/elevenlabs.js:304)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/elevenlabs/voices (public/scripts/extensions/tts/elevenlabs.js:304)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/elevenlabs.js:304` calls `POST /api/speech/elevenlabs/voices` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/elevenlabs/voices`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4df8cc5c22b17748", "name": "Dangling fetch: POST /api/speech/elevenlabs/voice-settings (public/scripts/extensions/tts/elevenlabs.js:316)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/elevenlabs/voice-settings (public/scripts/extensions/tts/elevenlabs.js:316)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/elevenlabs.js:316` calls `POST /api/speech/elevenlabs/voice-settings` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/elevenlabs/voice-settings`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-61fce680324cca19", "name": "Dangling fetch: POST /api/speech/elevenlabs/synthesize (public/scripts/extensions/tts/elevenlabs.js:348)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/elevenlabs/synthesize (public/scripts/extensions/tts/elevenlabs.js:348)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/elevenlabs.js:348` calls `POST /api/speech/elevenlabs/synthesize` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/elevenlabs/synthesize`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5a8d46e447d26eb3", "name": "Dangling fetch: POST /api/speech/elevenlabs/history-audio (public/scripts/extensions/tts/elevenlabs.js:370)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/elevenlabs/history-audio (public/scripts/extensions/tts/elevenlabs.js:370)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/elevenlabs.js:370` calls `POST /api/speech/elevenlabs/history-audio` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/elevenlabs/history-audio`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2ca36c9c5fe40c54", "name": "Dangling fetch: POST /api/speech/elevenlabs/history (public/scripts/extensions/tts/elevenlabs.js:388)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/elevenlabs/history (public/scripts/extensions/tts/elevenlabs.js:388)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/elevenlabs.js:388` calls `POST /api/speech/elevenlabs/history` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/elevenlabs/history`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1d15fbe8f6c70208", "name": "Dangling fetch: POST /api/speech/elevenlabs/voices/add (public/scripts/extensions/tts/elevenlabs.js:424)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/elevenlabs/voices/add (public/scripts/extensions/tts/elevenlabs.js:424)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/elevenlabs.js:424` calls `POST /api/speech/elevenlabs/voices/add` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/elevenlabs/voices/add`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-35cf14539cc4b94a", "name": "Dangling fetch: POST /api/minimax/generate-voice (public/scripts/extensions/tts/minimax.js:806)", "shortDescription": {"text": "Dangling fetch: POST /api/minimax/generate-voice (public/scripts/extensions/tts/minimax.js:806)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/minimax.js:806` calls `POST /api/minimax/generate-voice` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/minimax/generate-voice`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-69b3999e46ef3629", "name": "Dangling fetch: POST /api/speech/pollinations/voices (public/scripts/extensions/tts/pollinations.js:91)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/pollinations/voices (public/scripts/extensions/tts/pollinations.js:91)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/pollinations.js:91` calls `POST /api/speech/pollinations/voices` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/pollinations/voices`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-01937f3332a0df0e", "name": "Dangling fetch: POST /api/speech/pollinations/generate (public/scripts/extensions/tts/pollinations.js:133)", "shortDescription": {"text": "Dangling fetch: POST /api/speech/pollinations/generate (public/scripts/extensions/tts/pollinations.js:133)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/pollinations.js:133` calls `POST /api/speech/pollinations/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/speech/pollinations/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6a0831767ccb60c4", "name": "Dangling fetch: POST /api/novelai/generate-voice (public/scripts/extensions/tts/novel.js:198)", "shortDescription": {"text": "Dangling fetch: POST /api/novelai/generate-voice (public/scripts/extensions/tts/novel.js:198)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/novel.js:198` calls `POST /api/novelai/generate-voice` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/novelai/generate-voice`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-32b40909d895ec67", "name": "Dangling fetch: POST /api/openai/generate-voice (public/scripts/extensions/tts/openai.js:239)", "shortDescription": {"text": "Dangling fetch: POST /api/openai/generate-voice (public/scripts/extensions/tts/openai.js:239)"}, "fullDescription": {"text": "`public/scripts/extensions/tts/openai.js:239` calls `POST /api/openai/generate-voice` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openai/generate-voice`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d0f6c9bf109cf2ec", "name": "Dangling fetch: POST /api/translate/onering (public/scripts/extensions/translate/index.js:254)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/onering (public/scripts/extensions/translate/index.js:254)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:254` calls `POST /api/translate/onering` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/onering`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3b887c483d96c63e", "name": "Dangling fetch: POST /api/translate/libre (public/scripts/extensions/translate/index.js:275)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/libre (public/scripts/extensions/translate/index.js:275)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:275` calls `POST /api/translate/libre` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/libre`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1f692d5895f6bfb2", "name": "Dangling fetch: POST /api/translate/google (public/scripts/extensions/translate/index.js:296)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/google (public/scripts/extensions/translate/index.js:296)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:296` calls `POST /api/translate/google` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/google`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-86a4ae38746c45d3", "name": "Dangling fetch: POST /api/translate/lingva (public/scripts/extensions/translate/index.js:317)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/lingva (public/scripts/extensions/translate/index.js:317)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:317` calls `POST /api/translate/lingva` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/lingva`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2e5255a0eac4ebc9", "name": "Dangling fetch: POST /api/translate/deepl (public/scripts/extensions/translate/index.js:343)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/deepl (public/scripts/extensions/translate/index.js:343)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:343` calls `POST /api/translate/deepl` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/deepl`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f1c0a119acb935c2", "name": "Dangling fetch: POST /api/translate/deeplx (public/scripts/extensions/translate/index.js:364)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/deeplx (public/scripts/extensions/translate/index.js:364)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:364` calls `POST /api/translate/deeplx` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/deeplx`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f762924a40c6d35c", "name": "Dangling fetch: POST /api/translate/bing (public/scripts/extensions/translate/index.js:385)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/bing (public/scripts/extensions/translate/index.js:385)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:385` calls `POST /api/translate/bing` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/bing`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b15c1ab1d4731bbc", "name": "Dangling fetch: POST /api/translate/yandex (public/scripts/extensions/translate/index.js:413)", "shortDescription": {"text": "Dangling fetch: POST /api/translate/yandex (public/scripts/extensions/translate/index.js:413)"}, "fullDescription": {"text": "`public/scripts/extensions/translate/index.js:413` calls `POST /api/translate/yandex` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/translate/yandex`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5bec82e06abc7e85", "name": "Dangling fetch: POST /api/extra/caption (public/scripts/extensions/caption/index.js:274)", "shortDescription": {"text": "Dangling fetch: POST /api/extra/caption (public/scripts/extensions/caption/index.js:274)"}, "fullDescription": {"text": "`public/scripts/extensions/caption/index.js:274` calls `POST /api/extra/caption` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extra/caption`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f7a4c0e5d27b98d3", "name": "Dangling fetch: POST /api/horde/caption-image (public/scripts/extensions/caption/index.js:294)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/caption-image (public/scripts/extensions/caption/index.js:294)"}, "fullDescription": {"text": "`public/scripts/extensions/caption/index.js:294` calls `POST /api/horde/caption-image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/caption-image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5ca4ccff159d72ea", "name": "Dangling fetch: POST /api/assets/download (public/scripts/extensions/assets/index.js:390)", "shortDescription": {"text": "Dangling fetch: POST /api/assets/download (public/scripts/extensions/assets/index.js:390)"}, "fullDescription": {"text": "`public/scripts/extensions/assets/index.js:390` calls `POST /api/assets/download` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/assets/download`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a38b8bf9a6d00a4a", "name": "Dangling fetch: POST /api/assets/delete (public/scripts/extensions/assets/index.js:433)", "shortDescription": {"text": "Dangling fetch: POST /api/assets/delete (public/scripts/extensions/assets/index.js:433)"}, "fullDescription": {"text": "`public/scripts/extensions/assets/index.js:433` calls `POST /api/assets/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/assets/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-cfcc1ec8eb9cf280", "name": "Dangling fetch: POST /api/assets/get (public/scripts/extensions/assets/index.js:515)", "shortDescription": {"text": "Dangling fetch: POST /api/assets/get (public/scripts/extensions/assets/index.js:515)"}, "fullDescription": {"text": "`public/scripts/extensions/assets/index.js:515` calls `POST /api/assets/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/assets/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4473b05432aeb320", "name": "Dangling fetch: POST /api/vector/list (public/scripts/extensions/vectors/index.js:1027)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/list (public/scripts/extensions/vectors/index.js:1027)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1027` calls `POST /api/vector/list` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/list`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7689eceaddc06242", "name": "Dangling fetch: POST /api/vector/insert (public/scripts/extensions/vectors/index.js:1055)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/insert (public/scripts/extensions/vectors/index.js:1055)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1055` calls `POST /api/vector/insert` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/insert`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0bb9f33b58b471a8", "name": "Dangling fetch: POST /api/vector/delete (public/scripts/extensions/vectors/index.js:1129)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/delete (public/scripts/extensions/vectors/index.js:1129)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1129` calls `POST /api/vector/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6449486fcec94e69", "name": "Dangling fetch: POST /api/vector/query (public/scripts/extensions/vectors/index.js:1153)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/query (public/scripts/extensions/vectors/index.js:1153)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1153` calls `POST /api/vector/query` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/query`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-07b9fe713b96ca45", "name": "Dangling fetch: POST /api/vector/query-multi (public/scripts/extensions/vectors/index.js:1183)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/query-multi (public/scripts/extensions/vectors/index.js:1183)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1183` calls `POST /api/vector/query-multi` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/query-multi`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d5e6ac77fc2d2e4c", "name": "Dangling fetch: POST /api/vector/purge (public/scripts/extensions/vectors/index.js:1216)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/purge (public/scripts/extensions/vectors/index.js:1216)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1216` calls `POST /api/vector/purge` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/purge`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-86fcf72ae9873ce9", "name": "Dangling fetch: POST /api/vector/purge-all (public/scripts/extensions/vectors/index.js:1272)", "shortDescription": {"text": "Dangling fetch: POST /api/vector/purge-all (public/scripts/extensions/vectors/index.js:1272)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1272` calls `POST /api/vector/purge-all` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/vector/purge-all`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7f7fe989d3d431d0", "name": "Dangling fetch: POST /api/backends/kobold/embed (public/scripts/extensions/vectors/index.js:1455)", "shortDescription": {"text": "Dangling fetch: POST /api/backends/kobold/embed (public/scripts/extensions/vectors/index.js:1455)"}, "fullDescription": {"text": "`public/scripts/extensions/vectors/index.js:1455` calls `POST /api/backends/kobold/embed` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/backends/kobold/embed`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ffbfbe83b710a323", "name": "Dangling fetch: POST /api/images/list (public/scripts/extensions/gallery/index.js:115)", "shortDescription": {"text": "Dangling fetch: POST /api/images/list (public/scripts/extensions/gallery/index.js:115)"}, "fullDescription": {"text": "`public/scripts/extensions/gallery/index.js:115` calls `POST /api/images/list` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/images/list`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-31876a3a50b7f6fe", "name": "Dangling fetch: POST /api/images/folders (public/scripts/extensions/gallery/index.js:160)", "shortDescription": {"text": "Dangling fetch: POST /api/images/folders (public/scripts/extensions/gallery/index.js:160)"}, "fullDescription": {"text": "`public/scripts/extensions/gallery/index.js:160` calls `POST /api/images/folders` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/images/folders`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5c118dc9b321b577", "name": "Dangling fetch: POST /api/settings/get (public/scripts/extensions/quick-reply/index.js:56)", "shortDescription": {"text": "Dangling fetch: POST /api/settings/get (public/scripts/extensions/quick-reply/index.js:56)"}, "fullDescription": {"text": "`public/scripts/extensions/quick-reply/index.js:56` calls `POST /api/settings/get` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/settings/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-14143310963dcb2c", "name": "Dangling fetch: GET /scripts/extensions/quick-reply/html/qrEditor.html (public/scripts/extensions/quick-reply/src/QuickR", "shortDescription": {"text": "Dangling fetch: GET /scripts/extensions/quick-reply/html/qrEditor.html (public/scripts/extensions/quick-reply/src/QuickReply.js:385)"}, "fullDescription": {"text": "`public/scripts/extensions/quick-reply/src/QuickReply.js:385` calls `GET /scripts/extensions/quick-reply/html/qrEditor.html` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/scripts/extensions/quick-reply/html/qreditor.html`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2a093a20176749f9", "name": "Dangling fetch: POST /api/quick-replies/save (public/scripts/extensions/quick-reply/src/QuickReplySet.js:377)", "shortDescription": {"text": "Dangling fetch: POST /api/quick-replies/save (public/scripts/extensions/quick-reply/src/QuickReplySet.js:377)"}, "fullDescription": {"text": "`public/scripts/extensions/quick-reply/src/QuickReplySet.js:377` calls `POST /api/quick-replies/save` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/quick-replies/save`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1f87c83277f8c159", "name": "Dangling fetch: POST /api/quick-replies/delete (public/scripts/extensions/quick-reply/src/QuickReplySet.js:392)", "shortDescription": {"text": "Dangling fetch: POST /api/quick-replies/delete (public/scripts/extensions/quick-reply/src/QuickReplySet.js:392)"}, "fullDescription": {"text": "`public/scripts/extensions/quick-reply/src/QuickReplySet.js:392` calls `POST /api/quick-replies/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/quick-replies/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-81d26fc478c0fe91", "name": "Dangling fetch: GET /scripts/extensions/quick-reply/html/settings.html (public/scripts/extensions/quick-reply/src/ui/Set", "shortDescription": {"text": "Dangling fetch: GET /scripts/extensions/quick-reply/html/settings.html (public/scripts/extensions/quick-reply/src/ui/SettingsUi.js:54)"}, "fullDescription": {"text": "`public/scripts/extensions/quick-reply/src/ui/SettingsUi.js:54` calls `GET /scripts/extensions/quick-reply/html/settings.html` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/scripts/extensions/quick-reply/html/settings.html`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7be79d5fb432937f", "name": "Dangling fetch: POST /api/sd/ping (public/scripts/extensions/stable-diffusion/index.js:1353)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/ping (public/scripts/extensions/stable-diffusion/index.js:1353)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1353` calls `POST /api/sd/ping` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/ping`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-777dc64c4a7a4e96", "name": "Dangling fetch: POST /api/sd/sdcpp/ping (public/scripts/extensions/stable-diffusion/index.js:1376)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/sdcpp/ping (public/scripts/extensions/stable-diffusion/index.js:1376)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1376` calls `POST /api/sd/sdcpp/ping` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/sdcpp/ping`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0c9f9dfd8dc57af4", "name": "Dangling fetch: POST /api/sd/drawthings/ping (public/scripts/extensions/stable-diffusion/index.js:1399)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/drawthings/ping (public/scripts/extensions/stable-diffusion/index.js:1399)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1399` calls `POST /api/sd/drawthings/ping` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/drawthings/ping`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-300944e554f5bbca", "name": "Dangling fetch: POST /api/sd/comfy/ping (public/scripts/extensions/stable-diffusion/index.js:1445)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/ping (public/scripts/extensions/stable-diffusion/index.js:1445)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1445` calls `POST /api/sd/comfy/ping` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/ping`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0e94ed84bcef1c1f", "name": "Dangling fetch: POST /api/sd/comfyrunpod/ping (public/scripts/extensions/stable-diffusion/index.js:1469)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfyrunpod/ping (public/scripts/extensions/stable-diffusion/index.js:1469)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1469` calls `POST /api/sd/comfyrunpod/ping` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfyrunpod/ping`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-e9e35974912c1231", "name": "Dangling fetch: POST /api/sd/get-model (public/scripts/extensions/stable-diffusion/index.js:1522)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/get-model (public/scripts/extensions/stable-diffusion/index.js:1522)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1522` calls `POST /api/sd/get-model` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/get-model`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c4199cb4d74db639", "name": "Dangling fetch: POST /api/sd/drawthings/get-model (public/scripts/extensions/stable-diffusion/index.js:1541)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/drawthings/get-model (public/scripts/extensions/stable-diffusion/index.js:1541)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1541` calls `POST /api/sd/drawthings/get-model` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/drawthings/get-model`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b88dd5fb825dafb3", "name": "Dangling fetch: POST /api/sd/upscalers (public/scripts/extensions/stable-diffusion/index.js:1564)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/upscalers (public/scripts/extensions/stable-diffusion/index.js:1564)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1564` calls `POST /api/sd/upscalers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/upscalers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5b6df393face9d5a", "name": "Dangling fetch: POST /api/sd/schedulers (public/scripts/extensions/stable-diffusion/index.js:1583)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/schedulers (public/scripts/extensions/stable-diffusion/index.js:1583)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1583` calls `POST /api/sd/schedulers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/schedulers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-86f1b56de1b51740", "name": "Dangling fetch: POST /api/sd/sd-next/upscalers (public/scripts/extensions/stable-diffusion/index.js:1602)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/sd-next/upscalers (public/scripts/extensions/stable-diffusion/index.js:1602)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1602` calls `POST /api/sd/sd-next/upscalers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/sd-next/upscalers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6a4b641d0be87922", "name": "Dangling fetch: POST /api/sd/drawthings/get-upscaler (public/scripts/extensions/stable-diffusion/index.js:1621)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/drawthings/get-upscaler (public/scripts/extensions/stable-diffusion/index.js:1621)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1621` calls `POST /api/sd/drawthings/get-upscaler` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/drawthings/get-upscaler`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7da19687a640a44a", "name": "Dangling fetch: POST /api/sd/set-model (public/scripts/extensions/stable-diffusion/index.js:1642)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/set-model (public/scripts/extensions/stable-diffusion/index.js:1642)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1642` calls `POST /api/sd/set-model` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/set-model`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-211b7c7b1e63f162", "name": "Dangling fetch: POST /api/horde/sd-samplers (public/scripts/extensions/stable-diffusion/index.js:1766)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/sd-samplers (public/scripts/extensions/stable-diffusion/index.js:1766)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1766` calls `POST /api/horde/sd-samplers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/sd-samplers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1e694f3d9aefab9e", "name": "Dangling fetch: POST /api/sd/samplers (public/scripts/extensions/stable-diffusion/index.js:1801)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/samplers (public/scripts/extensions/stable-diffusion/index.js:1801)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1801` calls `POST /api/sd/samplers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/samplers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-659586fa770a5f58", "name": "Dangling fetch: POST /api/sd/sdcpp/models (public/scripts/extensions/stable-diffusion/index.js:1823)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/sdcpp/models (public/scripts/extensions/stable-diffusion/index.js:1823)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1823` calls `POST /api/sd/sdcpp/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/sdcpp/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0b63d5db30da36e5", "name": "Dangling fetch: POST /api/sd/comfy/samplers (public/scripts/extensions/stable-diffusion/index.js:1909)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/samplers (public/scripts/extensions/stable-diffusion/index.js:1909)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:1909` calls `POST /api/sd/comfy/samplers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/samplers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1c14fb6bb1f0355f", "name": "Dangling fetch: POST /api/sd/falai/models (public/scripts/extensions/stable-diffusion/index.js:2110)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/falai/models (public/scripts/extensions/stable-diffusion/index.js:2110)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2110` calls `POST /api/sd/falai/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/falai/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bcb934f0afea6486", "name": "Dangling fetch: POST /api/sd/workersai/models (public/scripts/extensions/stable-diffusion/index.js:2141)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/workersai/models (public/scripts/extensions/stable-diffusion/index.js:2141)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2141` calls `POST /api/sd/workersai/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/workersai/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2eb636264a022851", "name": "Dangling fetch: POST /api/sd/pollinations/models (public/scripts/extensions/stable-diffusion/index.js:2159)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/pollinations/models (public/scripts/extensions/stable-diffusion/index.js:2159)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2159` calls `POST /api/sd/pollinations/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/pollinations/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-54bab08a2cb868f5", "name": "Dangling fetch: POST /api/sd/together/models (public/scripts/extensions/stable-diffusion/index.js:2177)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/together/models (public/scripts/extensions/stable-diffusion/index.js:2177)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2177` calls `POST /api/sd/together/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/together/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-408fe525fea1385c", "name": "Dangling fetch: POST /api/sd/chutes/models (public/scripts/extensions/stable-diffusion/index.js:2195)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/chutes/models (public/scripts/extensions/stable-diffusion/index.js:2195)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2195` calls `POST /api/sd/chutes/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/chutes/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-39efd5e2008eb9cb", "name": "Dangling fetch: POST /api/sd/electronhub/models (public/scripts/extensions/stable-diffusion/index.js:2216)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/electronhub/models (public/scripts/extensions/stable-diffusion/index.js:2216)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2216` calls `POST /api/sd/electronhub/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/electronhub/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b33ae31a32879a01", "name": "Dangling fetch: POST /api/sd/nanogpt/models (public/scripts/extensions/stable-diffusion/index.js:2249)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/nanogpt/models (public/scripts/extensions/stable-diffusion/index.js:2249)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2249` calls `POST /api/sd/nanogpt/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/nanogpt/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6fddccc5951b4341", "name": "Dangling fetch: POST /api/horde/sd-models (public/scripts/extensions/stable-diffusion/index.js:2262)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/sd-models (public/scripts/extensions/stable-diffusion/index.js:2262)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2262` calls `POST /api/horde/sd-models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/sd-models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-982197701b4c58a7", "name": "Dangling fetch: POST /api/sd/models (public/scripts/extensions/stable-diffusion/index.js:2317)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/models (public/scripts/extensions/stable-diffusion/index.js:2317)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2317` calls `POST /api/sd/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-422b55ee7a12cbe5", "name": "Dangling fetch: POST /api/sd/aimlapi/models (public/scripts/extensions/stable-diffusion/index.js:2401)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/aimlapi/models (public/scripts/extensions/stable-diffusion/index.js:2401)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2401` calls `POST /api/sd/aimlapi/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/aimlapi/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-0d3562b08a53baec", "name": "Dangling fetch: POST /api/openrouter/models/image (public/scripts/extensions/stable-diffusion/index.js:2525)", "shortDescription": {"text": "Dangling fetch: POST /api/openrouter/models/image (public/scripts/extensions/stable-diffusion/index.js:2525)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2525` calls `POST /api/openrouter/models/image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openrouter/models/image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-61c47a6c1868b8ca", "name": "Dangling fetch: POST /api/sd/comfy/models (public/scripts/extensions/stable-diffusion/index.js:2553)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/models (public/scripts/extensions/stable-diffusion/index.js:2553)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2553` calls `POST /api/sd/comfy/models` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/models`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a95163d435d68e93", "name": "Dangling fetch: POST /api/sd/comfy/schedulers (public/scripts/extensions/stable-diffusion/index.js:2671)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/schedulers (public/scripts/extensions/stable-diffusion/index.js:2671)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2671` calls `POST /api/sd/comfy/schedulers` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/schedulers`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-79f23601878caa6a", "name": "Dangling fetch: POST /api/sd/vaes (public/scripts/extensions/stable-diffusion/index.js:2791)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/vaes (public/scripts/extensions/stable-diffusion/index.js:2791)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2791` calls `POST /api/sd/vaes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/vaes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5bd9f5fae85ffa03", "name": "Dangling fetch: POST /api/sd/comfy/vaes (public/scripts/extensions/stable-diffusion/index.js:2818)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/vaes (public/scripts/extensions/stable-diffusion/index.js:2818)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2818` calls `POST /api/sd/comfy/vaes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/vaes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-663cb9153164f25a", "name": "Dangling fetch: POST /api/sd/comfy/workflows (public/scripts/extensions/stable-diffusion/index.js:2837)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/workflows (public/scripts/extensions/stable-diffusion/index.js:2837)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:2837` calls `POST /api/sd/comfy/workflows` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/workflows`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-bf6e404676aeb1d1", "name": "Dangling fetch: POST /api/sd/together/generate (public/scripts/extensions/stable-diffusion/index.js:3461)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/together/generate (public/scripts/extensions/stable-diffusion/index.js:3461)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3461` calls `POST /api/sd/together/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/together/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-77f30aa36d141b41", "name": "Dangling fetch: POST /api/sd/pollinations/generate (public/scripts/extensions/stable-diffusion/index.js:3492)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/pollinations/generate (public/scripts/extensions/stable-diffusion/index.js:3492)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3492` calls `POST /api/sd/pollinations/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/pollinations/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-130e31b569bf08c7", "name": "Dangling fetch: POST /api/sd/electronhub/sizes (public/scripts/extensions/stable-diffusion/index.js:3650)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/electronhub/sizes (public/scripts/extensions/stable-diffusion/index.js:3650)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3650` calls `POST /api/sd/electronhub/sizes` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/electronhub/sizes`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-c8376a9a20f96151", "name": "Dangling fetch: POST /api/sd/stability/generate (public/scripts/extensions/stable-diffusion/index.js:3716)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/stability/generate (public/scripts/extensions/stable-diffusion/index.js:3716)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3716` calls `POST /api/sd/stability/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/stability/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8885a03363951843", "name": "Dangling fetch: POST /api/horde/generate-image (public/scripts/extensions/stable-diffusion/index.js:3758)", "shortDescription": {"text": "Dangling fetch: POST /api/horde/generate-image (public/scripts/extensions/stable-diffusion/index.js:3758)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3758` calls `POST /api/horde/generate-image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/horde/generate-image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a64d253a77435dcb", "name": "Dangling fetch: POST /api/sd/generate (public/scripts/extensions/stable-diffusion/index.js:3848)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/generate (public/scripts/extensions/stable-diffusion/index.js:3848)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3848` calls `POST /api/sd/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-f1d6152343141aef", "name": "Dangling fetch: POST /api/sd/sdcpp/generate (public/scripts/extensions/stable-diffusion/index.js:3898)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/sdcpp/generate (public/scripts/extensions/stable-diffusion/index.js:3898)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3898` calls `POST /api/sd/sdcpp/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/sdcpp/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-8856d8c4fd3048f4", "name": "Dangling fetch: POST /api/sd/drawthings/generate (public/scripts/extensions/stable-diffusion/index.js:3923)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/drawthings/generate (public/scripts/extensions/stable-diffusion/index.js:3923)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3923` calls `POST /api/sd/drawthings/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/drawthings/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-40972fb202994159", "name": "Dangling fetch: POST /api/novelai/generate-image (public/scripts/extensions/stable-diffusion/index.js:3966)", "shortDescription": {"text": "Dangling fetch: POST /api/novelai/generate-image (public/scripts/extensions/stable-diffusion/index.js:3966)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:3966` calls `POST /api/novelai/generate-image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/novelai/generate-image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-15331ac1e41b73f3", "name": "Dangling fetch: POST /api/openai/generate-video (public/scripts/extensions/stable-diffusion/index.js:4124)", "shortDescription": {"text": "Dangling fetch: POST /api/openai/generate-video (public/scripts/extensions/stable-diffusion/index.js:4124)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4124` calls `POST /api/openai/generate-video` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openai/generate-video`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-dc352058b786e0e5", "name": "Dangling fetch: POST /api/openai/generate-image (public/scripts/extensions/stable-diffusion/index.js:4144)", "shortDescription": {"text": "Dangling fetch: POST /api/openai/generate-image (public/scripts/extensions/stable-diffusion/index.js:4144)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4144` calls `POST /api/openai/generate-image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openai/generate-image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-642e0de853c2dcdb", "name": "Dangling fetch: POST /api/sd/aimlapi/generate-image (public/scripts/extensions/stable-diffusion/index.js:4198)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/aimlapi/generate-image (public/scripts/extensions/stable-diffusion/index.js:4198)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4198` calls `POST /api/sd/aimlapi/generate-image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/aimlapi/generate-image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-dce5d8addf7e4660", "name": "Dangling fetch: POST /api/sd/comfy/workflow (public/scripts/extensions/stable-diffusion/index.js:4222)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/workflow (public/scripts/extensions/stable-diffusion/index.js:4222)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4222` calls `POST /api/sd/comfy/workflow` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/workflow`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-7424224aaee105e1", "name": "Dangling fetch: POST /api/sd/huggingface/generate (public/scripts/extensions/stable-diffusion/index.js:4343)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/huggingface/generate (public/scripts/extensions/stable-diffusion/index.js:4343)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4343` calls `POST /api/sd/huggingface/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/huggingface/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-4db7c5e27d5d5149", "name": "Dangling fetch: POST /api/sd/chutes/generate (public/scripts/extensions/stable-diffusion/index.js:4370)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/chutes/generate (public/scripts/extensions/stable-diffusion/index.js:4370)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4370` calls `POST /api/sd/chutes/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/chutes/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-5924b595f2196d3a", "name": "Dangling fetch: POST /api/sd/electronhub/generate (public/scripts/extensions/stable-diffusion/index.js:4403)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/electronhub/generate (public/scripts/extensions/stable-diffusion/index.js:4403)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4403` calls `POST /api/sd/electronhub/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/electronhub/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-80613b8817c1338c", "name": "Dangling fetch: POST /api/sd/nanogpt/generate (public/scripts/extensions/stable-diffusion/index.js:4432)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/nanogpt/generate (public/scripts/extensions/stable-diffusion/index.js:4432)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4432` calls `POST /api/sd/nanogpt/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/nanogpt/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3923826fcd4b73d8", "name": "Dangling fetch: POST /api/sd/bfl/generate (public/scripts/extensions/stable-diffusion/index.js:4466)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/bfl/generate (public/scripts/extensions/stable-diffusion/index.js:4466)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4466` calls `POST /api/sd/bfl/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/bfl/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b62c4daa519a6242", "name": "Dangling fetch: POST /api/sd/xai/generate (public/scripts/extensions/stable-diffusion/index.js:4509)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/xai/generate (public/scripts/extensions/stable-diffusion/index.js:4509)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4509` calls `POST /api/sd/xai/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/xai/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-b5c256cd967aee97", "name": "Dangling fetch: POST /api/sd/falai/generate (public/scripts/extensions/stable-diffusion/index.js:4538)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/falai/generate (public/scripts/extensions/stable-diffusion/index.js:4538)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4538` calls `POST /api/sd/falai/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/falai/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-2306d180b9086465", "name": "Dangling fetch: POST /api/google/generate-video (public/scripts/extensions/stable-diffusion/index.js:4576)", "shortDescription": {"text": "Dangling fetch: POST /api/google/generate-video (public/scripts/extensions/stable-diffusion/index.js:4576)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4576` calls `POST /api/google/generate-video` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/google/generate-video`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-3a3df48da855bae1", "name": "Dangling fetch: POST /api/google/generate-image (public/scripts/extensions/stable-diffusion/index.js:4603)", "shortDescription": {"text": "Dangling fetch: POST /api/google/generate-image (public/scripts/extensions/stable-diffusion/index.js:4603)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4603` calls `POST /api/google/generate-image` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/google/generate-image`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-98b04ec5d83f472d", "name": "Dangling fetch: POST /api/sd/zai/generate-video (public/scripts/extensions/stable-diffusion/index.js:4649)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/zai/generate-video (public/scripts/extensions/stable-diffusion/index.js:4649)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4649` calls `POST /api/sd/zai/generate-video` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/zai/generate-video`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-82b06b6e21290dcf", "name": "Dangling fetch: POST /api/sd/zai/generate (public/scripts/extensions/stable-diffusion/index.js:4688)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/zai/generate (public/scripts/extensions/stable-diffusion/index.js:4688)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4688` calls `POST /api/sd/zai/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/zai/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ba8b66db876ceb87", "name": "Dangling fetch: POST /api/openrouter/image/generate (public/scripts/extensions/stable-diffusion/index.js:4717)", "shortDescription": {"text": "Dangling fetch: POST /api/openrouter/image/generate (public/scripts/extensions/stable-diffusion/index.js:4717)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4717` calls `POST /api/openrouter/image/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/openrouter/image/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-29838c78dff6d0c5", "name": "Dangling fetch: POST /api/sd/workersai/generate (public/scripts/extensions/stable-diffusion/index.js:4738)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/workersai/generate (public/scripts/extensions/stable-diffusion/index.js:4738)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4738` calls `POST /api/sd/workersai/generate` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/workersai/generate`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-175cf3119b2acc91", "name": "Dangling fetch: POST /api/sd/comfy/save-workflow (public/scripts/extensions/stable-diffusion/index.js:4842)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/save-workflow (public/scripts/extensions/stable-diffusion/index.js:4842)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4842` calls `POST /api/sd/comfy/save-workflow` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/save-workflow`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-fbc9af0bb293ae0a", "name": "Dangling fetch: POST /api/sd/comfy/delete-workflow (public/scripts/extensions/stable-diffusion/index.js:4889)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/delete-workflow (public/scripts/extensions/stable-diffusion/index.js:4889)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4889` calls `POST /api/sd/comfy/delete-workflow` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/delete-workflow`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-a208d45e7d84b221", "name": "Dangling fetch: POST /api/sd/comfy/rename-workflow (public/scripts/extensions/stable-diffusion/index.js:4936)", "shortDescription": {"text": "Dangling fetch: POST /api/sd/comfy/rename-workflow (public/scripts/extensions/stable-diffusion/index.js:4936)"}, "fullDescription": {"text": "`public/scripts/extensions/stable-diffusion/index.js:4936` calls `POST /api/sd/comfy/rename-workflow` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sd/comfy/rename-workflow`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-ec9908545571366f", "name": "Dangling fetch: POST /api/extra/classify (public/scripts/extensions/expressions/index.js:1062)", "shortDescription": {"text": "Dangling fetch: POST /api/extra/classify (public/scripts/extensions/expressions/index.js:1062)"}, "fullDescription": {"text": "`public/scripts/extensions/expressions/index.js:1062` calls `POST /api/extra/classify` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extra/classify`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-84c99297bcfca32d", "name": "Dangling fetch: GET /api/sprites/get?name=${encodeURIComponent(name)} (public/scripts/extensions/expressions/index.js:12", "shortDescription": {"text": "Dangling fetch: GET /api/sprites/get?name=${encodeURIComponent(name)} (public/scripts/extensions/expressions/index.js:1295)"}, "fullDescription": {"text": "`public/scripts/extensions/expressions/index.js:1295` calls `GET /api/sprites/get?name=${encodeURIComponent(name)}` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sprites/get`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-1d9b584c518eb89b", "name": "Dangling fetch: POST /api/extra/classify/labels (public/scripts/extensions/expressions/index.js:1445)", "shortDescription": {"text": "Dangling fetch: POST /api/extra/classify/labels (public/scripts/extensions/expressions/index.js:1445)"}, "fullDescription": {"text": "`public/scripts/extensions/expressions/index.js:1445` calls `POST /api/extra/classify/labels` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/extra/classify/labels`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-eea1c5e93a617802", "name": "Dangling fetch: POST /api/sprites/delete (public/scripts/extensions/expressions/index.js:2072)", "shortDescription": {"text": "Dangling fetch: POST /api/sprites/delete (public/scripts/extensions/expressions/index.js:2072)"}, "fullDescription": {"text": "`public/scripts/extensions/expressions/index.js:2072` calls `POST /api/sprites/delete` but no backend route in the scanned graph matches that path. This is a likely runtime 404 unless an external gateway or unsupported router provides it.\n\nTool: fetch\nNormalized path used for matching: `/sprites/delete`"}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 0.9}}, {"id": "scanner-d065b3d84e0ba3dc", "name": "282 backend endpoints not called by scanned frontend", "shortDescription": {"text": "282 backend endpoints not called by scanned frontend"}, "fullDescription": {"text": "No scanned frontend call matched these backend routes. Sample: USE /api/users, USE /proxy/:url(*), USE /api/moving-ui, USE /api/images, USE /api/quick-replies, USE /api/avatars, USE /api/themes, USE /api/openai + 274 more. This is fine when endpoints serve external clients (mobile apps, SDKs, third-party integrations, server-side webhooks). Otherwise document consumers or remove dead routes."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30795"}, "properties": {"repository": "SillyTavern/SillyTavern", "repoUrl": "https://github.com/SillyTavern/SillyTavern", "branch": "main"}, "results": [{"ruleId": "scanner-2918b141b6c3a94b", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 tests/frontend/MacroParser.e2e.js:313"}, "properties": {"repobilityId": "4bb4208d60f92a49", "scanner": "scanner-primary", "fingerprint": "2918b141b6c3a94b", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/frontend/MacroParser.e2e.js"}, "region": {"startLine": 313}}}]}, {"ruleId": "scanner-4fd89cf0d6379f5c", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 tests/frontend/MacroLexer.e2e.js:510"}, "properties": {"repobilityId": "78887485e0770b21", "scanner": "scanner-primary", "fingerprint": "4fd89cf0d6379f5c", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/frontend/MacroLexer.e2e.js"}, "region": {"startLine": 510}}}]}, {"ruleId": "scanner-71aeed7ec59d7080", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/script.js:2411"}, "properties": {"repobilityId": "e8de8d040ed5e4b4", "scanner": "scanner-primary", "fingerprint": "71aeed7ec59d7080", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 2411}}}]}, {"ruleId": "scanner-d6969ae2d61fa40d", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 public/script.js:4117"}, "properties": {"repobilityId": "5b607e6279e7a43a", "scanner": "scanner-primary", "fingerprint": "d6969ae2d61fa40d", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 4117}}}]}, {"ruleId": "scanner-0313d3f8b1568664", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/itemized-prompts.js:122"}, "properties": {"repobilityId": "a3962e223042bd61", "scanner": "scanner-primary", "fingerprint": "0313d3f8b1568664", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/itemized-prompts.js"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-e861afd764a2341f", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/power-user.js:1942"}, "properties": {"repobilityId": "c7181ab469e4d3c6", "scanner": "scanner-primary", "fingerprint": "e861afd764a2341f", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/power-user.js"}, "region": {"startLine": 1942}}}]}, {"ruleId": "scanner-572c2607fc49fe8c", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/macros.js:745"}, "properties": {"repobilityId": "97f55cc7223f6851", "scanner": "scanner-primary", "fingerprint": "572c2607fc49fe8c", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/macros.js"}, "region": {"startLine": 745}}}]}, {"ruleId": "scanner-5c1c96c4a8f407b3", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/events.js:20"}, "properties": {"repobilityId": "3cd939ac31cadf52", "scanner": "scanner-primary", "fingerprint": "5c1c96c4a8f407b3", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/events.js"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-3cab0c32a2c0cf42", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/world-info.js:955"}, "properties": {"repobilityId": "c9d1f60bd51c8c29", "scanner": "scanner-primary", "fingerprint": "3cab0c32a2c0cf42", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 955}}}]}, {"ruleId": "scanner-6ef2579b3c5049b7", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/slash-commands.js:4692"}, "properties": {"repobilityId": "9a15567ad46f997f", "scanner": "scanner-primary", "fingerprint": "6ef2579b3c5049b7", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/slash-commands.js"}, "region": {"startLine": 4692}}}]}, {"ruleId": "scanner-8a5af97b14c96574", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/PromptManager.js:1138"}, "properties": {"repobilityId": "2a4152b356aa7e64", "scanner": "scanner-primary", "fingerprint": "8a5af97b14c96574", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/PromptManager.js"}, "region": {"startLine": 1138}}}]}, {"ruleId": "scanner-b00ddfad23c60df5", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/textgen-models.js:1013"}, "properties": {"repobilityId": "b2525966dd1cf69b", "scanner": "scanner-primary", "fingerprint": "b00ddfad23c60df5", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/textgen-models.js"}, "region": {"startLine": 1013}}}]}, {"ruleId": "scanner-f409e0c8d6e1a287", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/instruct-mode.js:491"}, "properties": {"repobilityId": "3ad22d7056d4ce45", "scanner": "scanner-primary", "fingerprint": "f409e0c8d6e1a287", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/instruct-mode.js"}, "region": {"startLine": 491}}}]}, {"ruleId": "scanner-382948e05b522ae8", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/cfg-scale.js:113"}, "properties": {"repobilityId": "a4bc6235c517763b", "scanner": "scanner-primary", "fingerprint": "382948e05b522ae8", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/cfg-scale.js"}, "region": {"startLine": 113}}}]}, {"ruleId": "scanner-ce11e20fdcad2570", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/personas.js:1021"}, "properties": {"repobilityId": "564a0a134c4d9830", "scanner": "scanner-primary", "fingerprint": "ce11e20fdcad2570", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/personas.js"}, "region": {"startLine": 1021}}}]}, {"ruleId": "scanner-5d6168723359c307", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/authors-note.js:605"}, "properties": {"repobilityId": "02bc34e8a6b53857", "scanner": "scanner-primary", "fingerprint": "5d6168723359c307", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/authors-note.js"}, "region": {"startLine": 605}}}]}, {"ruleId": "scanner-ed417964809f3c84", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/openai.js:2632"}, "properties": {"repobilityId": "31df43c750736711", "scanner": "scanner-primary", "fingerprint": "ed417964809f3c84", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/openai.js"}, "region": {"startLine": 2632}}}]}, {"ruleId": "scanner-3d8ddeee40b3130d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions.js:2281"}, "properties": {"repobilityId": "9e448b89c9ee0fd4", "scanner": "scanner-primary", "fingerprint": "3d8ddeee40b3130d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 2281}}}]}, {"ruleId": "scanner-f32318d63aa662c6", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/slash-commands/SlashCommandParser.js:197"}, "properties": {"repobilityId": "af8ce1830cd30315", "scanner": "scanner-primary", "fingerprint": "f32318d63aa662c6", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/slash-commands/SlashCommandParser.js"}, "region": {"startLine": 197}}}]}, {"ruleId": "scanner-e9eb420471bf85f2", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/util/stream-fadein.js:24"}, "properties": {"repobilityId": "bae4465be7b4eb91", "scanner": "scanner-primary", "fingerprint": "e9eb420471bf85f2", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/util/stream-fadein.js"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-866e0b1664e35347", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/autocomplete/AutoComplete.js:277"}, "properties": {"repobilityId": "50f77fe2909f989c", "scanner": "scanner-primary", "fingerprint": "866e0b1664e35347", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/autocomplete/AutoComplete.js"}, "region": {"startLine": 277}}}]}, {"ruleId": "scanner-27259a777890bd94", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/macros/definitions/core-macros.js:367"}, "properties": {"repobilityId": "ba1ea2b33a5a7e30", "scanner": "scanner-primary", "fingerprint": "27259a777890bd94", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/macros/definitions/core-macros.js"}, "region": {"startLine": 367}}}]}, {"ruleId": "scanner-411ac99b9d2853b7", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/tts/pollinations.js:12"}, "properties": {"repobilityId": "4a7a5297d4bf65be", "scanner": "scanner-primary", "fingerprint": "411ac99b9d2853b7", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/pollinations.js"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-28f7a54eef335c8d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/tts/coqui.js:245"}, "properties": {"repobilityId": "d118cb82c4892afa", "scanner": "scanner-primary", "fingerprint": "28f7a54eef335c8d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/coqui.js"}, "region": {"startLine": 245}}}]}, {"ruleId": "scanner-040b44a8cfe27703", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/regex/index.js:1373"}, "properties": {"repobilityId": "16d45256477a30bd", "scanner": "scanner-primary", "fingerprint": "040b44a8cfe27703", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/regex/index.js"}, "region": {"startLine": 1373}}}]}, {"ruleId": "scanner-c89dbdfaa563b7d5", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/memory/index.js:1126"}, "properties": {"repobilityId": "55f6ee6afce504f9", "scanner": "scanner-primary", "fingerprint": "c89dbdfaa563b7d5", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/memory/index.js"}, "region": {"startLine": 1126}}}]}, {"ruleId": "scanner-363e8c66f432e726", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/quick-reply/src/QuickReply.js:290"}, "properties": {"repobilityId": "8937eee584916eb4", "scanner": "scanner-primary", "fingerprint": "363e8c66f432e726", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/src/QuickReply.js"}, "region": {"startLine": 290}}}]}, {"ruleId": "scanner-f236434c49760fa2", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/quick-reply/src/ui/SettingsUi.js:310"}, "properties": {"repobilityId": "cc884d3a1d00aa3c", "scanner": "scanner-primary", "fingerprint": "f236434c49760fa2", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/src/ui/SettingsUi.js"}, "region": {"startLine": 310}}}]}, {"ruleId": "scanner-c55108a5953fcd79", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/scripts/extensions/stable-diffusion/index.js:3942"}, "properties": {"repobilityId": "920c42644d606462", "scanner": "scanner-primary", "fingerprint": "c55108a5953fcd79", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3942}}}]}, {"ruleId": "scanner-f449aafe021e47aa", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 public/lib/toastr.min.js:6"}, "properties": {"repobilityId": "e4501ff0139153bc", "scanner": "scanner-primary", "fingerprint": "f449aafe021e47aa", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/toastr.min.js"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-abbbf23076a672d6", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 public/lib/epub.min.js:1"}, "properties": {"repobilityId": "cfe76682adb6b34f", "scanner": "scanner-primary", "fingerprint": "abbbf23076a672d6", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/epub.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-307fb1307a9578b6", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 public/lib/dialog-polyfill.esm.js:132"}, "properties": {"repobilityId": "e79ab1877f2cc175", "scanner": "scanner-primary", "fingerprint": "307fb1307a9578b6", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/dialog-polyfill.esm.js"}, "region": {"startLine": 132}}}]}, {"ruleId": "scanner-37148ca29593e1b6", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/server-main.js:368"}, "properties": {"repobilityId": "c6584dab2d4a93db", "scanner": "scanner-primary", "fingerprint": "37148ca29593e1b6", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/server-main.js"}, "region": {"startLine": 368}}}]}, {"ruleId": "scanner-86a7c45d4dd95199", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/constants.js:221"}, "properties": {"repobilityId": "d1a768bb77adbe05", "scanner": "scanner-primary", "fingerprint": "86a7c45d4dd95199", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/constants.js"}, "region": {"startLine": 221}}}]}, {"ruleId": "scanner-558750ddf501aa27", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/endpoints/search.js:370"}, "properties": {"repobilityId": "3a3678a41a31f088", "scanner": "scanner-primary", "fingerprint": "558750ddf501aa27", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/endpoints/search.js"}, "region": {"startLine": 370}}}]}, {"ruleId": "scanner-ab106d9c86a935df", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/endpoints/backends/chat-completions.js:772"}, "properties": {"repobilityId": "38cda12e477677f8", "scanner": "scanner-primary", "fingerprint": "ab106d9c86a935df", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/endpoints/backends/chat-completions.js"}, "region": {"startLine": 772}}}]}, {"ruleId": "scanner-6ff786ea1e993a28", "level": "warning", "message": {"text": "unquoted attribute var \u2014 public/scripts/extensions/connection-manager/edit.html:6"}, "properties": {"repobilityId": "b48cd147d3bff26e", "scanner": "scanner-primary", "fingerprint": "6ff786ea1e993a28", "layer": "security", "severity": "medium", "confidence": 0.55, "tags": ["semgrep", "security", "html-templates"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/connection-manager/edit.html"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-d0f3a6624ab9e7e7", "level": "warning", "message": {"text": "CVE-2026-44288: @protobufjs/utf8 1.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "e36c6fd291fe9280", "scanner": "scanner-primary", "fingerprint": "d0f3a6624ab9e7e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-2ed62e18b85d56ac", "level": "error", "message": {"text": "CVE-2026-44486: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "df95d747ea8a5d48", "scanner": "scanner-primary", "fingerprint": "2ed62e18b85d56ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44486"]}}, {"ruleId": "scanner-61dd25804f1550ff", "level": "error", "message": {"text": "CVE-2026-44487: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "dc0fed2a6be758a2", "scanner": "scanner-primary", "fingerprint": "61dd25804f1550ff", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44487"]}}, {"ruleId": "scanner-4d982114f0172043", "level": "error", "message": {"text": "CVE-2026-44488: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "460cfed74d881cfc", "scanner": "scanner-primary", "fingerprint": "4d982114f0172043", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44488"]}}, {"ruleId": "scanner-5479a2218c7e0b2a", "level": "error", "message": {"text": "CVE-2026-44492: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "721bd55cf5d6441f", "scanner": "scanner-primary", "fingerprint": "5479a2218c7e0b2a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44492"]}}, {"ruleId": "scanner-e135324a6015c309", "level": "error", "message": {"text": "CVE-2026-44494: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "b638ad8e237c2f3f", "scanner": "scanner-primary", "fingerprint": "e135324a6015c309", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44494"]}}, {"ruleId": "scanner-e9cc3c301e071e86", "level": "error", "message": {"text": "CVE-2026-44496: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "0a52470db40718ce", "scanner": "scanner-primary", "fingerprint": "e9cc3c301e071e86", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44496"]}}, {"ruleId": "scanner-d091e23f5e160179", "level": "error", "message": {"text": "GHSA-gcfj-64vw-6mp9: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "ef9489399fdf7a4e", "scanner": "scanner-primary", "fingerprint": "d091e23f5e160179", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-gcfj-64vw-6mp9"]}}, {"ruleId": "scanner-78d2f0d242b01650", "level": "warning", "message": {"text": "CVE-2026-44490: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "ae6ee68d61b62013", "scanner": "scanner-primary", "fingerprint": "78d2f0d242b01650", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44490"]}}, {"ruleId": "scanner-42fd6e6e830e6582", "level": "warning", "message": {"text": "GHSA-42h9-826w-cgv3: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "0d9c8e9fe30873ab", "scanner": "scanner-primary", "fingerprint": "42fd6e6e830e6582", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-42h9-826w-cgv3"]}}, {"ruleId": "scanner-2a59fccd12f0837b", "level": "warning", "message": {"text": "GHSA-7q8q-rj6j-mhjq: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "91ad60c5ff03c761", "scanner": "scanner-primary", "fingerprint": "2a59fccd12f0837b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-7q8q-rj6j-mhjq"]}}, {"ruleId": "scanner-b00be6728d44c9ee", "level": "warning", "message": {"text": "GHSA-f4gw-2p7v-4548: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "c687d15451f51ffe", "scanner": "scanner-primary", "fingerprint": "b00be6728d44c9ee", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f4gw-2p7v-4548"]}}, {"ruleId": "scanner-65103a713c87b1c5", "level": "warning", "message": {"text": "GHSA-hcpx-6fm6-wx23: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "24ca5d06efa5c1dd", "scanner": "scanner-primary", "fingerprint": "65103a713c87b1c5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-hcpx-6fm6-wx23"]}}, {"ruleId": "scanner-850b1e79fefb4d95", "level": "warning", "message": {"text": "GHSA-jqh4-m9w3-8hp9: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "90c7e8fb9cbaa97d", "scanner": "scanner-primary", "fingerprint": "850b1e79fefb4d95", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-jqh4-m9w3-8hp9"]}}, {"ruleId": "scanner-a6339a926059b783", "level": "warning", "message": {"text": "GHSA-mmx7-hfxf-jppx: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "5461ec5428c06e10", "scanner": "scanner-primary", "fingerprint": "a6339a926059b783", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mmx7-hfxf-jppx"]}}, {"ruleId": "scanner-75b167f9b67ee705", "level": "warning", "message": {"text": "GHSA-mwf2-3pr3-8698: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "8998840192b27da6", "scanner": "scanner-primary", "fingerprint": "75b167f9b67ee705", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-mwf2-3pr3-8698"]}}, {"ruleId": "scanner-8f7fb47273149cc6", "level": "warning", "message": {"text": "GHSA-pmv8-rq9r-6j72: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "b1b6410a2813895b", "scanner": "scanner-primary", "fingerprint": "8f7fb47273149cc6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-pmv8-rq9r-6j72"]}}, {"ruleId": "scanner-fb4818328e2c81e7", "level": "warning", "message": {"text": "GHSA-xj6q-8x83-jv6g: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "2459049e14c5f18a", "scanner": "scanner-primary", "fingerprint": "fb4818328e2c81e7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-xj6q-8x83-jv6g"]}}, {"ruleId": "scanner-d76402dfaa4deebc", "level": "note", "message": {"text": "CVE-2026-44489: axios 1.15.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "083077557d816407", "scanner": "scanner-primary", "fingerprint": "d76402dfaa4deebc", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44489"]}}, {"ruleId": "scanner-4584e5503768a719", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 1.20.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "2cc3cf9d6ecedcda", "scanner": "scanner-primary", "fingerprint": "4584e5503768a719", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-2323def9108d33da", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 2.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "8775b18ee2ab6ac7", "scanner": "scanner-primary", "fingerprint": "2323def9108d33da", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-5e05ea97a125c972", "level": "error", "message": {"text": "CVE-2026-14257: brace-expansion 2.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "54f567a7570eb6ed", "scanner": "scanner-primary", "fingerprint": "5e05ea97a125c972", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-14257"]}}, {"ruleId": "scanner-e556a14b2f71fdd9", "level": "warning", "message": {"text": "CVE-2026-49458: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "68ef9b88fbcd6698", "scanner": "scanner-primary", "fingerprint": "e556a14b2f71fdd9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49458"]}}, {"ruleId": "scanner-07ebf19b8a7f09f9", "level": "warning", "message": {"text": "CVE-2026-49459: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "c35892c95e78d1ff", "scanner": "scanner-primary", "fingerprint": "07ebf19b8a7f09f9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49459"]}}, {"ruleId": "scanner-9fc0ae253213e444", "level": "warning", "message": {"text": "CVE-2026-49978: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "60b8f9494f2fb243", "scanner": "scanner-primary", "fingerprint": "9fc0ae253213e444", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49978"]}}, {"ruleId": "scanner-d4c8406978feb84d", "level": "warning", "message": {"text": "CVE-2026-65898: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "4923826a87b11c2e", "scanner": "scanner-primary", "fingerprint": "d4c8406978feb84d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-65898"]}}, {"ruleId": "scanner-74534431657a4599", "level": "warning", "message": {"text": "CVE-2026-65902: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "f8eabe5b6523dbc2", "scanner": "scanner-primary", "fingerprint": "74534431657a4599", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-65902"]}}, {"ruleId": "scanner-0894aba2c3f41dbb", "level": "note", "message": {"text": "CVE-2026-65899: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "f8b08e600e2c4419", "scanner": "scanner-primary", "fingerprint": "0894aba2c3f41dbb", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-65899"]}}, {"ruleId": "scanner-6a99523bad6d0da0", "level": "note", "message": {"text": "CVE-2026-65900: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "75c2f7b14fdac805", "scanner": "scanner-primary", "fingerprint": "6a99523bad6d0da0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-65900"]}}, {"ruleId": "scanner-4fa4a6f3ffd21ef0", "level": "note", "message": {"text": "CVE-2026-65901: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "f63d1ee771372486", "scanner": "scanner-primary", "fingerprint": "4fa4a6f3ffd21ef0", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-65901"]}}, {"ruleId": "scanner-01f6de830a4b100c", "level": "note", "message": {"text": "GHSA-c2j3-45gr-mqc4: dompurify 3.4.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "aee0a06cc05badec", "scanner": "scanner-primary", "fingerprint": "01f6de830a4b100c", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-c2j3-45gr-mqc4"]}}, {"ruleId": "scanner-4adf6d36ffd584f8", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "85801951583e7517", "scanner": "scanner-primary", "fingerprint": "4adf6d36ffd584f8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-bf5bc3c980b78418", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "be42e91421de6101", "scanner": "scanner-primary", "fingerprint": "bf5bc3c980b78418", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-795a1c1a931b0551", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "05993e7b18c5a816", "scanner": "scanner-primary", "fingerprint": "795a1c1a931b0551", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-cf47d36fffbc9566", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "df4c97c1003072e7", "scanner": "scanner-primary", "fingerprint": "cf47d36fffbc9566", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-1ad924ae57f20cce", "level": "warning", "message": {"text": "CVE-2026-31808: file-type 16.5.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "a1c22e1e7ac7eb54", "scanner": "scanner-primary", "fingerprint": "1ad924ae57f20cce", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-31808"]}}, {"ruleId": "scanner-eab1e85fb715d773", "level": "error", "message": {"text": "CVE-2026-12143: form-data 4.0.5 \u2014 package-lock.json"}, "properties": {"repobilityId": "283ecf327c9979f0", "scanner": "scanner-primary", "fingerprint": "eab1e85fb715d773", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12143"]}}, {"ruleId": "scanner-4d821f6f21084ff1", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 9.0.5 \u2014 package-lock.json"}, "properties": {"repobilityId": "85dea9d0977e2b95", "scanner": "scanner-primary", "fingerprint": "4d821f6f21084ff1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-b9b3eec5255d3fc1", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.23 \u2014 package-lock.json"}, "properties": {"repobilityId": "bdc1eea34a7fcaeb", "scanner": "scanner-primary", "fingerprint": "b9b3eec5255d3fc1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-941ed3f6c02743e5", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.23 \u2014 package-lock.json"}, "properties": {"repobilityId": "cdf89f754cd79c7c", "scanner": "scanner-primary", "fingerprint": "941ed3f6c02743e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-eac9e36649ceed78", "level": "error", "message": {"text": "CVE-2026-5079: multer 2.1.1 \u2014 package-lock.json"}, "properties": {"repobilityId": "fa646c7cffe8a63d", "scanner": "scanner-primary", "fingerprint": "eac9e36649ceed78", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5079"]}}, {"ruleId": "scanner-9dac0055dc63b735", "level": "warning", "message": {"text": "CVE-2026-5038: multer 2.1.1 \u2014 package-lock.json"}, "properties": {"repobilityId": "53afc148aa8c275c", "scanner": "scanner-primary", "fingerprint": "9dac0055dc63b735", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-5038"]}}, {"ruleId": "scanner-dd5a75413103f67a", "level": "error", "message": {"text": "CVE-2026-41242: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "0ec5cf352f8b5ffb", "scanner": "scanner-primary", "fingerprint": "dd5a75413103f67a", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41242"]}}, {"ruleId": "scanner-97dc43230b30fb1b", "level": "error", "message": {"text": "CVE-2026-44289: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "dc709b624ced170a", "scanner": "scanner-primary", "fingerprint": "97dc43230b30fb1b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44289"]}}, {"ruleId": "scanner-41386cd14033e7a0", "level": "error", "message": {"text": "CVE-2026-44290: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "5c76d77b01cb7486", "scanner": "scanner-primary", "fingerprint": "41386cd14033e7a0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44290"]}}, {"ruleId": "scanner-d4e723f0f1b7ec96", "level": "error", "message": {"text": "CVE-2026-44291: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "bf21466190bd6142", "scanner": "scanner-primary", "fingerprint": "d4e723f0f1b7ec96", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44291"]}}, {"ruleId": "scanner-5b8857ba08f5e49a", "level": "error", "message": {"text": "CVE-2026-44293: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "eafdc11fb0943571", "scanner": "scanner-primary", "fingerprint": "5b8857ba08f5e49a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44293"]}}, {"ruleId": "scanner-ca5ad009d815e919", "level": "error", "message": {"text": "CVE-2026-48712: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "216f1086acafeac1", "scanner": "scanner-primary", "fingerprint": "ca5ad009d815e919", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48712"]}}, {"ruleId": "scanner-e2815a2c45be1156", "level": "warning", "message": {"text": "CVE-2026-44288: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "b4b8668ef6705cc5", "scanner": "scanner-primary", "fingerprint": "e2815a2c45be1156", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44288"]}}, {"ruleId": "scanner-178802405f548bd2", "level": "warning", "message": {"text": "CVE-2026-44292: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "de65536fbd4b05b5", "scanner": "scanner-primary", "fingerprint": "178802405f548bd2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44292"]}}, {"ruleId": "scanner-73654be544eed6ae", "level": "warning", "message": {"text": "CVE-2026-44294: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "eaa01ea015fd6da6", "scanner": "scanner-primary", "fingerprint": "73654be544eed6ae", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-44294"]}}, {"ruleId": "scanner-2b436fd91c94abbc", "level": "warning", "message": {"text": "CVE-2026-45740: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "ce9ca9c9ef29820d", "scanner": "scanner-primary", "fingerprint": "2b436fd91c94abbc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45740"]}}, {"ruleId": "scanner-a5c6f77d9c843c9a", "level": "warning", "message": {"text": "CVE-2026-54269: protobufjs 6.11.4 \u2014 package-lock.json"}, "properties": {"repobilityId": "b6c11f8706af2d29", "scanner": "scanner-primary", "fingerprint": "a5c6f77d9c843c9a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54269"]}}, {"ruleId": "scanner-b1c0cee138df7df1", "level": "warning", "message": {"text": "CVE-2026-8723: qs 6.14.2 \u2014 package-lock.json"}, "properties": {"repobilityId": "9874f96ea2c6eb3f", "scanner": "scanner-primary", "fingerprint": "b1c0cee138df7df1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-8723"]}}, {"ruleId": "scanner-0cdbf507bdba99d1", "level": "warning", "message": {"text": "CVE-2024-1899: showdown 2.1.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "91f32ed77f40c27e", "scanner": "scanner-primary", "fingerprint": "0cdbf507bdba99d1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2024-1899"]}}, {"ruleId": "scanner-7f1724bdeeccb121", "level": "error", "message": {"text": "CVE-2026-6951: simple-git 3.33.0 \u2014 package-lock.json"}, "properties": {"repobilityId": "86548dd8e9dd67c9", "scanner": "scanner-primary", "fingerprint": "7f1724bdeeccb121", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6951"]}}, {"ruleId": "scanner-7ae20d01f1de8a56", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 package-lock.json"}, "properties": {"repobilityId": "456116cfa0f62296", "scanner": "scanner-primary", "fingerprint": "7ae20d01f1de8a56", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-d3b41d24d73cf707", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.18.3 \u2014 package-lock.json"}, "properties": {"repobilityId": "f7e31279300ec7e6", "scanner": "scanner-primary", "fingerprint": "d3b41d24d73cf707", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-9f5abd1f03b5df58", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.18.3 \u2014 package-lock.json"}, "properties": {"repobilityId": "7635a49db32e4699", "scanner": "scanner-primary", "fingerprint": "9f5abd1f03b5df58", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-0ae996a9275eafe5", "level": "note", "message": {"text": "CVE-2026-49356: @babel/core 7.24.7 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "52db38a56be2c74b", "scanner": "scanner-primary", "fingerprint": "0ae996a9275eafe5", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-49356"]}}, {"ruleId": "scanner-175faf060975f12c", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 1.1.13 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "f47ae4104b6b2a4d", "scanner": "scanner-primary", "fingerprint": "175faf060975f12c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-40e8daee701f4340", "level": "error", "message": {"text": "CVE-2026-14257: brace-expansion 1.1.13 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "f42cc5ad618898ab", "scanner": "scanner-primary", "fingerprint": "40e8daee701f4340", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-14257"]}}, {"ruleId": "scanner-2840674e6a6dceb9", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 3.14.2 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "6f8e5898739b1aba", "scanner": "scanner-primary", "fingerprint": "2840674e6a6dceb9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-346651f3145a6d29", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 3.14.2 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "4b1a4670d4337667", "scanner": "scanner-primary", "fingerprint": "346651f3145a6d29", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-39c00fc1bc04f773", "level": "error", "message": {"text": "CVE-2026-59869: js-yaml 4.1.1 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "6f8e5898739b1aba", "scanner": "scanner-primary", "fingerprint": "39c00fc1bc04f773", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59869"]}}, {"ruleId": "scanner-e75b99201bb6d05b", "level": "warning", "message": {"text": "CVE-2026-53550: js-yaml 4.1.1 \u2014 tests/package-lock.json"}, "properties": {"repobilityId": "4b1a4670d4337667", "scanner": "scanner-primary", "fingerprint": "e75b99201bb6d05b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-53550"]}}, {"ruleId": "scanner-3a3527e70129fb18", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "properties": {"repobilityId": "691787f6b20605df", "scanner": "scanner-primary", "fingerprint": "3a3527e70129fb18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-3c4041c454cda88e", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "properties": {"repobilityId": "da995bb2cfa21f65", "scanner": "scanner-primary", "fingerprint": "3c4041c454cda88e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-d026cbfac9c2e95a", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:lts-alpine3.23"}, "properties": {"repobilityId": "d89b53f870ddf41c", "scanner": "scanner-primary", "fingerprint": "d026cbfac9c2e95a", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c1461dea687c6007", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/script.js:3669"}, "properties": {"repobilityId": "4e3c0f496f453f0f", "scanner": "scanner-primary", "fingerprint": "c1461dea687c6007", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 3669}}}]}, {"ruleId": "scanner-57fef5225c3fc086", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/power-user.js:1157"}, "properties": {"repobilityId": "cd31f8adcc17baf1", "scanner": "scanner-primary", "fingerprint": "57fef5225c3fc086", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/power-user.js"}, "region": {"startLine": 1157}}}]}, {"ruleId": "scanner-9f222b6710ebe11a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/data-maid.js:106"}, "properties": {"repobilityId": "348e2583a087b549", "scanner": "scanner-primary", "fingerprint": "9f222b6710ebe11a", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/data-maid.js"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-f33d6c2ba13b7570", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/utils.js:2581"}, "properties": {"repobilityId": "c28dd58229788630", "scanner": "scanner-primary", "fingerprint": "f33d6c2ba13b7570", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 2581}}}]}, {"ruleId": "scanner-03bd403ce7aedb9d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/slash-commands.js:4104"}, "properties": {"repobilityId": "19936a5dc3dd5dd8", "scanner": "scanner-primary", "fingerprint": "03bd403ce7aedb9d", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/slash-commands.js"}, "region": {"startLine": 4104}}}]}, {"ruleId": "scanner-d07ae44a330d531c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/PromptManager.js:1449"}, "properties": {"repobilityId": "32024f3ad866ea63", "scanner": "scanner-primary", "fingerprint": "d07ae44a330d531c", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/PromptManager.js"}, "region": {"startLine": 1449}}}]}, {"ruleId": "scanner-c9c3fdbc3c9d126e", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/PromptManager.js:1310"}, "properties": {"repobilityId": "07cd6270a12858ad", "scanner": "scanner-primary", "fingerprint": "c9c3fdbc3c9d126e", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/PromptManager.js"}, "region": {"startLine": 1310}}}]}, {"ruleId": "scanner-5761f9079a123aae", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/BulkEditOverlay.js:247"}, "properties": {"repobilityId": "7e0f059e262cb7c2", "scanner": "scanner-primary", "fingerprint": "5761f9079a123aae", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/BulkEditOverlay.js"}, "region": {"startLine": 247}}}]}, {"ruleId": "scanner-b2df5c2272a74ccf", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in public/scripts/i18n.js:251"}, "properties": {"repobilityId": "eca429b19ab6e5a5", "scanner": "scanner-primary", "fingerprint": "b2df5c2272a74ccf", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/i18n.js"}, "region": {"startLine": 251}}}]}, {"ruleId": "scanner-c7f7e1fece99a90d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/reasoning.js:560"}, "properties": {"repobilityId": "34e0a3908eb36481", "scanner": "scanner-primary", "fingerprint": "c7f7e1fece99a90d", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/reasoning.js"}, "region": {"startLine": 560}}}]}, {"ruleId": "scanner-9e6656e3e60afc44", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/horde.js:379"}, "properties": {"repobilityId": "7ba934e5fdf534fd", "scanner": "scanner-primary", "fingerprint": "9e6656e3e60afc44", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 379}}}]}, {"ruleId": "scanner-3469b07b31e1f662", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/chats.js:1944"}, "properties": {"repobilityId": "42fb8227a132fcdc", "scanner": "scanner-primary", "fingerprint": "3469b07b31e1f662", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chats.js"}, "region": {"startLine": 1944}}}]}, {"ruleId": "scanner-1b0b4b9f2cbda164", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in public/scripts/chats.js:813"}, "properties": {"repobilityId": "0f371fc97398986d", "scanner": "scanner-primary", "fingerprint": "1b0b4b9f2cbda164", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chats.js"}, "region": {"startLine": 813}}}]}, {"ruleId": "scanner-ef8700bc42c79d29", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/openai.js:1823"}, "properties": {"repobilityId": "10267d148293973a", "scanner": "scanner-primary", "fingerprint": "ef8700bc42c79d29", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/openai.js"}, "region": {"startLine": 1823}}}]}, {"ruleId": "scanner-779b872a13351243", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/util/stream-fadein.js:18"}, "properties": {"repobilityId": "ede86248511fdb3f", "scanner": "scanner-primary", "fingerprint": "779b872a13351243", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/util/stream-fadein.js"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-f952b58fe686123b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/autocomplete/MacroAutoCompleteOption.js:39"}, "properties": {"repobilityId": "6a0db905babd6640", "scanner": "scanner-primary", "fingerprint": "f952b58fe686123b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/autocomplete/MacroAutoCompleteOption.js"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-18c7e07389f60875", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js:349"}, "properties": {"repobilityId": "e5cf303526d06ca6", "scanner": "scanner-primary", "fingerprint": "18c7e07389f60875", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-eb913f8c1fe2b748", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/scripts/extensions/connection-manager/index.js:709"}, "properties": {"repobilityId": "9621d2a9977f3bab", "scanner": "scanner-primary", "fingerprint": "eb913f8c1fe2b748", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/connection-manager/index.js"}, "region": {"startLine": 709}}}]}, {"ruleId": "scanner-f4317e60cbef99b9", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in public/lib/epub.min.js:1"}, "properties": {"repobilityId": "50244b062b836462", "scanner": "scanner-primary", "fingerprint": "f4317e60cbef99b9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/epub.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3c638675bd97b1de", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/epub.min.js:1"}, "properties": {"repobilityId": "52806edff70bbead", "scanner": "scanner-primary", "fingerprint": "3c638675bd97b1de", "layer": "security", "severity": "medium", "confidence": 0.85, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/epub.min.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-232fd84b1fa8b91b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/toolcool-color-picker.js:8"}, "properties": {"repobilityId": "c5df249e77d591f7", "scanner": "scanner-primary", "fingerprint": "232fd84b1fa8b91b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/toolcool-color-picker.js"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-e0223893ab316603", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/lib/select2.min.js:2"}, "properties": {"repobilityId": "8787aa34b1c0166a", "scanner": "scanner-primary", "fingerprint": "e0223893ab316603", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/select2.min.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7a9208c6d4bc785b", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in public/lib/jszip.min.js:13"}, "properties": {"repobilityId": "157f148ca2a075e8", "scanner": "scanner-primary", "fingerprint": "7a9208c6d4bc785b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/lib/jszip.min.js"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-0fe2cc8022e468a5", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "511b516ef93e6937", "scanner": "scanner-primary", "fingerprint": "0fe2cc8022e468a5", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/npm-publish.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ff6ace1dc5b194c", "level": "note", "message": {"text": "Very large file: tests/prompt-converters.test.js (1263 lines)"}, "properties": {"repobilityId": "817472151110a25f", "scanner": "scanner-primary", "fingerprint": "1ff6ace1dc5b194c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-5e01db851f52be3e", "level": "note", "message": {"text": "Very large file: tests/frontend/MacroEngine.e2e.js (3411 lines)"}, "properties": {"repobilityId": "8d111a184872b7a2", "scanner": "scanner-primary", "fingerprint": "5e01db851f52be3e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d7e7ad3e0f94bdeb", "level": "note", "message": {"text": "Very large file: tests/frontend/MacroLexer.e2e.js (1348 lines)"}, "properties": {"repobilityId": "0045d3e8455cce37", "scanner": "scanner-primary", "fingerprint": "d7e7ad3e0f94bdeb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9f3cecf6b6ef7cce", "level": "note", "message": {"text": "Very large file: public/script.js (12537 lines)"}, "properties": {"repobilityId": "1991fa419308e1e4", "scanner": "scanner-primary", "fingerprint": "9f3cecf6b6ef7cce", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-fab33ce4fed07d47", "level": "note", "message": {"text": "Very large file: public/scripts/backgrounds.js (1865 lines)"}, "properties": {"repobilityId": "e973d9200f4f8705", "scanner": "scanner-primary", "fingerprint": "fab33ce4fed07d47", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f500e9f790880164", "level": "note", "message": {"text": "Very large file: public/scripts/power-user.js (4460 lines)"}, "properties": {"repobilityId": "40c3c0c4669d65ed", "scanner": "scanner-primary", "fingerprint": "f500e9f790880164", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2a4067085f58ca01", "level": "note", "message": {"text": "Very large file: public/scripts/group-chats.js (2490 lines)"}, "properties": {"repobilityId": "9afe89c7edce6008", "scanner": "scanner-primary", "fingerprint": "2a4067085f58ca01", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-14965c9153d9cbe5", "level": "note", "message": {"text": "Very large file: public/scripts/textgen-settings.js (1849 lines)"}, "properties": {"repobilityId": "3692f6a62b51d626", "scanner": "scanner-primary", "fingerprint": "14965c9153d9cbe5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-23369f4f8f581c9e", "level": "note", "message": {"text": "Very large file: public/scripts/variables.js (2348 lines)"}, "properties": {"repobilityId": "c78b7ad8c6feb536", "scanner": "scanner-primary", "fingerprint": "23369f4f8f581c9e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a6fe4ad5eead7ab4", "level": "note", "message": {"text": "Very large file: public/scripts/utils.js (3112 lines)"}, "properties": {"repobilityId": "3d8a5ff42476d42a", "scanner": "scanner-primary", "fingerprint": "a6fe4ad5eead7ab4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-109f7a38a05d7f5d", "level": "note", "message": {"text": "Very large file: public/scripts/world-info.js (6289 lines)"}, "properties": {"repobilityId": "df6387e56b4b1a80", "scanner": "scanner-primary", "fingerprint": "109f7a38a05d7f5d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2f8c6cab8911b818", "level": "note", "message": {"text": "Very large file: public/scripts/RossAscends-mods.js (1283 lines)"}, "properties": {"repobilityId": "037af0f29d9ab0de", "scanner": "scanner-primary", "fingerprint": "2f8c6cab8911b818", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-0e55aae6973f0237", "level": "note", "message": {"text": "Very large file: public/scripts/slash-commands.js (7095 lines)"}, "properties": {"repobilityId": "ac7864eae15ff8ff", "scanner": "scanner-primary", "fingerprint": "0e55aae6973f0237", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-39981c4df5db60cb", "level": "note", "message": {"text": "Very large file: public/scripts/PromptManager.js (2144 lines)"}, "properties": {"repobilityId": "c389996e97cec0b8", "scanner": "scanner-primary", "fingerprint": "39981c4df5db60cb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-72a9fa82efc8757a", "level": "note", "message": {"text": "Very large file: public/scripts/reasoning.js (1662 lines)"}, "properties": {"repobilityId": "b913c301c9f9782e", "scanner": "scanner-primary", "fingerprint": "72a9fa82efc8757a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-bfb9f38d4629d6d0", "level": "note", "message": {"text": "Very large file: public/scripts/personas.js (3006 lines)"}, "properties": {"repobilityId": "8c421bd841f1db2b", "scanner": "scanner-primary", "fingerprint": "bfb9f38d4629d6d0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-532bf91d5c9c753c", "level": "note", "message": {"text": "Very large file: public/scripts/tags.js (2824 lines)"}, "properties": {"repobilityId": "cf117618eb153426", "scanner": "scanner-primary", "fingerprint": "532bf91d5c9c753c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9cc91d1621be33ad", "level": "note", "message": {"text": "Very large file: public/scripts/secrets.js (1293 lines)"}, "properties": {"repobilityId": "08d3bc3bef008018", "scanner": "scanner-primary", "fingerprint": "9cc91d1621be33ad", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-44c7182981b01c9d", "level": "note", "message": {"text": "Very large file: public/scripts/chats.js (2422 lines)"}, "properties": {"repobilityId": "c23385afab568ebf", "scanner": "scanner-primary", "fingerprint": "44c7182981b01c9d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-828cfe5a30dab6b4", "level": "note", "message": {"text": "Very large file: public/scripts/openai.js (7249 lines)"}, "properties": {"repobilityId": "3a819e0c461ecbbf", "scanner": "scanner-primary", "fingerprint": "828cfe5a30dab6b4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-92e5cfde8772d0b5", "level": "note", "message": {"text": "Very large file: public/scripts/extensions.js (2315 lines)"}, "properties": {"repobilityId": "59fd6f31395170e0", "scanner": "scanner-primary", "fingerprint": "92e5cfde8772d0b5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ffb743f7c642fc3b", "level": "note", "message": {"text": "Very large file: public/scripts/slash-commands/SlashCommandParser.js (1356 lines)"}, "properties": {"repobilityId": "a408d31efc8e2a2e", "scanner": "scanner-primary", "fingerprint": "ffb743f7c642fc3b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-94beb7292765d4d9", "level": "note", "message": {"text": "Very large file: public/scripts/autocomplete/MacroAutoCompleteHelper.js (1217 lines)"}, "properties": {"repobilityId": "eccd86432163463e", "scanner": "scanner-primary", "fingerprint": "94beb7292765d4d9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-9a374c7b059e718b", "level": "note", "message": {"text": "Very large file: public/scripts/autocomplete/EnhancedMacroAutoCompleteOption.js (1872 lines)"}, "properties": {"repobilityId": "80ae0fdd873ffb49", "scanner": "scanner-primary", "fingerprint": "9a374c7b059e718b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-466d8f701103367f", "level": "note", "message": {"text": "Very large file: public/scripts/macros/engine/MacroCstWalker.js (1364 lines)"}, "properties": {"repobilityId": "c502e9aeaa01f503", "scanner": "scanner-primary", "fingerprint": "466d8f701103367f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-81b93cdff159c8e6", "level": "note", "message": {"text": "Very large file: public/scripts/extensions/tts/index.js (1622 lines)"}, "properties": {"repobilityId": "7a3482a444a56be7", "scanner": "scanner-primary", "fingerprint": "81b93cdff159c8e6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-400ca2ca45292329", "level": "note", "message": {"text": "Very large file: public/scripts/extensions/regex/index.js (2157 lines)"}, "properties": {"repobilityId": "80f187559b223647", "scanner": "scanner-primary", "fingerprint": "400ca2ca45292329", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d654c11cdb44379b", "level": "note", "message": {"text": "Very large file: public/scripts/extensions/vectors/index.js (2358 lines)"}, "properties": {"repobilityId": "77f030da6d29a9d1", "scanner": "scanner-primary", "fingerprint": "d654c11cdb44379b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-03d6e21ecc3923f7", "level": "note", "message": {"text": "Very large file: public/scripts/extensions/quick-reply/src/QuickReply.js (1923 lines)"}, "properties": {"repobilityId": "a7b614a2b97fe334", "scanner": "scanner-primary", "fingerprint": "03d6e21ecc3923f7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b7924fd6d637412b", "level": "note", "message": {"text": "Very large file: public/scripts/extensions/stable-diffusion/index.js (5998 lines)"}, "properties": {"repobilityId": "e033b71fb607adaf", "scanner": "scanner-primary", "fingerprint": "b7924fd6d637412b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8c0311934293e44f", "level": "note", "message": {"text": "Very large file: public/scripts/extensions/expressions/index.js (2576 lines)"}, "properties": {"repobilityId": "f71fc474f08892bc", "scanner": "scanner-primary", "fingerprint": "8c0311934293e44f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-be5b41867e92424b", "level": "note", "message": {"text": "Very large file: src/util.js (1577 lines)"}, "properties": {"repobilityId": "20ac0f17d2e4327a", "scanner": "scanner-primary", "fingerprint": "be5b41867e92424b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ef01d17a25df5d80", "level": "note", "message": {"text": "Very large file: src/prompt-converters.js (1445 lines)"}, "properties": {"repobilityId": "8f3254970b15ae63", "scanner": "scanner-primary", "fingerprint": "ef01d17a25df5d80", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-cc77222c9d7c8b67", "level": "note", "message": {"text": "Very large file: src/endpoints/characters.js (1685 lines)"}, "properties": {"repobilityId": "977ccd1326dcb7f0", "scanner": "scanner-primary", "fingerprint": "cc77222c9d7c8b67", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-77c0c9d0b7682407", "level": "note", "message": {"text": "Very large file: src/endpoints/stable-diffusion.js (2208 lines)"}, "properties": {"repobilityId": "e88c7b5d9dd98473", "scanner": "scanner-primary", "fingerprint": "77c0c9d0b7682407", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7f5409a9d6fbb781", "level": "note", "message": {"text": "Very large file: src/endpoints/backends/chat-completions.js (2896 lines)"}, "properties": {"repobilityId": "cc0c2f3b85751b21", "scanner": "scanner-primary", "fingerprint": "7f5409a9d6fbb781", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-102b7802b0cd82cd", "level": "note", "message": {"text": "68 TODO/FIXME markers"}, "properties": {"repobilityId": "4b38c118003e07d2", "scanner": "scanner-primary", "fingerprint": "102b7802b0cd82cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["maintenance"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "7f01e761bd7eb657", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "f23c0e26229f58ab", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "dc248ddacdac195c", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-c83e3a92116a1b52", "level": "note", "message": {"text": "Legacy-named symbol `substituteParamsLegacy` in public/script.js:2772"}, "properties": {"repobilityId": "b3fe0c6f9cba3b4a", "scanner": "scanner-primary", "fingerprint": "c83e3a92116a1b52", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7e0229f49ae4ca81", "level": "note", "message": {"text": "Legacy-named symbol `logDeprecated` in public/scripts/macros.js:64"}, "properties": {"repobilityId": "270f3126c2d5f684", "scanner": "scanner-primary", "fingerprint": "7e0229f49ae4ca81", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3cc84c12736c34d4", "level": "note", "message": {"text": "Legacy-named symbol `swipe_picker_copy` in public/scripts/swipe-picker.js:252"}, "properties": {"repobilityId": "7da84e2ddf1b3f3c", "scanner": "scanner-primary", "fingerprint": "3cc84c12736c34d4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-be119b3ce77fa458", "level": "note", "message": {"text": "Legacy-named symbol `nerdstash_v2` in public/scripts/tokenizers.js:87"}, "properties": {"repobilityId": "253bb0540c2338e6", "scanner": "scanner-primary", "fingerprint": "be119b3ce77fa458", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-d07c2ec84cff431f", "level": "note", "message": {"text": "Legacy-named symbol `mes_reasoning_copy` in public/scripts/reasoning.js:1218"}, "properties": {"repobilityId": "f56f0d82a13f5040", "scanner": "scanner-primary", "fingerprint": "d07c2ec84cff431f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-db2fb3349be218ac", "level": "note", "message": {"text": "Legacy-named symbol `personas_backup` in public/scripts/personas.js:2944"}, "properties": {"repobilityId": "8a90a630dba7635a", "scanner": "scanner-primary", "fingerprint": "db2fb3349be218ac", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-0ba3ee0133eedae4", "level": "note", "message": {"text": "Legacy-named symbol `tag_view_backup` in public/scripts/tags.js:2793"}, "properties": {"repobilityId": "dd60672448de73a4", "scanner": "scanner-primary", "fingerprint": "0ba3ee0133eedae4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2294bc61024f9f11", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 public/scripts/extensions.js:543"}, "properties": {"repobilityId": "857ec6f23195d46d", "scanner": "scanner-primary", "fingerprint": "2294bc61024f9f11", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 543}}}]}, {"ruleId": "scanner-63862bb7a3a26345", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 public/scripts/extensions/tts/kokoro.js:163"}, "properties": {"repobilityId": "e0ae6c95ac247d20", "scanner": "scanner-primary", "fingerprint": "63862bb7a3a26345", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/kokoro.js"}, "region": {"startLine": 163}}}]}, {"ruleId": "scanner-b4cda11b1380a60e", "level": "note", "message": {"text": "Legacy-named symbol `eleven_multilingual_v2` in public/scripts/extensions/tts/elevenlabs.js:38"}, "properties": {"repobilityId": "3263cad7f45d8ae6", "scanner": "scanner-primary", "fingerprint": "b4cda11b1380a60e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-ba4deff56ecd1521", "level": "note", "message": {"text": "Legacy-named symbol `chara_card_v2` in src/byaf.js:250"}, "properties": {"repobilityId": "21b61e56db36bfb4", "scanner": "scanner-primary", "fingerprint": "ba4deff56ecd1521", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7143105ced020619", "level": "note", "message": {"text": "Legacy-named symbol `chara_card_v2` in src/types/spec-v2.d.ts:2"}, "properties": {"repobilityId": "9a93d03710017d3c", "scanner": "scanner-primary", "fingerprint": "7143105ced020619", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-f1074c2f9b1605db", "level": "note", "message": {"text": "Legacy-named symbol `chara_card_v2` in src/endpoints/content-manager.js:476"}, "properties": {"repobilityId": "eaba3abba19a7d8a", "scanner": "scanner-primary", "fingerprint": "f1074c2f9b1605db", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-9b66e1b7bb8bf26f", "level": "note", "message": {"text": "Legacy-named symbol `spp_nerd_v2` in src/endpoints/tokenizers.js:254"}, "properties": {"repobilityId": "a10ef1f40c580256", "scanner": "scanner-primary", "fingerprint": "9b66e1b7bb8bf26f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-27481694978b14a9", "level": "note", "message": {"text": "Legacy-named symbol `isDeprecated` in src/endpoints/google.js:440"}, "properties": {"repobilityId": "bd94d0166c931f84", "scanner": "scanner-primary", "fingerprint": "27481694978b14a9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-24fa99e710b58035", "level": "note", "message": {"text": "Legacy-named symbol `chara_card_v2` in src/endpoints/characters.js:596"}, "properties": {"repobilityId": "ba194c6374524684", "scanner": "scanner-primary", "fingerprint": "24fa99e710b58035", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-5296014038a93308", "level": "note", "message": {"text": "Legacy-named symbol `t2a_v2` in src/endpoints/minimax.js:67"}, "properties": {"repobilityId": "8653667297782622", "scanner": "scanner-primary", "fingerprint": "5296014038a93308", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-10643b3872ddf5a3", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/stable-diffusion.js:122"}, "properties": {"repobilityId": "cb90ebebfb1ed1bf", "scanner": "scanner-primary", "fingerprint": "10643b3872ddf5a3", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/endpoints/stable-diffusion.js"}, "region": {"startLine": 122}}}]}, {"ruleId": "scanner-9bfa5545c7a96486", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/nanogpt.js:52"}, "properties": {"repobilityId": "38b28bd6049e49b7", "scanner": "scanner-primary", "fingerprint": "9bfa5545c7a96486", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/endpoints/nanogpt.js"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-5b6090887e804031", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 src/endpoints/backends/kobold.js:163"}, "properties": {"repobilityId": "54e99463a8289430", "scanner": "scanner-primary", "fingerprint": "5b6090887e804031", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/endpoints/backends/kobold.js"}, "region": {"startLine": 163}}}]}, {"ruleId": "scanner-1bc61d7364459ca2", "level": "note", "message": {"text": "Legacy-named symbol `chara_card_v2` in src/validator/TavernCardValidator.js:89"}, "properties": {"repobilityId": "50e663534ebe2369", "scanner": "scanner-primary", "fingerprint": "1bc61d7364459ca2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-e7b61ed1590c3b4d", "level": "warning", "message": {"text": "Vulnerable dependency body-parser 1.20.4: GHSA-v422-hmwv-36x6"}, "properties": {"repobilityId": "a80186f8109a4132", "scanner": "scanner-primary", "fingerprint": "e7b61ed1590c3b4d", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-v422-hmwv-36x6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4bb196091f818041", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-76mc-f452-cxcm"}, "properties": {"repobilityId": "9a2beb3965a28d4d", "scanner": "scanner-primary", "fingerprint": "4bb196091f818041", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-76mc-f452-cxcm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c2ef6b2ef296dc98", "level": "note", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-c2j3-45gr-mqc4"}, "properties": {"repobilityId": "45b2a093a3422f04", "scanner": "scanner-primary", "fingerprint": "c2ef6b2ef296dc98", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-c2j3-45gr-mqc4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8e7db3f8fdb375e0", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-cmwh-pvxp-8882"}, "properties": {"repobilityId": "503857d1cf1d7a70", "scanner": "scanner-primary", "fingerprint": "8e7db3f8fdb375e0", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-cmwh-pvxp-8882"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d99382dbe7c75cec", "level": "note", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-gvmj-g25r-r7wr"}, "properties": {"repobilityId": "9f3d04f3da7df50b", "scanner": "scanner-primary", "fingerprint": "d99382dbe7c75cec", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-gvmj-g25r-r7wr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-740a416df111ad12", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-hpcv-96wg-7vj8"}, "properties": {"repobilityId": "9e6997cd4880f09d", "scanner": "scanner-primary", "fingerprint": "740a416df111ad12", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hpcv-96wg-7vj8"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-77caf7814614790e", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-r47g-fvhr-h676"}, "properties": {"repobilityId": "0b6177c177bb91d9", "scanner": "scanner-primary", "fingerprint": "77caf7814614790e", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-r47g-fvhr-h676"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10f4f9f0a7919e50", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-rp9w-3fw7-7cwq"}, "properties": {"repobilityId": "07f6288da7984946", "scanner": "scanner-primary", "fingerprint": "10f4f9f0a7919e50", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rp9w-3fw7-7cwq"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1564ac5779d49487", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-vxr8-fq34-vvx9"}, "properties": {"repobilityId": "faf6cadf57053a5c", "scanner": "scanner-primary", "fingerprint": "1564ac5779d49487", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-vxr8-fq34-vvx9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b7ad40c79facae70", "level": "warning", "message": {"text": "Vulnerable dependency dompurify 3.4.2: GHSA-x4vx-rjvf-j5p4"}, "properties": {"repobilityId": "ee27ab122652ab17", "scanner": "scanner-primary", "fingerprint": "b7ad40c79facae70", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-x4vx-rjvf-j5p4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ef74e3a752b3301b", "level": "warning", "message": {"text": "Vulnerable dependency form-data 4.0.5: GHSA-hmw2-7cc7-3qxx"}, "properties": {"repobilityId": "ad1cdc8bb6564feb", "scanner": "scanner-primary", "fingerprint": "ef74e3a752b3301b", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hmw2-7cc7-3qxx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29ff6340e2fbba20", "level": "warning", "message": {"text": "Vulnerable dependency multer 2.1.1: GHSA-3p4h-7m6x-2hcm"}, "properties": {"repobilityId": "3d21a5ce152aca4d", "scanner": "scanner-primary", "fingerprint": "29ff6340e2fbba20", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-3p4h-7m6x-2hcm"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-26f2d1e0427ce15c", "level": "error", "message": {"text": "Vulnerable dependency multer 2.1.1: GHSA-72gw-mp4g-v24j"}, "properties": {"repobilityId": "5fd28b2ffad63174", "scanner": "scanner-primary", "fingerprint": "26f2d1e0427ce15c", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-72gw-mp4g-v24j"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5ccaf2b2806595b4", "level": "warning", "message": {"text": "Vulnerable dependency showdown 2.1.0: GHSA-rmmh-p597-ppvv"}, "properties": {"repobilityId": "c010437a3f8266f3", "scanner": "scanner-primary", "fingerprint": "5ccaf2b2806595b4", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-rmmh-p597-ppvv"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bd501872c313f352", "level": "error", "message": {"text": "Vulnerable dependency simple-git 3.33.0: GHSA-hffm-xvc3-vprc"}, "properties": {"repobilityId": "3262afa85ce312f8", "scanner": "scanner-primary", "fingerprint": "bd501872c313f352", "layer": "dependencies", "severity": "critical", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-hffm-xvc3-vprc"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b01d57d7856e6524", "level": "warning", "message": {"text": "Vulnerable dependency ws 8.18.3: GHSA-58qx-3vcg-4xpx"}, "properties": {"repobilityId": "b65c6dffece3e05a", "scanner": "scanner-primary", "fingerprint": "b01d57d7856e6524", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-58qx-3vcg-4xpx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9b0d4480a2767b41", "level": "error", "message": {"text": "Vulnerable dependency ws 8.18.3: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": "a3e9cb019eb10d27", "scanner": "scanner-primary", "fingerprint": "9b0d4480a2767b41", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-96hv-2xvq-fx4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b57935db5767b7a", "level": "warning", "message": {"text": "Vulnerable dependency @protobufjs/utf8 1.1.0: GHSA-q6x5-8v7m-xcrf"}, "properties": {"repobilityId": "d845ffffe8ff2904", "scanner": "scanner-primary", "fingerprint": "6b57935db5767b7a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-q6x5-8v7m-xcrf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-defb820e44bef396", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.1.0: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "99627bea33b3e44f", "scanner": "scanner-primary", "fingerprint": "defb820e44bef396", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b0e4e4a3d45273d", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 2.1.0: GHSA-mh99-v99m-4gvg"}, "properties": {"repobilityId": "1510c7f84d77bd5f", "scanner": "scanner-primary", "fingerprint": "7b0e4e4a3d45273d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh99-v99m-4gvg", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fd33e4098759ac02", "level": "error", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-35jp-ww65-95wh"}, "properties": {"repobilityId": "490018abfb55aa37", "scanner": "scanner-primary", "fingerprint": "fd33e4098759ac02", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-35jp-ww65-95wh", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1aa7ed4a82fe7515", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-42h9-826w-cgv3"}, "properties": {"repobilityId": "9bac47a54c2d2285", "scanner": "scanner-primary", "fingerprint": "1aa7ed4a82fe7515", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-42h9-826w-cgv3", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81312e858274a322", "level": "note", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-654m-c8p4-x5fp"}, "properties": {"repobilityId": "0a746fcafffd24d5", "scanner": "scanner-primary", "fingerprint": "81312e858274a322", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-654m-c8p4-x5fp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-40a634b30cbd5de2", "level": "error", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-777c-7fjr-54vf"}, "properties": {"repobilityId": "6acfb54da0a07725", "scanner": "scanner-primary", "fingerprint": "40a634b30cbd5de2", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-777c-7fjr-54vf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74ad15603f7358f5", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-7q8q-rj6j-mhjq"}, "properties": {"repobilityId": "1f1392c58a054edf", "scanner": "scanner-primary", "fingerprint": "74ad15603f7358f5", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-7q8q-rj6j-mhjq", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8f762b5f040227fb", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-898c-q2cr-xwhg"}, "properties": {"repobilityId": "228f1d198f0ff1df", "scanner": "scanner-primary", "fingerprint": "8f762b5f040227fb", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-898c-q2cr-xwhg", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72826426f0f6a976", "level": "error", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-f4gw-2p7v-4548"}, "properties": {"repobilityId": "d4d82f0fe8af734c", "scanner": "scanner-primary", "fingerprint": "72826426f0f6a976", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-f4gw-2p7v-4548", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28c92ad35b58a75e", "level": "error", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-gcfj-64vw-6mp9"}, "properties": {"repobilityId": "990453725fb2cdcc", "scanner": "scanner-primary", "fingerprint": "28c92ad35b58a75e", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-gcfj-64vw-6mp9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e922b32c9f06ffae", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-hcpx-6fm6-wx23"}, "properties": {"repobilityId": "2b2a64b2246ede18", "scanner": "scanner-primary", "fingerprint": "e922b32c9f06ffae", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hcpx-6fm6-wx23", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-86de01609079ef31", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-hfxv-24rg-xrqf"}, "properties": {"repobilityId": "7b85a74daa43e5a5", "scanner": "scanner-primary", "fingerprint": "86de01609079ef31", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-hfxv-24rg-xrqf", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-83e70aedbecd3a4a", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-j5f8-grm9-p9fc"}, "properties": {"repobilityId": "f34fe17ea09b9e54", "scanner": "scanner-primary", "fingerprint": "83e70aedbecd3a4a", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-j5f8-grm9-p9fc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3324ea3aeea87300", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-jqh4-m9w3-8hp9"}, "properties": {"repobilityId": "e704c8652cb42dd2", "scanner": "scanner-primary", "fingerprint": "3324ea3aeea87300", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-jqh4-m9w3-8hp9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-641ee58bb6dd7e96", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-mmx7-hfxf-jppx"}, "properties": {"repobilityId": "5499ddb2841ca800", "scanner": "scanner-primary", "fingerprint": "641ee58bb6dd7e96", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mmx7-hfxf-jppx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e2e4c135ada645dd", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-mwf2-3pr3-8698"}, "properties": {"repobilityId": "7f4068bde334f3dd", "scanner": "scanner-primary", "fingerprint": "e2e4c135ada645dd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mwf2-3pr3-8698", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2ec3dd9182de19cd", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-p92q-9vqr-4j8v"}, "properties": {"repobilityId": "2172890568c6e4b1", "scanner": "scanner-primary", "fingerprint": "2ec3dd9182de19cd", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-p92q-9vqr-4j8v", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d992b673b9ca0ea", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-pjwm-pj3p-43mv"}, "properties": {"repobilityId": "c97fdcf5633a3602", "scanner": "scanner-primary", "fingerprint": "2d992b673b9ca0ea", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-pjwm-pj3p-43mv", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-521c33c009330cca", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-pmv8-rq9r-6j72"}, "properties": {"repobilityId": "f7027094fd3a943c", "scanner": "scanner-primary", "fingerprint": "521c33c009330cca", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-pmv8-rq9r-6j72", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4742e1711949d040", "level": "warning", "message": {"text": "Vulnerable dependency axios 1.15.2: GHSA-xj6q-8x83-jv6g"}, "properties": {"repobilityId": "2af7f4e06ba51496", "scanner": "scanner-primary", "fingerprint": "4742e1711949d040", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-xj6q-8x83-jv6g", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e5adfb4de22b5dfc", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "579bbb43dc72a04b", "scanner": "scanner-primary", "fingerprint": "e5adfb4de22b5dfc", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c5b3747f6ac6c380", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 1.1.14: GHSA-mh99-v99m-4gvg"}, "properties": {"repobilityId": "4e2c81994bf3d76c", "scanner": "scanner-primary", "fingerprint": "c5b3747f6ac6c380", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh99-v99m-4gvg", "transitive", "dev-dependency"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e0bcc5916af91f27", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-4c8g-83qw-93j6"}, "properties": {"repobilityId": "ccba8e073dd684ab", "scanner": "scanner-primary", "fingerprint": "e0bcc5916af91f27", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-4c8g-83qw-93j6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-41060e7beb571855", "level": "warning", "message": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-q3j6-qgpj-74h6"}, "properties": {"repobilityId": "9eb02b57c07aeb74", "scanner": "scanner-primary", "fingerprint": "41060e7beb571855", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-q3j6-qgpj-74h6", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e668e6737d5d8a0d", "level": "error", "message": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-v2hh-gcrm-f6hx"}, "properties": {"repobilityId": "c516ccc3502eb13b", "scanner": "scanner-primary", "fingerprint": "e668e6737d5d8a0d", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v2hh-gcrm-f6hx", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c15f421d52222fa8", "level": "warning", "message": {"text": "Vulnerable dependency fast-uri 3.1.0: GHSA-v39h-62p7-jpjc"}, "properties": {"repobilityId": "06c91e3216e3fe95", "scanner": "scanner-primary", "fingerprint": "c15f421d52222fa8", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-v39h-62p7-jpjc", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5fa51cb1b6ee6b23", "level": "warning", "message": {"text": "Vulnerable dependency file-type 16.5.4: GHSA-5v7r-6r5c-r473"}, "properties": {"repobilityId": "048d33131e7e66a5", "scanner": "scanner-primary", "fingerprint": "5fa51cb1b6ee6b23", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-5v7r-6r5c-r473", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package-lock.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8e96978dfe3a202", "level": "note", "message": {"text": "Dependency @iconfu/svg-inject is a major version behind"}, "properties": {"repobilityId": "aa1cb3e2a139d5c1", "scanner": "scanner-primary", "fingerprint": "d8e96978dfe3a202", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b6e35c071b354366", "level": "note", "message": {"text": "Dependency @types/jest is a major version behind"}, "properties": {"repobilityId": "c8ab556e3061f858", "scanner": "scanner-primary", "fingerprint": "b6e35c071b354366", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tests/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3a8277f2b7fcb654", "level": "note", "message": {"text": "Dependency @zeldafan0225/ai_horde is a major version behind"}, "properties": {"repobilityId": "93175645296ea13d", "scanner": "scanner-primary", "fingerprint": "3a8277f2b7fcb654", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9001556669c1d1ed", "level": "warning", "message": {"text": "Dependency agent-base is two or more major versions behind"}, "properties": {"repobilityId": "22865a62db7ef777", "scanner": "scanner-primary", "fingerprint": "9001556669c1d1ed", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c88813e0aac9bfc8", "level": "note", "message": {"text": "Dependency archiver is a major version behind"}, "properties": {"repobilityId": "0f1d8159fa48a250", "scanner": "scanner-primary", "fingerprint": "c88813e0aac9bfc8", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ede9f24cb8869f4c", "level": "note", "message": {"text": "Dependency body-parser is a major version behind"}, "properties": {"repobilityId": "bb231de6fb031dbf", "scanner": "scanner-primary", "fingerprint": "ede9f24cb8869f4c", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3a3f5a11c4e5f33a", "level": "note", "message": {"text": "Dependency chalk is a major version behind"}, "properties": {"repobilityId": "2200177c4a6d93c8", "scanner": "scanner-primary", "fingerprint": "3a3f5a11c4e5f33a", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2b239381395a9cf9", "level": "warning", "message": {"text": "Dependency chevrotain is two or more major versions behind"}, "properties": {"repobilityId": "f23fcb65c997e2fc", "scanner": "scanner-primary", "fingerprint": "2b239381395a9cf9", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9d088778cea208f2", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/get (public/script.js:1222)"}, "properties": {"repobilityId": "dab7a20a36ef5727", "scanner": "scanner-primary", "fingerprint": "9d088778cea208f2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 1222}}}]}, {"ruleId": "scanner-1a764ff54b653030", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/all (public/script.js:1293)"}, "properties": {"repobilityId": "643311cebdb9f113", "scanner": "scanner-primary", "fingerprint": "1a764ff54b653030", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 1293}}}]}, {"ruleId": "scanner-0dbaa3a0f201a2e4", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/delete (public/script.js:1337)"}, "properties": {"repobilityId": "2829da759528a227", "scanner": "scanner-primary", "fingerprint": "0dbaa3a0f201a2e4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 1337}}}]}, {"ruleId": "scanner-9b3801bccff6844b", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/chats (public/script.js:1388)"}, "properties": {"repobilityId": "eeb6582d2b9224b8", "scanner": "scanner-primary", "fingerprint": "9b3801bccff6844b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 1388}}}]}, {"ruleId": "scanner-9878b2ff595137a3", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/duplicate (public/script.js:6005)"}, "properties": {"repobilityId": "1b073048c3b7fde8", "scanner": "scanner-primary", "fingerprint": "9878b2ff595137a3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 6005}}}]}, {"ruleId": "scanner-271e0dd2fcd69641", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/rename (public/script.js:7149)"}, "properties": {"repobilityId": "47938c4f09b2c35d", "scanner": "scanner-primary", "fingerprint": "271e0dd2fcd69641", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 7149}}}]}, {"ruleId": "scanner-ca93eb283b013587", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/get (public/script.js:7252)"}, "properties": {"repobilityId": "7f1f0c3cb2b6daec", "scanner": "scanner-primary", "fingerprint": "ca93eb283b013587", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 7252}}}]}, {"ruleId": "scanner-40aba23e8774a450", "level": "error", "message": {"text": "Dangling fetch: GET /characters/${avatarKey} (public/script.js:7464)"}, "properties": {"repobilityId": "ec11b3694a946946", "scanner": "scanner-primary", "fingerprint": "40aba23e8774a450", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 7464}}}]}, {"ruleId": "scanner-9ad56ff84503b822", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/get (public/script.js:7855)"}, "properties": {"repobilityId": "718bc1b45ec6fdb7", "scanner": "scanner-primary", "fingerprint": "9ad56ff84503b822", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 7855}}}]}, {"ruleId": "scanner-7299ec9734a8eb13", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/search (public/script.js:8523)"}, "properties": {"repobilityId": "9be089aca9071da6", "scanner": "scanner-primary", "fingerprint": "7299ec9734a8eb13", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 8523}}}]}, {"ruleId": "scanner-201c3b8c7c2feac5", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/import (public/script.js:9389)"}, "properties": {"repobilityId": "d89b4ce320a38bcf", "scanner": "scanner-primary", "fingerprint": "201c3b8c7c2feac5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 9389}}}]}, {"ruleId": "scanner-cc5dfe3110bdae4d", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/import (public/script.js:10492)"}, "properties": {"repobilityId": "018f875edb49c8ae", "scanner": "scanner-primary", "fingerprint": "cc5dfe3110bdae4d", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 10492}}}]}, {"ruleId": "scanner-f39f976ed6587cbc", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/rename (public/script.js:10624)"}, "properties": {"repobilityId": "201cc753e6485b2b", "scanner": "scanner-primary", "fingerprint": "f39f976ed6587cbc", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 10624}}}]}, {"ruleId": "scanner-b4ec5cee76c2ed05", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/script.js:10725)"}, "properties": {"repobilityId": "582ce16d1bcdfb79", "scanner": "scanner-primary", "fingerprint": "b4ec5cee76c2ed05", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 10725}}}]}, {"ruleId": "scanner-a91d4c217b3b2555", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/delete (public/script.js:10803)"}, "properties": {"repobilityId": "8de65c2ba8360a0f", "scanner": "scanner-primary", "fingerprint": "a91d4c217b3b2555", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 10803}}}]}, {"ruleId": "scanner-149bb36b201cae37", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/export (public/script.js:11456)"}, "properties": {"repobilityId": "5d402bfb3e719c04", "scanner": "scanner-primary", "fingerprint": "149bb36b201cae37", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 11456}}}]}, {"ruleId": "scanner-4138462aceb22218", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/export (public/script.js:11991)"}, "properties": {"repobilityId": "09803c46ddda6f9e", "scanner": "scanner-primary", "fingerprint": "4138462aceb22218", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/script.js"}, "region": {"startLine": 11991}}}]}, {"ruleId": "scanner-efb6a2bec7c82e6c", "level": "error", "message": {"text": "Dangling fetch: POST /api/backgrounds/rename (public/scripts/backgrounds.js:512)"}, "properties": {"repobilityId": "f6ab5eecd0a8fdf8", "scanner": "scanner-primary", "fingerprint": "efb6a2bec7c82e6c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 512}}}]}, {"ruleId": "scanner-2071a9ef69b80beb", "level": "error", "message": {"text": "Dangling fetch: POST /api/backgrounds/all (public/scripts/backgrounds.js:709)"}, "properties": {"repobilityId": "24509562613446cd", "scanner": "scanner-primary", "fingerprint": "2071a9ef69b80beb", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 709}}}]}, {"ruleId": "scanner-655f76e1a69cbe13", "level": "error", "message": {"text": "Dangling fetch: POST /api/image-metadata/all (public/scripts/backgrounds.js:742)"}, "properties": {"repobilityId": "f45dc35d704e9ba6", "scanner": "scanner-primary", "fingerprint": "655f76e1a69cbe13", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 742}}}]}, {"ruleId": "scanner-d08129f6b565bf32", "level": "error", "message": {"text": "Dangling fetch: POST /api/backgrounds/folders (public/scripts/backgrounds.js:766)"}, "properties": {"repobilityId": "fd35e8a496e406da", "scanner": "scanner-primary", "fingerprint": "d08129f6b565bf32", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 766}}}]}, {"ruleId": "scanner-86190c0bc7f50740", "level": "error", "message": {"text": "Dangling fetch: POST /api/image-metadata/folders/set-thumbnails (public/scripts/backgrounds.js:793)"}, "properties": {"repobilityId": "cffdc60c598a69b7", "scanner": "scanner-primary", "fingerprint": "86190c0bc7f50740", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 793}}}]}, {"ruleId": "scanner-9433cfadb44fce8c", "level": "error", "message": {"text": "Dangling fetch: POST /api/image-metadata/folders/create (public/scripts/backgrounds.js:1168)"}, "properties": {"repobilityId": "ed2b6ae309fa4fa3", "scanner": "scanner-primary", "fingerprint": "9433cfadb44fce8c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 1168}}}]}, {"ruleId": "scanner-54add3b7df934733", "level": "error", "message": {"text": "Dangling fetch: POST /api/image-metadata/folders/update (public/scripts/backgrounds.js:1197)"}, "properties": {"repobilityId": "2933d0410c9db636", "scanner": "scanner-primary", "fingerprint": "54add3b7df934733", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 1197}}}]}, {"ruleId": "scanner-e8c68c744e370527", "level": "error", "message": {"text": "Dangling fetch: POST /api/image-metadata/folders/delete (public/scripts/backgrounds.js:1225)"}, "properties": {"repobilityId": "11e176f00a2a7c9d", "scanner": "scanner-primary", "fingerprint": "e8c68c744e370527", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 1225}}}]}, {"ruleId": "scanner-26e38d7c2d7fae9b", "level": "error", "message": {"text": "Dangling fetch: POST /api/backgrounds/delete (public/scripts/backgrounds.js:1450)"}, "properties": {"repobilityId": "0acc04835354da73", "scanner": "scanner-primary", "fingerprint": "26e38d7c2d7fae9b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 1450}}}]}, {"ruleId": "scanner-1dc70e37c2221dd4", "level": "error", "message": {"text": "Dangling fetch: POST /api/backgrounds/upload (public/scripts/backgrounds.js:1554)"}, "properties": {"repobilityId": "ead7b39485bab1b5", "scanner": "scanner-primary", "fingerprint": "1dc70e37c2221dd4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/backgrounds.js"}, "region": {"startLine": 1554}}}]}, {"ruleId": "scanner-64d5073710634ed1", "level": "error", "message": {"text": "Dangling fetch: POST /api/themes/delete (public/scripts/power-user.js:2404)"}, "properties": {"repobilityId": "be40cc6b3cfbb449", "scanner": "scanner-primary", "fingerprint": "64d5073710634ed1", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/power-user.js"}, "region": {"startLine": 2404}}}]}, {"ruleId": "scanner-8a0df228e7cc20c5", "level": "error", "message": {"text": "Dangling fetch: POST /api/themes/save (public/scripts/power-user.js:2499)"}, "properties": {"repobilityId": "e19ce620b1e87bd3", "scanner": "scanner-primary", "fingerprint": "8a0df228e7cc20c5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/power-user.js"}, "region": {"startLine": 2499}}}]}, {"ruleId": "scanner-3fc5241387768122", "level": "error", "message": {"text": "Dangling fetch: POST /api/moving-ui/save (public/scripts/power-user.js:2610)"}, "properties": {"repobilityId": "589991320ef1f2a4", "scanner": "scanner-primary", "fingerprint": "3fc5241387768122", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/power-user.js"}, "region": {"startLine": 2610}}}]}, {"ruleId": "scanner-8c7ce635184d9b2a", "level": "error", "message": {"text": "Dangling fetch: POST /api/groups/edit (public/scripts/group-chats.js:156)"}, "properties": {"repobilityId": "6b495ff348725849", "scanner": "scanner-primary", "fingerprint": "8c7ce635184d9b2a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 156}}}]}, {"ruleId": "scanner-48bd363507647517", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/group/get (public/scripts/group-chats.js:196)"}, "properties": {"repobilityId": "3f77b6065e468f16", "scanner": "scanner-primary", "fingerprint": "48bd363507647517", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 196}}}]}, {"ruleId": "scanner-023599a1fd6d639b", "level": "error", "message": {"text": "Dangling fetch: POST /api/groups/all (public/scripts/group-chats.js:759)"}, "properties": {"repobilityId": "d98d217cdc5bd89d", "scanner": "scanner-primary", "fingerprint": "023599a1fd6d639b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 759}}}]}, {"ruleId": "scanner-3a54a69ecfcf8700", "level": "error", "message": {"text": "Dangling fetch: POST /api/groups/delete (public/scripts/group-chats.js:1326)"}, "properties": {"repobilityId": "01c2ea4bd9fe3a70", "scanner": "scanner-primary", "fingerprint": "3a54a69ecfcf8700", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 1326}}}]}, {"ruleId": "scanner-6d34f54ef02f3825", "level": "error", "message": {"text": "Dangling fetch: POST /api/groups/create (public/scripts/group-chats.js:2119)"}, "properties": {"repobilityId": "fcc9aaa1b17053be", "scanner": "scanner-primary", "fingerprint": "6d34f54ef02f3825", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 2119}}}]}, {"ruleId": "scanner-86596925b1c17d17", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/group/info (public/scripts/group-chats.js:2172)"}, "properties": {"repobilityId": "3278ee79c0b99168", "scanner": "scanner-primary", "fingerprint": "86596925b1c17d17", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 2172}}}]}, {"ruleId": "scanner-bda6ae519e0f9127", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/group/delete (public/scripts/group-chats.js:2249)"}, "properties": {"repobilityId": "757d5f8cff809c9d", "scanner": "scanner-primary", "fingerprint": "bda6ae519e0f9127", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 2249}}}]}, {"ruleId": "scanner-65b780381faa6cf4", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/group/import (public/scripts/group-chats.js:2319)"}, "properties": {"repobilityId": "87eafd5dc6c3315e", "scanner": "scanner-primary", "fingerprint": "65b780381faa6cf4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/group-chats.js"}, "region": {"startLine": 2319}}}]}, {"ruleId": "scanner-c645a42208c33ec0", "level": "error", "message": {"text": "Dangling fetch: POST /api/data-maid/report (public/scripts/data-maid.js:69)"}, "properties": {"repobilityId": "1e9fcf2d9919d412", "scanner": "scanner-primary", "fingerprint": "c645a42208c33ec0", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/data-maid.js"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-40bc44268198bc34", "level": "error", "message": {"text": "Dangling fetch: POST /api/data-maid/finalize (public/scripts/data-maid.js:87)"}, "properties": {"repobilityId": "0bed9166028c13e5", "scanner": "scanner-primary", "fingerprint": "40bc44268198bc34", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/data-maid.js"}, "region": {"startLine": 87}}}]}, {"ruleId": "scanner-ec0475fc37eaa273", "level": "error", "message": {"text": "Dangling fetch: POST /api/data-maid/delete (public/scripts/data-maid.js:332)"}, "properties": {"repobilityId": "00959c1203fb9969", "scanner": "scanner-primary", "fingerprint": "ec0475fc37eaa273", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/data-maid.js"}, "region": {"startLine": 332}}}]}, {"ruleId": "scanner-c02d03057ff31c14", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/chats (public/scripts/bookmarks.js:71)"}, "properties": {"repobilityId": "6de28dc5e4a836b1", "scanner": "scanner-primary", "fingerprint": "c02d03057ff31c14", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/bookmarks.js"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-2e69463f24bbdb38", "level": "error", "message": {"text": "Dangling fetch: POST /api/groups/create (public/scripts/bookmarks.js:378)"}, "properties": {"repobilityId": "929f41ba14f7d9a9", "scanner": "scanner-primary", "fingerprint": "2e69463f24bbdb38", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/bookmarks.js"}, "region": {"startLine": 378}}}]}, {"ruleId": "scanner-18801a44e3f33081", "level": "error", "message": {"text": "Dangling fetch: POST /api/files/sanitize-filename (public/scripts/utils.js:1619)"}, "properties": {"repobilityId": "a279eb5003dbb0b5", "scanner": "scanner-primary", "fingerprint": "18801a44e3f33081", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 1619}}}]}, {"ruleId": "scanner-b817fce404beb767", "level": "error", "message": {"text": "Dangling fetch: POST /api/images/upload (public/scripts/utils.js:1662)"}, "properties": {"repobilityId": "fb6e925eaab4f1cf", "scanner": "scanner-primary", "fingerprint": "b817fce404beb767", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 1662}}}]}, {"ruleId": "scanner-38d6cf4b463d243e", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/office/probe (public/scripts/utils.js:2106)"}, "properties": {"repobilityId": "654629e5fbe5753f", "scanner": "scanner-primary", "fingerprint": "38d6cf4b463d243e", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 2106}}}]}, {"ruleId": "scanner-c2f7d12853aa4a02", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/office/parse (public/scripts/utils.js:2125)"}, "properties": {"repobilityId": "6a52bded0f6e94e8", "scanner": "scanner-primary", "fingerprint": "c2f7d12853aa4a02", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 2125}}}]}, {"ruleId": "scanner-cac5a176b69ffba5", "level": "error", "message": {"text": "Dangling fetch: GET /css/${name} (public/scripts/utils.js:2581)"}, "properties": {"repobilityId": "e06e8235383d80b1", "scanner": "scanner-primary", "fingerprint": "cac5a176b69ffba5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 2581}}}]}, {"ruleId": "scanner-0bba926017144658", "level": "error", "message": {"text": "Dangling fetch: POST /api/content/importURL (public/scripts/utils.js:2982)"}, "properties": {"repobilityId": "887d20e6ebb6e2c9", "scanner": "scanner-primary", "fingerprint": "0bba926017144658", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 2982}}}]}, {"ruleId": "scanner-f8bc1bd8ca84efe9", "level": "error", "message": {"text": "Dangling fetch: POST /api/content/importUUID (public/scripts/utils.js:2989)"}, "properties": {"repobilityId": "01619e71974d13c1", "scanner": "scanner-primary", "fingerprint": "f8bc1bd8ca84efe9", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/utils.js"}, "region": {"startLine": 2989}}}]}, {"ruleId": "scanner-c36d1a77612c0efc", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/list (public/scripts/login.js:24)"}, "properties": {"repobilityId": "a18a76c67eaa9247", "scanner": "scanner-primary", "fingerprint": "c36d1a77612c0efc", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/login.js"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-2cfe8076e142bfda", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/recover-step1 (public/scripts/login.js:53)"}, "properties": {"repobilityId": "2345b9f81edaf288", "scanner": "scanner-primary", "fingerprint": "2cfe8076e142bfda", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/login.js"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-615c464b0b4e12fa", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/recover-step2 (public/scripts/login.js:84)"}, "properties": {"repobilityId": "a57859acef4e4bdc", "scanner": "scanner-primary", "fingerprint": "615c464b0b4e12fa", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/login.js"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-b192d96d9708d69f", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/login (public/scripts/login.js:115)"}, "properties": {"repobilityId": "d004bf36334775a7", "scanner": "scanner-primary", "fingerprint": "b192d96d9708d69f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/login.js"}, "region": {"startLine": 115}}}]}, {"ruleId": "scanner-50d32f895c58e254", "level": "error", "message": {"text": "Dangling fetch: POST /api/worldinfo/get (public/scripts/world-info.js:2045)"}, "properties": {"repobilityId": "1a103dc64c77933b", "scanner": "scanner-primary", "fingerprint": "50d32f895c58e254", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 2045}}}]}, {"ruleId": "scanner-f9afb473f19068ef", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/get (public/scripts/world-info.js:2062)"}, "properties": {"repobilityId": "976351305a7bcc95", "scanner": "scanner-primary", "fingerprint": "f9afb473f19068ef", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 2062}}}]}, {"ruleId": "scanner-bd1fc503613c0daa", "level": "error", "message": {"text": "Dangling fetch: POST /api/worldinfo/edit (public/scripts/world-info.js:4075)"}, "properties": {"repobilityId": "fbc71de8b5d54d08", "scanner": "scanner-primary", "fingerprint": "bd1fc503613c0daa", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 4075}}}]}, {"ruleId": "scanner-263114710f40a27e", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/world-info.js:4187)"}, "properties": {"repobilityId": "98cfdcf5f8f50859", "scanner": "scanner-primary", "fingerprint": "263114710f40a27e", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 4187}}}]}, {"ruleId": "scanner-1fef1cc1909be69f", "level": "error", "message": {"text": "Dangling fetch: POST /api/worldinfo/delete (public/scripts/world-info.js:4239)"}, "properties": {"repobilityId": "93bbcd0130b559cf", "scanner": "scanner-primary", "fingerprint": "1fef1cc1909be69f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 4239}}}]}, {"ruleId": "scanner-fdc59de11e7eb40d", "level": "error", "message": {"text": "Dangling fetch: POST /api/worldinfo/import (public/scripts/world-info.js:5785)"}, "properties": {"repobilityId": "b4ef0de39e5acb0f", "scanner": "scanner-primary", "fingerprint": "fdc59de11e7eb40d", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/world-info.js"}, "region": {"startLine": 5785}}}]}, {"ruleId": "scanner-89c94404088b48b4", "level": "error", "message": {"text": "Dangling fetch: POST /api/backups/chat/download (public/scripts/chat-backups.js:29)"}, "properties": {"repobilityId": "3212b3f3795f4ce3", "scanner": "scanner-primary", "fingerprint": "89c94404088b48b4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chat-backups.js"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-76fcea4b021068b2", "level": "error", "message": {"text": "Dangling fetch: POST /api/backups/chat/delete (public/scripts/chat-backups.js:128)"}, "properties": {"repobilityId": "fd66aecef2da4688", "scanner": "scanner-primary", "fingerprint": "76fcea4b021068b2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chat-backups.js"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-f54aa36ae78f8cd4", "level": "error", "message": {"text": "Dangling fetch: POST /api/backups/chat/get (public/scripts/chat-backups.js:156)"}, "properties": {"repobilityId": "facbbeb327562258", "scanner": "scanner-primary", "fingerprint": "f54aa36ae78f8cd4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chat-backups.js"}, "region": {"startLine": 156}}}]}, {"ruleId": "scanner-fe9fe8eddcf87808", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/text-completions/generate (public/scripts/custom-request.js:147)"}, "properties": {"repobilityId": "0544266294a67499", "scanner": "scanner-primary", "fingerprint": "fe9fe8eddcf87808", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/custom-request.js"}, "region": {"startLine": 147}}}]}, {"ruleId": "scanner-89ed0bc64355d654", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/chat-completions/generate (public/scripts/custom-request.js:463)"}, "properties": {"repobilityId": "237fecd2f5e91c42", "scanner": "scanner-primary", "fingerprint": "89ed0bc64355d654", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/custom-request.js"}, "region": {"startLine": 463}}}]}, {"ruleId": "scanner-9e809b4c89906d44", "level": "error", "message": {"text": "Dangling fetch: POST /api/stats/get (public/scripts/stats.js:179)"}, "properties": {"repobilityId": "441f2076fdcd18a3", "scanner": "scanner-primary", "fingerprint": "9e809b4c89906d44", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/stats.js"}, "region": {"startLine": 179}}}]}, {"ruleId": "scanner-4c4a47042f7a2e57", "level": "error", "message": {"text": "Dangling fetch: POST /api/stats/recreate (public/scripts/stats.js:202)"}, "properties": {"repobilityId": "a79afc8b18eb9563", "scanner": "scanner-primary", "fingerprint": "4c4a47042f7a2e57", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/stats.js"}, "region": {"startLine": 202}}}]}, {"ruleId": "scanner-bec448d326a13f97", "level": "error", "message": {"text": "Dangling fetch: POST /api/stats/update (public/scripts/stats.js:238)"}, "properties": {"repobilityId": "98537a6c529cc428", "scanner": "scanner-primary", "fingerprint": "bec448d326a13f97", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/stats.js"}, "region": {"startLine": 238}}}]}, {"ruleId": "scanner-f1697549d3f6f8f3", "level": "error", "message": {"text": "Dangling fetch: POST /api/openrouter/models/providers (public/scripts/textgen-models.js:365)"}, "properties": {"repobilityId": "b280627ca3d94e97", "scanner": "scanner-primary", "fingerprint": "f1697549d3f6f8f3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/textgen-models.js"}, "region": {"startLine": 365}}}]}, {"ruleId": "scanner-8500ac9b26e1dfe8", "level": "error", "message": {"text": "Dangling fetch: POST /api/nanogpt/models/providers (public/scripts/textgen-models.js:413)"}, "properties": {"repobilityId": "fe38e334cd7b7f10", "scanner": "scanner-primary", "fingerprint": "8500ac9b26e1dfe8", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/textgen-models.js"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-c6f8de2f23bcc7f7", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/text-completions/ollama/download (public/scripts/textgen-models.js:1182)"}, "properties": {"repobilityId": "d20eaec52dbf8edd", "scanner": "scanner-primary", "fingerprint": "c6f8de2f23bcc7f7", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/textgen-models.js"}, "region": {"startLine": 1182}}}]}, {"ruleId": "scanner-0cc4f92a90b0fc8a", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/text-completions/tabby/download (public/scripts/textgen-models.js:1252)"}, "properties": {"repobilityId": "7c468a97663093f5", "scanner": "scanner-primary", "fingerprint": "0cc4f92a90b0fc8a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/textgen-models.js"}, "region": {"startLine": 1252}}}]}, {"ruleId": "scanner-5f2dbebd8b27fd5c", "level": "error", "message": {"text": "Dangling fetch: POST /api/search/visit (public/scripts/scrapers.js:193)"}, "properties": {"repobilityId": "e874b7a7973923aa", "scanner": "scanner-primary", "fingerprint": "5f2dbebd8b27fd5c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/scrapers.js"}, "region": {"startLine": 193}}}]}, {"ruleId": "scanner-18072d162bc52543", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/fandom/probe-mediawiki (public/scripts/scrapers.js:260)"}, "properties": {"repobilityId": "92c5c34bfa49d37b", "scanner": "scanner-primary", "fingerprint": "18072d162bc52543", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/scrapers.js"}, "region": {"startLine": 260}}}]}, {"ruleId": "scanner-2c299b8a46efba10", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/fandom/scrape-mediawiki (public/scripts/scrapers.js:301)"}, "properties": {"repobilityId": "fe1a98cf3619a99e", "scanner": "scanner-primary", "fingerprint": "2c299b8a46efba10", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/scrapers.js"}, "region": {"startLine": 301}}}]}, {"ruleId": "scanner-9be1ecf2a597510c", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/fandom/probe (public/scripts/scrapers.js:353)"}, "properties": {"repobilityId": "7de0676f845debad", "scanner": "scanner-primary", "fingerprint": "9be1ecf2a597510c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/scrapers.js"}, "region": {"startLine": 353}}}]}, {"ruleId": "scanner-cdc22a8191d0e968", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/fandom/scrape (public/scripts/scrapers.js:408)"}, "properties": {"repobilityId": "417a7c7e71115ba1", "scanner": "scanner-primary", "fingerprint": "cdc22a8191d0e968", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/scrapers.js"}, "region": {"startLine": 408}}}]}, {"ruleId": "scanner-fa848a21a28ec035", "level": "error", "message": {"text": "Dangling fetch: POST /api/search/transcript (public/scripts/scrapers.js:558)"}, "properties": {"repobilityId": "e004d6e6dfeadf17", "scanner": "scanner-primary", "fingerprint": "fa848a21a28ec035", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/scrapers.js"}, "region": {"startLine": 558}}}]}, {"ruleId": "scanner-54d4ee1bc334cbde", "level": "error", "message": {"text": "Dangling fetch: POST /api/chats/recent (public/scripts/welcome-screen.js:765)"}, "properties": {"repobilityId": "0000fb0946b09c32", "scanner": "scanner-primary", "fingerprint": "54d4ee1bc334cbde", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/welcome-screen.js"}, "region": {"startLine": 765}}}]}, {"ruleId": "scanner-343925906fe789af", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/create (public/scripts/welcome-screen.js:869)"}, "properties": {"repobilityId": "2d542767dad6b11f", "scanner": "scanner-primary", "fingerprint": "343925906fe789af", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/welcome-screen.js"}, "region": {"startLine": 869}}}]}, {"ruleId": "scanner-6332eaebf21bb091", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/duplicate (public/scripts/BulkEditOverlay.js:48)"}, "properties": {"repobilityId": "285ce72b8272693f", "scanner": "scanner-primary", "fingerprint": "6332eaebf21bb091", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/BulkEditOverlay.js"}, "region": {"startLine": 48}}}]}, {"ruleId": "scanner-5ad741d21093b932", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/BulkEditOverlay.js:84)"}, "properties": {"repobilityId": "bd6322dfbbb64490", "scanner": "scanner-primary", "fingerprint": "5ad741d21093b932", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/BulkEditOverlay.js"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-8d79b5c6c6a5e6fc", "level": "error", "message": {"text": "Dangling fetch: POST /api/avatars/get (public/scripts/personas.js:276)"}, "properties": {"repobilityId": "28f63160b166d373", "scanner": "scanner-primary", "fingerprint": "8d79b5c6c6a5e6fc", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/personas.js"}, "region": {"startLine": 276}}}]}, {"ruleId": "scanner-a7f1220b93b5b398", "level": "error", "message": {"text": "Dangling fetch: POST /api/avatars/upload (public/scripts/personas.js:370)"}, "properties": {"repobilityId": "5dc21bb0d22a0412", "scanner": "scanner-primary", "fingerprint": "a7f1220b93b5b398", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/personas.js"}, "region": {"startLine": 370}}}]}, {"ruleId": "scanner-76c7df36add082f3", "level": "error", "message": {"text": "Dangling fetch: POST /api/avatars/delete (public/scripts/personas.js:1170)"}, "properties": {"repobilityId": "e3977ec86c7f1af6", "scanner": "scanner-primary", "fingerprint": "76c7df36add082f3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/personas.js"}, "region": {"startLine": 1170}}}]}, {"ruleId": "scanner-8989f669d7f875b2", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/text-workers (public/scripts/horde.js:42)"}, "properties": {"repobilityId": "46f81f7a5fee56e3", "scanner": "scanner-primary", "fingerprint": "8989f669d7f875b2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 42}}}]}, {"ruleId": "scanner-d9dae982e99792e5", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/text-models (public/scripts/horde.js:56)"}, "properties": {"repobilityId": "6904b7851b3e3092", "scanner": "scanner-primary", "fingerprint": "d9dae982e99792e5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-c5d939673e306319", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/task-status (public/scripts/horde.js:73)"}, "properties": {"repobilityId": "87c338370942e315", "scanner": "scanner-primary", "fingerprint": "c5d939673e306319", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-2fff114372ae1187", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/cancel-task (public/scripts/horde.js:91)"}, "properties": {"repobilityId": "a6098ae071452ad8", "scanner": "scanner-primary", "fingerprint": "2fff114372ae1187", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-3425a325afcebf88", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/status (public/scripts/horde.js:108)"}, "properties": {"repobilityId": "9b34249d15368153", "scanner": "scanner-primary", "fingerprint": "3425a325afcebf88", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-2cae3f22d51fb7fd", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/generate-text (public/scripts/horde.js:221)"}, "properties": {"repobilityId": "6c8fc431831facdf", "scanner": "scanner-primary", "fingerprint": "2cae3f22d51fb7fd", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 221}}}]}, {"ruleId": "scanner-b1b0355626486504", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/user-info (public/scripts/horde.js:328)"}, "properties": {"repobilityId": "7bc4e69ee1408187", "scanner": "scanner-primary", "fingerprint": "b1b0355626486504", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/horde.js"}, "region": {"startLine": 328}}}]}, {"ruleId": "scanner-119c299745daf06e", "level": "error", "message": {"text": "Dangling fetch: GET /api/users/me (public/scripts/user.js:64)"}, "properties": {"repobilityId": "81ae59fb1d57a644", "scanner": "scanner-primary", "fingerprint": "119c299745daf06e", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-99c2c8128d19d25b", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/get (public/scripts/user.js:85)"}, "properties": {"repobilityId": "5d5eefdcef50ad7d", "scanner": "scanner-primary", "fingerprint": "99c2c8128d19d25b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 85}}}]}, {"ruleId": "scanner-6c1c8e5287015075", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/enable (public/scripts/user.js:108)"}, "properties": {"repobilityId": "ec1d7f867802a931", "scanner": "scanner-primary", "fingerprint": "6c1c8e5287015075", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-365e03545fec76a1", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/disable (public/scripts/user.js:128)"}, "properties": {"repobilityId": "cc3428d90584e350", "scanner": "scanner-primary", "fingerprint": "365e03545fec76a1", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-42d34bc568c10037", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/promote (public/scripts/user.js:154)"}, "properties": {"repobilityId": "cb37f29635530286", "scanner": "scanner-primary", "fingerprint": "42d34bc568c10037", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 154}}}]}, {"ruleId": "scanner-2fc8dab5fa795ee2", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/demote (public/scripts/user.js:179)"}, "properties": {"repobilityId": "4c9593efdd39aa0f", "scanner": "scanner-primary", "fingerprint": "2fc8dab5fa795ee2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 179}}}]}, {"ruleId": "scanner-0fc291cc3effda40", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/create (public/scripts/user.js:230)"}, "properties": {"repobilityId": "0e9ae9fb4ed92375", "scanner": "scanner-primary", "fingerprint": "0fc291cc3effda40", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 230}}}]}, {"ruleId": "scanner-2c89c058f783d076", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/backup (public/scripts/user.js:258)"}, "properties": {"repobilityId": "69c7c49a931c23db", "scanner": "scanner-primary", "fingerprint": "2c89c058f783d076", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 258}}}]}, {"ruleId": "scanner-009b47a7667a24bd", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/change-password (public/scripts/user.js:322)"}, "properties": {"repobilityId": "050ba19122294ba4", "scanner": "scanner-primary", "fingerprint": "009b47a7667a24bd", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 322}}}]}, {"ruleId": "scanner-dca9e302148c3d0d", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/delete (public/scripts/user.js:376)"}, "properties": {"repobilityId": "6bd86e04614e21b1", "scanner": "scanner-primary", "fingerprint": "dca9e302148c3d0d", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 376}}}]}, {"ruleId": "scanner-1e099e0050071db8", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/reset-settings (public/scripts/user.js:413)"}, "properties": {"repobilityId": "493e07dbe1c459fd", "scanner": "scanner-primary", "fingerprint": "1e099e0050071db8", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-aa0b1852fe7c31d7", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/change-name (public/scripts/user.js:449)"}, "properties": {"repobilityId": "ae85bd8bf42fecb3", "scanner": "scanner-primary", "fingerprint": "aa0b1852fe7c31d7", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 449}}}]}, {"ruleId": "scanner-37cf792873a55a61", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/restore-snapshot (public/scripts/user.js:486)"}, "properties": {"repobilityId": "9726337ff97a3314", "scanner": "scanner-primary", "fingerprint": "37cf792873a55a61", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 486}}}]}, {"ruleId": "scanner-feae004a75189e35", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/load-snapshot (public/scripts/user.js:511)"}, "properties": {"repobilityId": "e28b659db652459a", "scanner": "scanner-primary", "fingerprint": "feae004a75189e35", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 511}}}]}, {"ruleId": "scanner-b178392fd0e2e73c", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/get-snapshots (public/scripts/user.js:539)"}, "properties": {"repobilityId": "bf21bcc383939970", "scanner": "scanner-primary", "fingerprint": "b178392fd0e2e73c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 539}}}]}, {"ruleId": "scanner-0080040f7936ddeb", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/make-snapshot (public/scripts/user.js:565)"}, "properties": {"repobilityId": "7cbc977df3995a35", "scanner": "scanner-primary", "fingerprint": "0080040f7936ddeb", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 565}}}]}, {"ruleId": "scanner-4a8896798b8dc559", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/reset-step1 (public/scripts/user.js:623)"}, "properties": {"repobilityId": "5ee365294c95971e", "scanner": "scanner-primary", "fingerprint": "4a8896798b8dc559", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 623}}}]}, {"ruleId": "scanner-d87ac68eda8a664a", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/reset-step2 (public/scripts/user.js:655)"}, "properties": {"repobilityId": "51accfef0d0650b9", "scanner": "scanner-primary", "fingerprint": "d87ac68eda8a664a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 655}}}]}, {"ruleId": "scanner-527ef19beba3239f", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/change-avatar (public/scripts/user.js:764)"}, "properties": {"repobilityId": "afc4d3601261f208", "scanner": "scanner-primary", "fingerprint": "527ef19beba3239f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 764}}}]}, {"ruleId": "scanner-3456249d340d5ae4", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/logout (public/scripts/user.js:862)"}, "properties": {"repobilityId": "3444a3432364c045", "scanner": "scanner-primary", "fingerprint": "3456249d340d5ae4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 862}}}]}, {"ruleId": "scanner-269d71e40b7b4222", "level": "error", "message": {"text": "Dangling fetch: POST /api/users/slugify (public/scripts/user.js:884)"}, "properties": {"repobilityId": "ff6ca4287a04226b", "scanner": "scanner-primary", "fingerprint": "269d71e40b7b4222", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/user.js"}, "region": {"startLine": 884}}}]}, {"ruleId": "scanner-343fa191dcb6780b", "level": "error", "message": {"text": "Dangling fetch: POST /api/presets/save (public/scripts/preset-manager.js:477)"}, "properties": {"repobilityId": "b617dae539d38d7d", "scanner": "scanner-primary", "fingerprint": "343fa191dcb6780b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/preset-manager.js"}, "region": {"startLine": 477}}}]}, {"ruleId": "scanner-36c868f258f99940", "level": "error", "message": {"text": "Dangling fetch: POST /api/presets/delete (public/scripts/preset-manager.js:809)"}, "properties": {"repobilityId": "d93ab8cd95468ad0", "scanner": "scanner-primary", "fingerprint": "36c868f258f99940", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/preset-manager.js"}, "region": {"startLine": 809}}}]}, {"ruleId": "scanner-5761ca1fe77bb1de", "level": "error", "message": {"text": "Dangling fetch: POST /api/presets/restore (public/scripts/preset-manager.js:824)"}, "properties": {"repobilityId": "59d10453ebcd2024", "scanner": "scanner-primary", "fingerprint": "5761ca1fe77bb1de", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/preset-manager.js"}, "region": {"startLine": 824}}}]}, {"ruleId": "scanner-c7605e77d7775b93", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/settings (public/scripts/secrets.js:291)"}, "properties": {"repobilityId": "34de7253fe6be160", "scanner": "scanner-primary", "fingerprint": "c7605e77d7775b93", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 291}}}]}, {"ruleId": "scanner-af147f213f895e33", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/view (public/scripts/secrets.js:309)"}, "properties": {"repobilityId": "c16052a398c6393c", "scanner": "scanner-primary", "fingerprint": "af147f213f895e33", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 309}}}]}, {"ruleId": "scanner-66374b37ee77944c", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/write (public/scripts/secrets.js:361)"}, "properties": {"repobilityId": "1f6e062bc1c65d40", "scanner": "scanner-primary", "fingerprint": "66374b37ee77944c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 361}}}]}, {"ruleId": "scanner-be387eeb9623a3f6", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/delete (public/scripts/secrets.js:390)"}, "properties": {"repobilityId": "fbbb27ad558cc253", "scanner": "scanner-primary", "fingerprint": "be387eeb9623a3f6", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 390}}}]}, {"ruleId": "scanner-0f8bd72dfd4f16e6", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/read (public/scripts/secrets.js:413)"}, "properties": {"repobilityId": "eb7a00e31c198c68", "scanner": "scanner-primary", "fingerprint": "0f8bd72dfd4f16e6", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-9ae0dd030db9b248", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/find (public/scripts/secrets.js:436)"}, "properties": {"repobilityId": "7c8471c60f828357", "scanner": "scanner-primary", "fingerprint": "9ae0dd030db9b248", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 436}}}]}, {"ruleId": "scanner-b4f88e133bd77310", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/rotate (public/scripts/secrets.js:461)"}, "properties": {"repobilityId": "f04ba8e465fb60d8", "scanner": "scanner-primary", "fingerprint": "b4f88e133bd77310", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 461}}}]}, {"ruleId": "scanner-b72f76719767d492", "level": "error", "message": {"text": "Dangling fetch: POST /api/secrets/rename (public/scripts/secrets.js:486)"}, "properties": {"repobilityId": "20e5de4e47c11268", "scanner": "scanner-primary", "fingerprint": "b72f76719767d492", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 486}}}]}, {"ruleId": "scanner-ab0b5e391b0d0d51", "level": "error", "message": {"text": "Dangling fetch: POST /api/openrouter/credits (public/scripts/secrets.js:1176)"}, "properties": {"repobilityId": "7f3d9763d518b140", "scanner": "scanner-primary", "fingerprint": "ab0b5e391b0d0d51", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 1176}}}]}, {"ruleId": "scanner-5d6f2dfad8ed69cf", "level": "error", "message": {"text": "Dangling fetch: POST /api/nanogpt/credits (public/scripts/secrets.js:1242)"}, "properties": {"repobilityId": "769f9a697cce51ab", "scanner": "scanner-primary", "fingerprint": "5d6f2dfad8ed69cf", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/secrets.js"}, "region": {"startLine": 1242}}}]}, {"ruleId": "scanner-78cde9dfb142f201", "level": "error", "message": {"text": "Dangling fetch: POST /api/files/upload (public/scripts/chats.js:276)"}, "properties": {"repobilityId": "58ddb6e81b4dce12", "scanner": "scanner-primary", "fingerprint": "78cde9dfb142f201", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chats.js"}, "region": {"startLine": 276}}}]}, {"ruleId": "scanner-25be55d8c812abf7", "level": "error", "message": {"text": "Dangling fetch: POST /api/images/delete (public/scripts/chats.js:1099)"}, "properties": {"repobilityId": "a348e40b893005fb", "scanner": "scanner-primary", "fingerprint": "25be55d8c812abf7", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chats.js"}, "region": {"startLine": 1099}}}]}, {"ruleId": "scanner-5ca70521ba399d15", "level": "error", "message": {"text": "Dangling fetch: POST /api/files/delete (public/scripts/chats.js:1130)"}, "properties": {"repobilityId": "f2f1564c610951f7", "scanner": "scanner-primary", "fingerprint": "5ca70521ba399d15", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chats.js"}, "region": {"startLine": 1130}}}]}, {"ruleId": "scanner-3daaeec984550dc9", "level": "error", "message": {"text": "Dangling fetch: POST /api/files/verify (public/scripts/chats.js:1832)"}, "properties": {"repobilityId": "a39f537fdc5075ee", "scanner": "scanner-primary", "fingerprint": "3daaeec984550dc9", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/chats.js"}, "region": {"startLine": 1832}}}]}, {"ruleId": "scanner-7815171688fe9fdc", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/chat-completions/bias?model=${getTokenizerModel()} (public/scripts/openai.js:3311)"}, "properties": {"repobilityId": "2a294dd488349785", "scanner": "scanner-primary", "fingerprint": "7815171688fe9fdc", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/openai.js"}, "region": {"startLine": 3311}}}]}, {"ruleId": "scanner-839edef6aeb3b649", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/chat-completions/status (public/scripts/openai.js:4437)"}, "properties": {"repobilityId": "568218f0a2493d52", "scanner": "scanner-primary", "fingerprint": "839edef6aeb3b649", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/openai.js"}, "region": {"startLine": 4437}}}]}, {"ruleId": "scanner-199810519d4637bf", "level": "error", "message": {"text": "Dangling fetch: POST /api/presets/save (public/scripts/openai.js:4495)"}, "properties": {"repobilityId": "c451859adb760768", "scanner": "scanner-primary", "fingerprint": "199810519d4637bf", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/openai.js"}, "region": {"startLine": 4495}}}]}, {"ruleId": "scanner-a2f9a0a83ce5d8f8", "level": "error", "message": {"text": "Dangling fetch: POST /api/presets/delete (public/scripts/openai.js:4860)"}, "properties": {"repobilityId": "4477eff4a68af3c1", "scanner": "scanner-primary", "fingerprint": "a2f9a0a83ce5d8f8", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/openai.js"}, "region": {"startLine": 4860}}}]}, {"ruleId": "scanner-2a1c7101ae801e31", "level": "error", "message": {"text": "Dangling fetch: GET /api/extensions/discover (public/scripts/extensions.js:300)"}, "properties": {"repobilityId": "7a3f359adb9e47d0", "scanner": "scanner-primary", "fingerprint": "2a1c7101ae801e31", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 300}}}]}, {"ruleId": "scanner-61379ce63048f0f4", "level": "error", "message": {"text": "Dangling fetch: GET /scripts/extensions/${name}/${localeFile} (public/scripts/extensions.js:862)"}, "properties": {"repobilityId": "bd7ba7660985632a", "scanner": "scanner-primary", "fingerprint": "61379ce63048f0f4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 862}}}]}, {"ruleId": "scanner-4ef5d3d429090b3d", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/update (public/scripts/extensions.js:1360)"}, "properties": {"repobilityId": "3cdbcd933bd45e9a", "scanner": "scanner-primary", "fingerprint": "4ef5d3d429090b3d", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1360}}}]}, {"ruleId": "scanner-7c254df773cf6cb6", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/move (public/scripts/extensions.js:1531)"}, "properties": {"repobilityId": "7773dbd7db3ae245", "scanner": "scanner-primary", "fingerprint": "7c254df773cf6cb6", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1531}}}]}, {"ruleId": "scanner-03065065ddde743b", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/delete (public/scripts/extensions.js:1571)"}, "properties": {"repobilityId": "3017858a8230d669", "scanner": "scanner-primary", "fingerprint": "03065065ddde743b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1571}}}]}, {"ruleId": "scanner-0289f5e95345fe70", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/version (public/scripts/extensions.js:1601)"}, "properties": {"repobilityId": "c933bbe545e72340", "scanner": "scanner-primary", "fingerprint": "0289f5e95345fe70", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1601}}}]}, {"ruleId": "scanner-2ad68bdb842552e6", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/branches (public/scripts/extensions.js:1634)"}, "properties": {"repobilityId": "09c483484c54d8b5", "scanner": "scanner-primary", "fingerprint": "2ad68bdb842552e6", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1634}}}]}, {"ruleId": "scanner-6effcf40a9893366", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/switch (public/scripts/extensions.js:1666)"}, "properties": {"repobilityId": "e6d5a8302cf84112", "scanner": "scanner-primary", "fingerprint": "6effcf40a9893366", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1666}}}]}, {"ruleId": "scanner-45925e1c67a784ea", "level": "error", "message": {"text": "Dangling fetch: POST /api/extensions/install (public/scripts/extensions.js:1746)"}, "properties": {"repobilityId": "ae660410818261d8", "scanner": "scanner-primary", "fingerprint": "45925e1c67a784ea", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 1746}}}]}, {"ruleId": "scanner-a021b244c6cd4d81", "level": "error", "message": {"text": "Dangling fetch: POST /api/characters/merge-attributes (public/scripts/extensions.js:2102)"}, "properties": {"repobilityId": "d207b9171382c4b4", "scanner": "scanner-primary", "fingerprint": "a021b244c6cd4d81", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions.js"}, "region": {"startLine": 2102}}}]}, {"ruleId": "scanner-64527557e1701b75", "level": "error", "message": {"text": "Dangling fetch: POST /api/plugins/edge-tts/probe (public/scripts/extensions/tts/edge.js:260)"}, "properties": {"repobilityId": "2909249ecdf53011", "scanner": "scanner-primary", "fingerprint": "64527557e1701b75", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/edge.js"}, "region": {"startLine": 260}}}]}, {"ruleId": "scanner-738f260a1397907b", "level": "error", "message": {"text": "Dangling fetch: POST /api/google/list-native-voices (public/scripts/extensions/tts/google-native.js:96)"}, "properties": {"repobilityId": "c79472785df64b97", "scanner": "scanner-primary", "fingerprint": "738f260a1397907b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/google-native.js"}, "region": {"startLine": 96}}}]}, {"ruleId": "scanner-e4fbdd6a83ca88bb", "level": "error", "message": {"text": "Dangling fetch: POST /api/google/generate-native-tts (public/scripts/extensions/tts/google-native.js:164)"}, "properties": {"repobilityId": "c6c700f577d8c63f", "scanner": "scanner-primary", "fingerprint": "e4fbdd6a83ca88bb", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/google-native.js"}, "region": {"startLine": 164}}}]}, {"ruleId": "scanner-55336261ce244896", "level": "error", "message": {"text": "Dangling fetch: POST /api/openai/chutes/generate-voice (public/scripts/extensions/tts/chutes.js:201)"}, "properties": {"repobilityId": "a0687c25ff3f6f14", "scanner": "scanner-primary", "fingerprint": "55336261ce244896", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/chutes.js"}, "region": {"startLine": 201}}}]}, {"ruleId": "scanner-3e5af3add9ae32b1", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/synthesize (public/scripts/extensions/tts/speecht5.js:175)"}, "properties": {"repobilityId": "e21d9540010c5d77", "scanner": "scanner-primary", "fingerprint": "3e5af3add9ae32b1", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/speecht5.js"}, "region": {"startLine": 175}}}]}, {"ruleId": "scanner-2c8d9401aa225030", "level": "error", "message": {"text": "Dangling fetch: POST /api/azure/list (public/scripts/extensions/tts/azure.js:143)"}, "properties": {"repobilityId": "9dbd3bfe64b5616d", "scanner": "scanner-primary", "fingerprint": "2c8d9401aa225030", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/azure.js"}, "region": {"startLine": 143}}}]}, {"ruleId": "scanner-d3a83d925f1eed3b", "level": "error", "message": {"text": "Dangling fetch: POST /api/azure/generate (public/scripts/extensions/tts/azure.js:191)"}, "properties": {"repobilityId": "4ba9d7356805563d", "scanner": "scanner-primary", "fingerprint": "d3a83d925f1eed3b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/azure.js"}, "region": {"startLine": 191}}}]}, {"ruleId": "scanner-c2368cd5c081ff23", "level": "error", "message": {"text": "Dangling fetch: POST /api/volcengine/generate-voice (public/scripts/extensions/tts/volcengine.js:297)"}, "properties": {"repobilityId": "dbb198cc577112d6", "scanner": "scanner-primary", "fingerprint": "c2368cd5c081ff23", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/volcengine.js"}, "region": {"startLine": 297}}}]}, {"ruleId": "scanner-3eca027af67cc020", "level": "error", "message": {"text": "Dangling fetch: POST /api/openai/electronhub/models (public/scripts/extensions/tts/electronhub.js:188)"}, "properties": {"repobilityId": "1a7eee20ffa3bcea", "scanner": "scanner-primary", "fingerprint": "3eca027af67cc020", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/electronhub.js"}, "region": {"startLine": 188}}}]}, {"ruleId": "scanner-78289626452477a2", "level": "error", "message": {"text": "Dangling fetch: POST /api/openai/electronhub/generate-voice (public/scripts/extensions/tts/electronhub.js:443)"}, "properties": {"repobilityId": "1a869fb27304c18e", "scanner": "scanner-primary", "fingerprint": "78289626452477a2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/electronhub.js"}, "region": {"startLine": 443}}}]}, {"ruleId": "scanner-44af6ebc1813d27b", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/elevenlabs/voices (public/scripts/extensions/tts/elevenlabs.js:304)"}, "properties": {"repobilityId": "837eeefe6df23a2f", "scanner": "scanner-primary", "fingerprint": "44af6ebc1813d27b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/elevenlabs.js"}, "region": {"startLine": 304}}}]}, {"ruleId": "scanner-4df8cc5c22b17748", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/elevenlabs/voice-settings (public/scripts/extensions/tts/elevenlabs.js:316)"}, "properties": {"repobilityId": "3a8faa4187044652", "scanner": "scanner-primary", "fingerprint": "4df8cc5c22b17748", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/elevenlabs.js"}, "region": {"startLine": 316}}}]}, {"ruleId": "scanner-61fce680324cca19", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/elevenlabs/synthesize (public/scripts/extensions/tts/elevenlabs.js:348)"}, "properties": {"repobilityId": "1df5693508cedd64", "scanner": "scanner-primary", "fingerprint": "61fce680324cca19", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/elevenlabs.js"}, "region": {"startLine": 348}}}]}, {"ruleId": "scanner-5a8d46e447d26eb3", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/elevenlabs/history-audio (public/scripts/extensions/tts/elevenlabs.js:370)"}, "properties": {"repobilityId": "d014f98c5ba6bfff", "scanner": "scanner-primary", "fingerprint": "5a8d46e447d26eb3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/elevenlabs.js"}, "region": {"startLine": 370}}}]}, {"ruleId": "scanner-2ca36c9c5fe40c54", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/elevenlabs/history (public/scripts/extensions/tts/elevenlabs.js:388)"}, "properties": {"repobilityId": "23aa463780eeae86", "scanner": "scanner-primary", "fingerprint": "2ca36c9c5fe40c54", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/elevenlabs.js"}, "region": {"startLine": 388}}}]}, {"ruleId": "scanner-1d15fbe8f6c70208", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/elevenlabs/voices/add (public/scripts/extensions/tts/elevenlabs.js:424)"}, "properties": {"repobilityId": "25ffb4700d137295", "scanner": "scanner-primary", "fingerprint": "1d15fbe8f6c70208", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/elevenlabs.js"}, "region": {"startLine": 424}}}]}, {"ruleId": "scanner-35cf14539cc4b94a", "level": "error", "message": {"text": "Dangling fetch: POST /api/minimax/generate-voice (public/scripts/extensions/tts/minimax.js:806)"}, "properties": {"repobilityId": "01fe19e222403a9e", "scanner": "scanner-primary", "fingerprint": "35cf14539cc4b94a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/minimax.js"}, "region": {"startLine": 806}}}]}, {"ruleId": "scanner-69b3999e46ef3629", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/pollinations/voices (public/scripts/extensions/tts/pollinations.js:91)"}, "properties": {"repobilityId": "197e9a5b33b72907", "scanner": "scanner-primary", "fingerprint": "69b3999e46ef3629", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/pollinations.js"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-01937f3332a0df0e", "level": "error", "message": {"text": "Dangling fetch: POST /api/speech/pollinations/generate (public/scripts/extensions/tts/pollinations.js:133)"}, "properties": {"repobilityId": "d5481c315b42cbfe", "scanner": "scanner-primary", "fingerprint": "01937f3332a0df0e", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/pollinations.js"}, "region": {"startLine": 133}}}]}, {"ruleId": "scanner-6a0831767ccb60c4", "level": "error", "message": {"text": "Dangling fetch: POST /api/novelai/generate-voice (public/scripts/extensions/tts/novel.js:198)"}, "properties": {"repobilityId": "70821a60bc32fd5b", "scanner": "scanner-primary", "fingerprint": "6a0831767ccb60c4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/novel.js"}, "region": {"startLine": 198}}}]}, {"ruleId": "scanner-32b40909d895ec67", "level": "error", "message": {"text": "Dangling fetch: POST /api/openai/generate-voice (public/scripts/extensions/tts/openai.js:239)"}, "properties": {"repobilityId": "097b84e3fabdf7d9", "scanner": "scanner-primary", "fingerprint": "32b40909d895ec67", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/tts/openai.js"}, "region": {"startLine": 239}}}]}, {"ruleId": "scanner-d0f6c9bf109cf2ec", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/onering (public/scripts/extensions/translate/index.js:254)"}, "properties": {"repobilityId": "7824273bd269db69", "scanner": "scanner-primary", "fingerprint": "d0f6c9bf109cf2ec", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 254}}}]}, {"ruleId": "scanner-3b887c483d96c63e", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/libre (public/scripts/extensions/translate/index.js:275)"}, "properties": {"repobilityId": "8aaa5da9e0fe1847", "scanner": "scanner-primary", "fingerprint": "3b887c483d96c63e", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 275}}}]}, {"ruleId": "scanner-1f692d5895f6bfb2", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/google (public/scripts/extensions/translate/index.js:296)"}, "properties": {"repobilityId": "441355071e068fad", "scanner": "scanner-primary", "fingerprint": "1f692d5895f6bfb2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 296}}}]}, {"ruleId": "scanner-86a4ae38746c45d3", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/lingva (public/scripts/extensions/translate/index.js:317)"}, "properties": {"repobilityId": "4563139905e79acc", "scanner": "scanner-primary", "fingerprint": "86a4ae38746c45d3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 317}}}]}, {"ruleId": "scanner-2e5255a0eac4ebc9", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/deepl (public/scripts/extensions/translate/index.js:343)"}, "properties": {"repobilityId": "16322b715ccff039", "scanner": "scanner-primary", "fingerprint": "2e5255a0eac4ebc9", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 343}}}]}, {"ruleId": "scanner-f1c0a119acb935c2", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/deeplx (public/scripts/extensions/translate/index.js:364)"}, "properties": {"repobilityId": "931f6a5ced95b7a7", "scanner": "scanner-primary", "fingerprint": "f1c0a119acb935c2", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 364}}}]}, {"ruleId": "scanner-f762924a40c6d35c", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/bing (public/scripts/extensions/translate/index.js:385)"}, "properties": {"repobilityId": "c66f5e69d2ea61fa", "scanner": "scanner-primary", "fingerprint": "f762924a40c6d35c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 385}}}]}, {"ruleId": "scanner-b15c1ab1d4731bbc", "level": "error", "message": {"text": "Dangling fetch: POST /api/translate/yandex (public/scripts/extensions/translate/index.js:413)"}, "properties": {"repobilityId": "d8961a386843b31a", "scanner": "scanner-primary", "fingerprint": "b15c1ab1d4731bbc", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/translate/index.js"}, "region": {"startLine": 413}}}]}, {"ruleId": "scanner-5bec82e06abc7e85", "level": "error", "message": {"text": "Dangling fetch: POST /api/extra/caption (public/scripts/extensions/caption/index.js:274)"}, "properties": {"repobilityId": "496d4c394c1896c5", "scanner": "scanner-primary", "fingerprint": "5bec82e06abc7e85", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/caption/index.js"}, "region": {"startLine": 274}}}]}, {"ruleId": "scanner-f7a4c0e5d27b98d3", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/caption-image (public/scripts/extensions/caption/index.js:294)"}, "properties": {"repobilityId": "7e15d418d14a5d14", "scanner": "scanner-primary", "fingerprint": "f7a4c0e5d27b98d3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/caption/index.js"}, "region": {"startLine": 294}}}]}, {"ruleId": "scanner-5ca4ccff159d72ea", "level": "error", "message": {"text": "Dangling fetch: POST /api/assets/download (public/scripts/extensions/assets/index.js:390)"}, "properties": {"repobilityId": "2d3019dc91a3c7d5", "scanner": "scanner-primary", "fingerprint": "5ca4ccff159d72ea", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/assets/index.js"}, "region": {"startLine": 390}}}]}, {"ruleId": "scanner-a38b8bf9a6d00a4a", "level": "error", "message": {"text": "Dangling fetch: POST /api/assets/delete (public/scripts/extensions/assets/index.js:433)"}, "properties": {"repobilityId": "f48aeff350ebaffc", "scanner": "scanner-primary", "fingerprint": "a38b8bf9a6d00a4a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/assets/index.js"}, "region": {"startLine": 433}}}]}, {"ruleId": "scanner-cfcc1ec8eb9cf280", "level": "error", "message": {"text": "Dangling fetch: POST /api/assets/get (public/scripts/extensions/assets/index.js:515)"}, "properties": {"repobilityId": "e293a2be6f92dd9d", "scanner": "scanner-primary", "fingerprint": "cfcc1ec8eb9cf280", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/assets/index.js"}, "region": {"startLine": 515}}}]}, {"ruleId": "scanner-4473b05432aeb320", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/list (public/scripts/extensions/vectors/index.js:1027)"}, "properties": {"repobilityId": "bd866b0f1e5cd868", "scanner": "scanner-primary", "fingerprint": "4473b05432aeb320", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1027}}}]}, {"ruleId": "scanner-7689eceaddc06242", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/insert (public/scripts/extensions/vectors/index.js:1055)"}, "properties": {"repobilityId": "bc74e8b169b671d9", "scanner": "scanner-primary", "fingerprint": "7689eceaddc06242", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1055}}}]}, {"ruleId": "scanner-0bb9f33b58b471a8", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/delete (public/scripts/extensions/vectors/index.js:1129)"}, "properties": {"repobilityId": "ab3685839e71556b", "scanner": "scanner-primary", "fingerprint": "0bb9f33b58b471a8", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1129}}}]}, {"ruleId": "scanner-6449486fcec94e69", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/query (public/scripts/extensions/vectors/index.js:1153)"}, "properties": {"repobilityId": "910b98d0fe0ad9e0", "scanner": "scanner-primary", "fingerprint": "6449486fcec94e69", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1153}}}]}, {"ruleId": "scanner-07b9fe713b96ca45", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/query-multi (public/scripts/extensions/vectors/index.js:1183)"}, "properties": {"repobilityId": "a7c30f7ea752132c", "scanner": "scanner-primary", "fingerprint": "07b9fe713b96ca45", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1183}}}]}, {"ruleId": "scanner-d5e6ac77fc2d2e4c", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/purge (public/scripts/extensions/vectors/index.js:1216)"}, "properties": {"repobilityId": "45eb5a69d9deebb7", "scanner": "scanner-primary", "fingerprint": "d5e6ac77fc2d2e4c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1216}}}]}, {"ruleId": "scanner-86fcf72ae9873ce9", "level": "error", "message": {"text": "Dangling fetch: POST /api/vector/purge-all (public/scripts/extensions/vectors/index.js:1272)"}, "properties": {"repobilityId": "9ce55fb38851e41b", "scanner": "scanner-primary", "fingerprint": "86fcf72ae9873ce9", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1272}}}]}, {"ruleId": "scanner-7f7fe989d3d431d0", "level": "error", "message": {"text": "Dangling fetch: POST /api/backends/kobold/embed (public/scripts/extensions/vectors/index.js:1455)"}, "properties": {"repobilityId": "8714e52c0e586ed5", "scanner": "scanner-primary", "fingerprint": "7f7fe989d3d431d0", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/vectors/index.js"}, "region": {"startLine": 1455}}}]}, {"ruleId": "scanner-ffbfbe83b710a323", "level": "error", "message": {"text": "Dangling fetch: POST /api/images/list (public/scripts/extensions/gallery/index.js:115)"}, "properties": {"repobilityId": "b57917492f148f9a", "scanner": "scanner-primary", "fingerprint": "ffbfbe83b710a323", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/gallery/index.js"}, "region": {"startLine": 115}}}]}, {"ruleId": "scanner-31876a3a50b7f6fe", "level": "error", "message": {"text": "Dangling fetch: POST /api/images/folders (public/scripts/extensions/gallery/index.js:160)"}, "properties": {"repobilityId": "d3b538cce777d8ad", "scanner": "scanner-primary", "fingerprint": "31876a3a50b7f6fe", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/gallery/index.js"}, "region": {"startLine": 160}}}]}, {"ruleId": "scanner-5c118dc9b321b577", "level": "error", "message": {"text": "Dangling fetch: POST /api/settings/get (public/scripts/extensions/quick-reply/index.js:56)"}, "properties": {"repobilityId": "abede650762af6e9", "scanner": "scanner-primary", "fingerprint": "5c118dc9b321b577", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/index.js"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-14143310963dcb2c", "level": "error", "message": {"text": "Dangling fetch: GET /scripts/extensions/quick-reply/html/qrEditor.html (public/scripts/extensions/quick-reply/src/QuickReply.js:385)"}, "properties": {"repobilityId": "521be2d8a8db4a68", "scanner": "scanner-primary", "fingerprint": "14143310963dcb2c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/src/QuickReply.js"}, "region": {"startLine": 385}}}]}, {"ruleId": "scanner-2a093a20176749f9", "level": "error", "message": {"text": "Dangling fetch: POST /api/quick-replies/save (public/scripts/extensions/quick-reply/src/QuickReplySet.js:377)"}, "properties": {"repobilityId": "10d936e4f4f277c3", "scanner": "scanner-primary", "fingerprint": "2a093a20176749f9", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/src/QuickReplySet.js"}, "region": {"startLine": 377}}}]}, {"ruleId": "scanner-1f87c83277f8c159", "level": "error", "message": {"text": "Dangling fetch: POST /api/quick-replies/delete (public/scripts/extensions/quick-reply/src/QuickReplySet.js:392)"}, "properties": {"repobilityId": "ca620f4298bcbcf9", "scanner": "scanner-primary", "fingerprint": "1f87c83277f8c159", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/src/QuickReplySet.js"}, "region": {"startLine": 392}}}]}, {"ruleId": "scanner-81d26fc478c0fe91", "level": "error", "message": {"text": "Dangling fetch: GET /scripts/extensions/quick-reply/html/settings.html (public/scripts/extensions/quick-reply/src/ui/SettingsUi.js:54)"}, "properties": {"repobilityId": "22ee53f82cacce7d", "scanner": "scanner-primary", "fingerprint": "81d26fc478c0fe91", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/quick-reply/src/ui/SettingsUi.js"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-7be79d5fb432937f", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/ping (public/scripts/extensions/stable-diffusion/index.js:1353)"}, "properties": {"repobilityId": "b5c0c826c5ea2afe", "scanner": "scanner-primary", "fingerprint": "7be79d5fb432937f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1353}}}]}, {"ruleId": "scanner-777dc64c4a7a4e96", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/sdcpp/ping (public/scripts/extensions/stable-diffusion/index.js:1376)"}, "properties": {"repobilityId": "1c7b6c37b871c8cc", "scanner": "scanner-primary", "fingerprint": "777dc64c4a7a4e96", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1376}}}]}, {"ruleId": "scanner-0c9f9dfd8dc57af4", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/drawthings/ping (public/scripts/extensions/stable-diffusion/index.js:1399)"}, "properties": {"repobilityId": "e2019930793b7abd", "scanner": "scanner-primary", "fingerprint": "0c9f9dfd8dc57af4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1399}}}]}, {"ruleId": "scanner-300944e554f5bbca", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/ping (public/scripts/extensions/stable-diffusion/index.js:1445)"}, "properties": {"repobilityId": "62327fedf83ce76f", "scanner": "scanner-primary", "fingerprint": "300944e554f5bbca", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1445}}}]}, {"ruleId": "scanner-0e94ed84bcef1c1f", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfyrunpod/ping (public/scripts/extensions/stable-diffusion/index.js:1469)"}, "properties": {"repobilityId": "74728943b52fed02", "scanner": "scanner-primary", "fingerprint": "0e94ed84bcef1c1f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1469}}}]}, {"ruleId": "scanner-e9e35974912c1231", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/get-model (public/scripts/extensions/stable-diffusion/index.js:1522)"}, "properties": {"repobilityId": "65ce9d4beca41137", "scanner": "scanner-primary", "fingerprint": "e9e35974912c1231", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1522}}}]}, {"ruleId": "scanner-c4199cb4d74db639", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/drawthings/get-model (public/scripts/extensions/stable-diffusion/index.js:1541)"}, "properties": {"repobilityId": "b115336476437aa5", "scanner": "scanner-primary", "fingerprint": "c4199cb4d74db639", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1541}}}]}, {"ruleId": "scanner-b88dd5fb825dafb3", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/upscalers (public/scripts/extensions/stable-diffusion/index.js:1564)"}, "properties": {"repobilityId": "9f1c2556168d37c9", "scanner": "scanner-primary", "fingerprint": "b88dd5fb825dafb3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1564}}}]}, {"ruleId": "scanner-5b6df393face9d5a", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/schedulers (public/scripts/extensions/stable-diffusion/index.js:1583)"}, "properties": {"repobilityId": "e173049de95ab884", "scanner": "scanner-primary", "fingerprint": "5b6df393face9d5a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1583}}}]}, {"ruleId": "scanner-86f1b56de1b51740", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/sd-next/upscalers (public/scripts/extensions/stable-diffusion/index.js:1602)"}, "properties": {"repobilityId": "bea3aa07b54ef7a7", "scanner": "scanner-primary", "fingerprint": "86f1b56de1b51740", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1602}}}]}, {"ruleId": "scanner-6a4b641d0be87922", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/drawthings/get-upscaler (public/scripts/extensions/stable-diffusion/index.js:1621)"}, "properties": {"repobilityId": "3af2e45812906be7", "scanner": "scanner-primary", "fingerprint": "6a4b641d0be87922", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1621}}}]}, {"ruleId": "scanner-7da19687a640a44a", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/set-model (public/scripts/extensions/stable-diffusion/index.js:1642)"}, "properties": {"repobilityId": "e3532317cf69465f", "scanner": "scanner-primary", "fingerprint": "7da19687a640a44a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1642}}}]}, {"ruleId": "scanner-211b7c7b1e63f162", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/sd-samplers (public/scripts/extensions/stable-diffusion/index.js:1766)"}, "properties": {"repobilityId": "796cb15ad6620760", "scanner": "scanner-primary", "fingerprint": "211b7c7b1e63f162", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1766}}}]}, {"ruleId": "scanner-1e694f3d9aefab9e", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/samplers (public/scripts/extensions/stable-diffusion/index.js:1801)"}, "properties": {"repobilityId": "e102dc87cbe5e83b", "scanner": "scanner-primary", "fingerprint": "1e694f3d9aefab9e", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1801}}}]}, {"ruleId": "scanner-659586fa770a5f58", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/sdcpp/models (public/scripts/extensions/stable-diffusion/index.js:1823)"}, "properties": {"repobilityId": "6968f3628818d6b1", "scanner": "scanner-primary", "fingerprint": "659586fa770a5f58", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1823}}}]}, {"ruleId": "scanner-0b63d5db30da36e5", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/samplers (public/scripts/extensions/stable-diffusion/index.js:1909)"}, "properties": {"repobilityId": "8f2754b24c672e6b", "scanner": "scanner-primary", "fingerprint": "0b63d5db30da36e5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 1909}}}]}, {"ruleId": "scanner-1c14fb6bb1f0355f", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/falai/models (public/scripts/extensions/stable-diffusion/index.js:2110)"}, "properties": {"repobilityId": "4080b0989adf5903", "scanner": "scanner-primary", "fingerprint": "1c14fb6bb1f0355f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2110}}}]}, {"ruleId": "scanner-bcb934f0afea6486", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/workersai/models (public/scripts/extensions/stable-diffusion/index.js:2141)"}, "properties": {"repobilityId": "ff4c7b9eb40f58fe", "scanner": "scanner-primary", "fingerprint": "bcb934f0afea6486", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2141}}}]}, {"ruleId": "scanner-2eb636264a022851", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/pollinations/models (public/scripts/extensions/stable-diffusion/index.js:2159)"}, "properties": {"repobilityId": "9b9a1fc0fcb8091a", "scanner": "scanner-primary", "fingerprint": "2eb636264a022851", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2159}}}]}, {"ruleId": "scanner-54bab08a2cb868f5", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/together/models (public/scripts/extensions/stable-diffusion/index.js:2177)"}, "properties": {"repobilityId": "61f766e8794ae2c8", "scanner": "scanner-primary", "fingerprint": "54bab08a2cb868f5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2177}}}]}, {"ruleId": "scanner-408fe525fea1385c", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/chutes/models (public/scripts/extensions/stable-diffusion/index.js:2195)"}, "properties": {"repobilityId": "74b6b7165e376d7e", "scanner": "scanner-primary", "fingerprint": "408fe525fea1385c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2195}}}]}, {"ruleId": "scanner-39efd5e2008eb9cb", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/electronhub/models (public/scripts/extensions/stable-diffusion/index.js:2216)"}, "properties": {"repobilityId": "107cbae72d64369b", "scanner": "scanner-primary", "fingerprint": "39efd5e2008eb9cb", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2216}}}]}, {"ruleId": "scanner-b33ae31a32879a01", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/nanogpt/models (public/scripts/extensions/stable-diffusion/index.js:2249)"}, "properties": {"repobilityId": "39f706c6835bfcf7", "scanner": "scanner-primary", "fingerprint": "b33ae31a32879a01", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2249}}}]}, {"ruleId": "scanner-6fddccc5951b4341", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/sd-models (public/scripts/extensions/stable-diffusion/index.js:2262)"}, "properties": {"repobilityId": "75982dd62bfec609", "scanner": "scanner-primary", "fingerprint": "6fddccc5951b4341", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2262}}}]}, {"ruleId": "scanner-982197701b4c58a7", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/models (public/scripts/extensions/stable-diffusion/index.js:2317)"}, "properties": {"repobilityId": "e4253365339e8d23", "scanner": "scanner-primary", "fingerprint": "982197701b4c58a7", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2317}}}]}, {"ruleId": "scanner-422b55ee7a12cbe5", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/aimlapi/models (public/scripts/extensions/stable-diffusion/index.js:2401)"}, "properties": {"repobilityId": "20b737ac0528cfad", "scanner": "scanner-primary", "fingerprint": "422b55ee7a12cbe5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2401}}}]}, {"ruleId": "scanner-0d3562b08a53baec", "level": "error", "message": {"text": "Dangling fetch: POST /api/openrouter/models/image (public/scripts/extensions/stable-diffusion/index.js:2525)"}, "properties": {"repobilityId": "13b44de6bf34b9a0", "scanner": "scanner-primary", "fingerprint": "0d3562b08a53baec", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2525}}}]}, {"ruleId": "scanner-61c47a6c1868b8ca", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/models (public/scripts/extensions/stable-diffusion/index.js:2553)"}, "properties": {"repobilityId": "da29fc224b97e8ce", "scanner": "scanner-primary", "fingerprint": "61c47a6c1868b8ca", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2553}}}]}, {"ruleId": "scanner-a95163d435d68e93", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/schedulers (public/scripts/extensions/stable-diffusion/index.js:2671)"}, "properties": {"repobilityId": "cded937caf4f222f", "scanner": "scanner-primary", "fingerprint": "a95163d435d68e93", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2671}}}]}, {"ruleId": "scanner-79f23601878caa6a", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/vaes (public/scripts/extensions/stable-diffusion/index.js:2791)"}, "properties": {"repobilityId": "8c4646af1c847f4b", "scanner": "scanner-primary", "fingerprint": "79f23601878caa6a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2791}}}]}, {"ruleId": "scanner-5bd9f5fae85ffa03", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/vaes (public/scripts/extensions/stable-diffusion/index.js:2818)"}, "properties": {"repobilityId": "b4cd2332aed8ad26", "scanner": "scanner-primary", "fingerprint": "5bd9f5fae85ffa03", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2818}}}]}, {"ruleId": "scanner-663cb9153164f25a", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/workflows (public/scripts/extensions/stable-diffusion/index.js:2837)"}, "properties": {"repobilityId": "40eeaac98313a2de", "scanner": "scanner-primary", "fingerprint": "663cb9153164f25a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 2837}}}]}, {"ruleId": "scanner-bf6e404676aeb1d1", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/together/generate (public/scripts/extensions/stable-diffusion/index.js:3461)"}, "properties": {"repobilityId": "0b609b5ba2d07c22", "scanner": "scanner-primary", "fingerprint": "bf6e404676aeb1d1", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3461}}}]}, {"ruleId": "scanner-77f30aa36d141b41", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/pollinations/generate (public/scripts/extensions/stable-diffusion/index.js:3492)"}, "properties": {"repobilityId": "20a182fd8e599d0b", "scanner": "scanner-primary", "fingerprint": "77f30aa36d141b41", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3492}}}]}, {"ruleId": "scanner-130e31b569bf08c7", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/electronhub/sizes (public/scripts/extensions/stable-diffusion/index.js:3650)"}, "properties": {"repobilityId": "6b7f01535170eaf4", "scanner": "scanner-primary", "fingerprint": "130e31b569bf08c7", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3650}}}]}, {"ruleId": "scanner-c8376a9a20f96151", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/stability/generate (public/scripts/extensions/stable-diffusion/index.js:3716)"}, "properties": {"repobilityId": "2d9d35bae8d03323", "scanner": "scanner-primary", "fingerprint": "c8376a9a20f96151", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3716}}}]}, {"ruleId": "scanner-8885a03363951843", "level": "error", "message": {"text": "Dangling fetch: POST /api/horde/generate-image (public/scripts/extensions/stable-diffusion/index.js:3758)"}, "properties": {"repobilityId": "88a4d99c3233cef3", "scanner": "scanner-primary", "fingerprint": "8885a03363951843", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3758}}}]}, {"ruleId": "scanner-a64d253a77435dcb", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/generate (public/scripts/extensions/stable-diffusion/index.js:3848)"}, "properties": {"repobilityId": "ca174369c86b75be", "scanner": "scanner-primary", "fingerprint": "a64d253a77435dcb", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3848}}}]}, {"ruleId": "scanner-f1d6152343141aef", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/sdcpp/generate (public/scripts/extensions/stable-diffusion/index.js:3898)"}, "properties": {"repobilityId": "c3887d214ac450fe", "scanner": "scanner-primary", "fingerprint": "f1d6152343141aef", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3898}}}]}, {"ruleId": "scanner-8856d8c4fd3048f4", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/drawthings/generate (public/scripts/extensions/stable-diffusion/index.js:3923)"}, "properties": {"repobilityId": "08ef753f5a6089d9", "scanner": "scanner-primary", "fingerprint": "8856d8c4fd3048f4", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3923}}}]}, {"ruleId": "scanner-40972fb202994159", "level": "error", "message": {"text": "Dangling fetch: POST /api/novelai/generate-image (public/scripts/extensions/stable-diffusion/index.js:3966)"}, "properties": {"repobilityId": "4984d520e1594015", "scanner": "scanner-primary", "fingerprint": "40972fb202994159", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 3966}}}]}, {"ruleId": "scanner-15331ac1e41b73f3", "level": "error", "message": {"text": "Dangling fetch: POST /api/openai/generate-video (public/scripts/extensions/stable-diffusion/index.js:4124)"}, "properties": {"repobilityId": "3a667a7446ccc7e2", "scanner": "scanner-primary", "fingerprint": "15331ac1e41b73f3", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4124}}}]}, {"ruleId": "scanner-dc352058b786e0e5", "level": "error", "message": {"text": "Dangling fetch: POST /api/openai/generate-image (public/scripts/extensions/stable-diffusion/index.js:4144)"}, "properties": {"repobilityId": "462584d709f781ce", "scanner": "scanner-primary", "fingerprint": "dc352058b786e0e5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4144}}}]}, {"ruleId": "scanner-642e0de853c2dcdb", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/aimlapi/generate-image (public/scripts/extensions/stable-diffusion/index.js:4198)"}, "properties": {"repobilityId": "c7928e9e10f6e7f1", "scanner": "scanner-primary", "fingerprint": "642e0de853c2dcdb", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4198}}}]}, {"ruleId": "scanner-dce5d8addf7e4660", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/workflow (public/scripts/extensions/stable-diffusion/index.js:4222)"}, "properties": {"repobilityId": "21f7ed9a57c605fb", "scanner": "scanner-primary", "fingerprint": "dce5d8addf7e4660", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4222}}}]}, {"ruleId": "scanner-7424224aaee105e1", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/huggingface/generate (public/scripts/extensions/stable-diffusion/index.js:4343)"}, "properties": {"repobilityId": "8a6a6aae2fd49b19", "scanner": "scanner-primary", "fingerprint": "7424224aaee105e1", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4343}}}]}, {"ruleId": "scanner-4db7c5e27d5d5149", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/chutes/generate (public/scripts/extensions/stable-diffusion/index.js:4370)"}, "properties": {"repobilityId": "a3ac34794e47a491", "scanner": "scanner-primary", "fingerprint": "4db7c5e27d5d5149", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4370}}}]}, {"ruleId": "scanner-5924b595f2196d3a", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/electronhub/generate (public/scripts/extensions/stable-diffusion/index.js:4403)"}, "properties": {"repobilityId": "3fb25e349399c4de", "scanner": "scanner-primary", "fingerprint": "5924b595f2196d3a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4403}}}]}, {"ruleId": "scanner-80613b8817c1338c", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/nanogpt/generate (public/scripts/extensions/stable-diffusion/index.js:4432)"}, "properties": {"repobilityId": "0d33142f20f3595a", "scanner": "scanner-primary", "fingerprint": "80613b8817c1338c", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4432}}}]}, {"ruleId": "scanner-3923826fcd4b73d8", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/bfl/generate (public/scripts/extensions/stable-diffusion/index.js:4466)"}, "properties": {"repobilityId": "02a7fe5df7896b51", "scanner": "scanner-primary", "fingerprint": "3923826fcd4b73d8", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4466}}}]}, {"ruleId": "scanner-b62c4daa519a6242", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/xai/generate (public/scripts/extensions/stable-diffusion/index.js:4509)"}, "properties": {"repobilityId": "7fcf4ece150fc862", "scanner": "scanner-primary", "fingerprint": "b62c4daa519a6242", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4509}}}]}, {"ruleId": "scanner-b5c256cd967aee97", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/falai/generate (public/scripts/extensions/stable-diffusion/index.js:4538)"}, "properties": {"repobilityId": "cde6690f704f1bb6", "scanner": "scanner-primary", "fingerprint": "b5c256cd967aee97", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4538}}}]}, {"ruleId": "scanner-2306d180b9086465", "level": "error", "message": {"text": "Dangling fetch: POST /api/google/generate-video (public/scripts/extensions/stable-diffusion/index.js:4576)"}, "properties": {"repobilityId": "04dc3ffe363497b4", "scanner": "scanner-primary", "fingerprint": "2306d180b9086465", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4576}}}]}, {"ruleId": "scanner-3a3df48da855bae1", "level": "error", "message": {"text": "Dangling fetch: POST /api/google/generate-image (public/scripts/extensions/stable-diffusion/index.js:4603)"}, "properties": {"repobilityId": "bcef40b8e45a32e2", "scanner": "scanner-primary", "fingerprint": "3a3df48da855bae1", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4603}}}]}, {"ruleId": "scanner-98b04ec5d83f472d", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/zai/generate-video (public/scripts/extensions/stable-diffusion/index.js:4649)"}, "properties": {"repobilityId": "cc38cea6b72c3a6a", "scanner": "scanner-primary", "fingerprint": "98b04ec5d83f472d", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4649}}}]}, {"ruleId": "scanner-82b06b6e21290dcf", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/zai/generate (public/scripts/extensions/stable-diffusion/index.js:4688)"}, "properties": {"repobilityId": "726e965922c3788b", "scanner": "scanner-primary", "fingerprint": "82b06b6e21290dcf", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4688}}}]}, {"ruleId": "scanner-ba8b66db876ceb87", "level": "error", "message": {"text": "Dangling fetch: POST /api/openrouter/image/generate (public/scripts/extensions/stable-diffusion/index.js:4717)"}, "properties": {"repobilityId": "800b6f9331c2d7af", "scanner": "scanner-primary", "fingerprint": "ba8b66db876ceb87", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4717}}}]}, {"ruleId": "scanner-29838c78dff6d0c5", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/workersai/generate (public/scripts/extensions/stable-diffusion/index.js:4738)"}, "properties": {"repobilityId": "46f0f83a0e958142", "scanner": "scanner-primary", "fingerprint": "29838c78dff6d0c5", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4738}}}]}, {"ruleId": "scanner-175cf3119b2acc91", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/save-workflow (public/scripts/extensions/stable-diffusion/index.js:4842)"}, "properties": {"repobilityId": "09a37818341ebf0d", "scanner": "scanner-primary", "fingerprint": "175cf3119b2acc91", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4842}}}]}, {"ruleId": "scanner-fbc9af0bb293ae0a", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/delete-workflow (public/scripts/extensions/stable-diffusion/index.js:4889)"}, "properties": {"repobilityId": "57f438d07d71c4e1", "scanner": "scanner-primary", "fingerprint": "fbc9af0bb293ae0a", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4889}}}]}, {"ruleId": "scanner-a208d45e7d84b221", "level": "error", "message": {"text": "Dangling fetch: POST /api/sd/comfy/rename-workflow (public/scripts/extensions/stable-diffusion/index.js:4936)"}, "properties": {"repobilityId": "e9d1287668f46213", "scanner": "scanner-primary", "fingerprint": "a208d45e7d84b221", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/stable-diffusion/index.js"}, "region": {"startLine": 4936}}}]}, {"ruleId": "scanner-ec9908545571366f", "level": "error", "message": {"text": "Dangling fetch: POST /api/extra/classify (public/scripts/extensions/expressions/index.js:1062)"}, "properties": {"repobilityId": "26f448686ca89543", "scanner": "scanner-primary", "fingerprint": "ec9908545571366f", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/expressions/index.js"}, "region": {"startLine": 1062}}}]}, {"ruleId": "scanner-84c99297bcfca32d", "level": "error", "message": {"text": "Dangling fetch: GET /api/sprites/get?name=${encodeURIComponent(name)} (public/scripts/extensions/expressions/index.js:1295)"}, "properties": {"repobilityId": "f54e4fe295236295", "scanner": "scanner-primary", "fingerprint": "84c99297bcfca32d", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/expressions/index.js"}, "region": {"startLine": 1295}}}]}, {"ruleId": "scanner-1d9b584c518eb89b", "level": "error", "message": {"text": "Dangling fetch: POST /api/extra/classify/labels (public/scripts/extensions/expressions/index.js:1445)"}, "properties": {"repobilityId": "d72732b990aa72b8", "scanner": "scanner-primary", "fingerprint": "1d9b584c518eb89b", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/expressions/index.js"}, "region": {"startLine": 1445}}}]}, {"ruleId": "scanner-eea1c5e93a617802", "level": "error", "message": {"text": "Dangling fetch: POST /api/sprites/delete (public/scripts/extensions/expressions/index.js:2072)"}, "properties": {"repobilityId": "59bd2e2e902c313c", "scanner": "scanner-primary", "fingerprint": "eea1c5e93a617802", "layer": "api", "severity": "high", "confidence": 0.9, "tags": ["wiring", "dangling-fetch", "fetch"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/scripts/extensions/expressions/index.js"}, "region": {"startLine": 2072}}}]}, {"ruleId": "scanner-d065b3d84e0ba3dc", "level": "note", "message": {"text": "282 backend endpoints not called by scanned frontend"}, "properties": {"repobilityId": "3c8e96670c5e1f9f", "scanner": "scanner-primary", "fingerprint": "d065b3d84e0ba3dc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}