{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-89ad996084d827bc", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-a.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-a.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e62ed6849282f68", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b2.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b2.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16dfe0e34dd0c171", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-cancellation.ts:35", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-cancellation.ts:35"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43f0a4db788d8172", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-business-rules.ts:56", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-business-rules.ts:56"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e740c261f9f1b1b4", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b1.ts:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b1.ts:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ece733cb7a47f282", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-negative.ts:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-negative.ts:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-106414007574c4ce", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-coverage.ts:43", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-coverage.ts:43"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-053e1bae165712d0", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-notifications.ts:43", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-notifications.ts:43"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4bd655bdabc730b", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-boarding.ts:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-boarding.ts:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33f92e03980334c2", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-ratings-sos.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-ratings-sos.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a8bfb8638f4f90b", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-security.ts:27", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-security.ts:27"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d03c06b986408f59", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-complaints.ts:47", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-complaints.ts:47"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76debd6b37bc095b", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-audit-trail.ts:53", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-audit-trail.ts:53"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6cf7f4f144758873", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final.ts:48", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final.ts:48"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5a09c4cb2525167", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b.ts:42", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b.ts:42"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54ec1522453b9b01", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-extended.ts:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-extended.ts:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a37ec196abfa2507", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-edge-cases.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-edge-cases.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03d964968b6d38bd", "name": "Stray `console.log` in TS/JS \u2014 tests/e2e-api.ts:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api.ts:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb1a32a874a5b131", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/main.ts:112", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/main.ts:112"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de5f4a03b9c42d43", "name": "TODO/FIXME marker in shipping code \u2014 apps/api/src/common/guards/email-verified.guard.ts:12", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 apps/api/src/common/guards/email-verified.guard.ts:12"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c102817e3dd748f0", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/modules/sos/sos.service.ts:91", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/modules/sos/sos.service.ts:91"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4116a6e907500a26", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/modules/registration/registration.service.ts:710", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/modules/registration/registration.service.ts:710"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0d1e612e8672e19", "name": "Icon-only button without accessible name \u2014 apps/web/src/components/ui/ReportUserModal.tsx:57", "shortDescription": {"text": "Icon-only button without accessible name \u2014 apps/web/src/components/ui/ReportUserModal.tsx:57"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d171bb7ae590647", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/ContactCard.tsx:51", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/ContactCard.tsx:51"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d874ad835d47e735", "name": "Icon-only button without accessible name \u2014 apps/web/src/components/ui/MapPinModal.tsx:90", "shortDescription": {"text": "Icon-only button without accessible name \u2014 apps/web/src/components/ui/MapPinModal.tsx:90"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e39401d86835361", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/SavedLocationPicker.tsx:216", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/SavedLocationPicker.tsx:216"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cece35153b3b3823", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/RideCard.tsx:60", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/RideCard.tsx:60"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a9c63f09b167ea06", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/LocationInput.tsx:102", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/LocationInput.tsx:102"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-acdf1f838e228af9", "name": "Stray `console.log` in TS/JS \u2014 apps/web/src/app/api/maps/place-details/route.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/app/api/maps/place-details/route.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a1ec5d4a3ebf537", "name": "Stray `console.log` in TS/JS \u2014 apps/web/src/app/api/maps/autocomplete/route.ts:76", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/app/api/maps/autocomplete/route.ts:76"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-919b39a6e0a893d1", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/page.tsx:319", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/page.tsx:319"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5a607791d011a134", "name": "TODO/FIXME marker in shipping code \u2014 apps/web/src/app/(dashboard)/rides/page.tsx:40", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 apps/web/src/app/(dashboard)/rides/page.tsx:40"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4d88289987d60d71", "name": "Icon-only button without accessible name \u2014 apps/web/src/app/(dashboard)/rides/search/page.tsx:96", "shortDescription": {"text": "Icon-only button without accessible name \u2014 apps/web/src/app/(dashboard)/rides/search/page.tsx:96"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67b8bf40afc7df5a", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/search/page.tsx:254", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/search/page.tsx:254"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9eafefdafe89b1e4", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/leaderboard/page.tsx:95", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/leaderboard/page.tsx:95"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b302b50e148348b2", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/board/page.tsx:279", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/board/page.tsx:279"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-19a2ee176d385580", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/requests/page.tsx:130", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/requests/page.tsx:130"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0d11ca7c0794cdb5", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/dashboard/page.tsx:328", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/dashboard/page.tsx:328"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7d846b4aff5e04c0", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/profile/page.tsx:426", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/profile/page.tsx:426"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f371312ea0967abc", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/profile/locations/page.tsx:243", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/profile/locations/page.tsx:243"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-77314c7a1c7c4b8a", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/layout.tsx:94", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/layout.tsx:94"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a405a85ddd6fa548", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/rides/page.tsx:289", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/rides/page.tsx:289"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-689742d6e18e989d", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/rides/RideDetailPanel.tsx:288", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/rides/RideDetailPanel.tsx:288"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d5810ef9d6f6d71a", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/users/page.tsx:302", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/users/page.tsx:302"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-27c7bcefc75211b1", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/users/[id]/page.tsx:476", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/users/[id]/page.tsx:476"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f97c5c0ef736b744", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/verification/page.tsx:101", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/verification/page.tsx:101"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a3c1e4dbeb030737", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/audit-log/page.tsx:134", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/audit-log/page.tsx:134"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dfc0725671f0525b", "name": "Stray `console.log` in TS/JS \u2014 apps/web/src/lib/mappls-token.ts:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/lib/mappls-token.ts:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8282458faae943c1", "name": "Stray `console.log` in TS/JS \u2014 prisma/reset-test-data.ts:70", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 prisma/reset-test-data.ts:70"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5398b5136990b23b", "name": "Stray `console.log` in TS/JS \u2014 prisma/seed.ts:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 prisma/seed.ts:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97af1a58ee38f687", "name": "TODO/FIXME marker in shipping code \u2014 packages/shared/src/enums.ts:6", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/shared/src/enums.ts:6"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00d35e9f7a0e9de7", "name": "Runtime dotenv file present in repo: .env.railway", "shortDescription": {"text": "Runtime dotenv file present in repo: .env.railway"}, "fullDescription": {"text": "`.env.railway` looks like a runtime dotenv file. It contains secret-looking assignments for MINIO_ACCESS_KEY, MINIO_SECRET_KEY. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-e611a3c1783f8baf", "name": "Runtime dotenv file present in repo: apps/web/.env.production", "shortDescription": {"text": "Runtime dotenv file present in repo: apps/web/.env.production"}, "fullDescription": {"text": "`apps/web/.env.production` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f4ad58d61f29078", "name": "Insecure pattern 'node_child_process' in package.json:47", "shortDescription": {"text": "Insecure pattern 'node_child_process' in package.json:47"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf5a5d066334f3e5", "name": "Insecure pattern 'cors_wildcard' in apps/api/src/modules/live-tracking/live-tracking.gateway.ts:17", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in apps/api/src/modules/live-tracking/live-tracking.gateway.ts:17"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d80960f68dd8de34", "name": "Insecure pattern 'local_storage_auth_token' in apps/web/src/lib/api.ts:35", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/lib/api.ts:35"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-050c63b8ef24880d", "name": "Insecure pattern 'local_storage_auth_token' in apps/web/src/store/auth.store.ts:54", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/store/auth.store.ts:54"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0441f4b4d2024658", "name": "Possible secret in prisma/seed.ts", "shortDescription": {"text": "Possible secret in prisma/seed.ts"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-895bbdf06dccad13", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/github-script@v7 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be86ca6298353713", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-64192a3c67110d01", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-740b5c2d4050381e", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a3483b30ccc8961", "name": "Very large file: tests/e2e-api-final-a.ts (980 lines)", "shortDescription": {"text": "Very large file: tests/e2e-api-final-a.ts (980 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b66b1ee2334dbcd3", "name": "Very large file: tests/e2e-api-final.ts (1774 lines)", "shortDescription": {"text": "Very large file: tests/e2e-api-final.ts (1774 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e3af6e888f46162", "name": "Very large file: apps/api/src/modules/rides/rides.service.ts (1191 lines)", "shortDescription": {"text": "Very large file: apps/api/src/modules/rides/rides.service.ts (1191 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5093879ab8f10e9", "name": "Very large file: apps/web/src/app/(dashboard)/rides/[id]/page.tsx (1077 lines)", "shortDescription": {"text": "Very large file: apps/web/src/app/(dashboard)/rides/[id]/page.tsx (1077 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01f96f71d9907a8c", "name": "README lacks setup or run instructions", "shortDescription": {"text": "README lacks setup or run instructions"}, "fullDescription": {"text": "A README exists, but it does not contain common install/setup/run markers. This matches a frequent generated-code pattern: UI is present, operational handoff is thin."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b06b8d86f24c77f9", "name": "Node manifest has dependencies but no lockfile: apps/api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 61 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 104 placeholder/mock markers across 30 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: operator-readme, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing operator-readme, lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c5f98b152cddb6d", "name": "Agent authority lacks a verifier contract: .claude/launch.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-73e5cf83a2153f92", "name": "Commented-code block (6 lines) in tests/e2e/giver-flow.spec.ts:292", "shortDescription": {"text": "Commented-code block (6 lines) in tests/e2e/giver-flow.spec.ts:292"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e87284bad27e1a9", "name": "Legacy-named symbol `WrongOld` in tests/e2e/auth.spec.ts:185", "shortDescription": {"text": "Legacy-named symbol `WrongOld` in tests/e2e/auth.spec.ts:185"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55481955730ab264", "name": "Commented-code block (5 lines) in tests/e2e/lifecycle.spec.ts:94", "shortDescription": {"text": "Commented-code block (5 lines) in tests/e2e/lifecycle.spec.ts:94"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c279d1cf4e82e473", "name": "Commented-code block (6 lines) in tests/e2e/verification-bypass.spec.ts:9", "shortDescription": {"text": "Commented-code block (6 lines) in tests/e2e/verification-bypass.spec.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-794bbe3efd737d0f", "name": "Commented-code block (6 lines) in tests/e2e/permission-leaks.spec.ts:179", "shortDescription": {"text": "Commented-code block (6 lines) in tests/e2e/permission-leaks.spec.ts:179"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-22fdf6016ea5fba4", "name": "Commented-code block (5 lines) in apps/web/src/app/(dashboard)/rides/page.tsx:84", "shortDescription": {"text": "Commented-code block (5 lines) in apps/web/src/app/(dashboard)/rides/page.tsx:84"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b0b5e7cb1208a7cd", "name": "13 env vars used in code but missing from .env.example", "shortDescription": {"text": "13 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CI`, `FRONTEND_URL`, `NEXT_PUBLIC_APP_COMMIT`, `NEXT_PUBLIC_APP_URL`, `NEXT_PUBLIC_APP_VERSION`, `NEXT_PUBLIC_FEATURE_RECURRING_RIDES`, `NEXT_PUBLIC_FEATURE_WOMEN_ONLY`, `PLAYWRIGHT_BASE_URL` + 5 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ead3e453dba206f", "name": "Dangling fetch: GET /api/maps/autocomplete?input=${encodeURIComponent(input.trim())} (apps/web/src/components/ui/MapPinM", "shortDescription": {"text": "Dangling fetch: GET /api/maps/autocomplete?input=${encodeURIComponent(input.trim())} (apps/web/src/components/ui/MapPinModal.tsx:56)"}, "fullDescription": {"text": "`apps/web/src/components/ui/MapPinModal.tsx:56` calls `GET /api/maps/autocomplete?input=${encodeURIComponent(input.trim())}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/maps/autocomplete`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea9bfa7935c50dc5", "name": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/componen", "shortDescription": {"text": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/components/ui/SavedLocationPicker.tsx:58)"}, "fullDescription": {"text": "`apps/web/src/components/ui/SavedLocationPicker.tsx:58` calls `GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/nominatim.openstreetmap.org/reverse`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-88df9d1d53ade7ce", "name": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/app/api/", "shortDescription": {"text": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/app/api/maps/reverse-geocode/route.ts:30)"}, "fullDescription": {"text": "`apps/web/src/app/api/maps/reverse-geocode/route.ts:30` calls `GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/nominatim.openstreetmap.org/reverse`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8642a4795e5754c9", "name": "Dangling fetch: GET https://atlas.mappls.com/api/places/place-details/json?placeId=${encodeURIComponent(placeId)} (apps/", "shortDescription": {"text": "Dangling fetch: GET https://atlas.mappls.com/api/places/place-details/json?placeId=${encodeURIComponent(placeId)} (apps/web/src/app/api/maps/place-details/route.ts:12)"}, "fullDescription": {"text": "`apps/web/src/app/api/maps/place-details/route.ts:12` calls `GET https://atlas.mappls.com/api/places/place-details/json?placeId=${encodeURIComponent(placeId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/atlas.mappls.com/api/places/place-details/json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c7cc9ba8af3650cf", "name": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/app/(dashboard)/rides/search/page.tsx:", "shortDescription": {"text": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/app/(dashboard)/rides/search/page.tsx:65)"}, "fullDescription": {"text": "`apps/web/src/app/(dashboard)/rides/search/page.tsx:65` calls `GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/maps/reverse-geocode`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c1b3557ab53e78e", "name": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/lib/geo.ts:19)", "shortDescription": {"text": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/lib/geo.ts:19)"}, "fullDescription": {"text": "`apps/web/src/lib/geo.ts:19` calls `GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/maps/reverse-geocode`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-823d8d80fc45bb96", "name": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/lib/olamaps.ts:75)", "shortDescription": {"text": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/lib/olamaps.ts:75)"}, "fullDescription": {"text": "`apps/web/src/lib/olamaps.ts:75` calls `GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/maps/reverse-geocode`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-47a6da54041fa200", "name": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/lib/olam", "shortDescription": {"text": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/lib/olamaps.ts:83)"}, "fullDescription": {"text": "`apps/web/src/lib/olamaps.ts:83` calls `GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/nominatim.openstreetmap.org/reverse`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2af91e6547bfe417", "name": "Dangling fetch: GET /api/maps/place-details?placeId=${encodeURIComponent(placeId)} (apps/web/src/lib/olamaps.ts:172)", "shortDescription": {"text": "Dangling fetch: GET /api/maps/place-details?placeId=${encodeURIComponent(placeId)} (apps/web/src/lib/olamaps.ts:172)"}, "fullDescription": {"text": "`apps/web/src/lib/olamaps.ts:172` calls `GET /api/maps/place-details?placeId=${encodeURIComponent(placeId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/maps/place-details`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c36714694834f8aa", "name": "Unused endpoint: GET /rides/search", "shortDescription": {"text": "Unused endpoint: GET /rides/search"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `GET /rides/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6519acd87fcb8e1", "name": "Unused endpoint: GET /rides/community", "shortDescription": {"text": "Unused endpoint: GET /rides/community"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `GET /rides/community` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef409e359be5a50d", "name": "Unused endpoint: GET /rides/given", "shortDescription": {"text": "Unused endpoint: GET /rides/given"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `GET /rides/given` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-802f432f48772487", "name": "Unused endpoint: GET /rides/taken", "shortDescription": {"text": "Unused endpoint: GET /rides/taken"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `GET /rides/taken` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-931b365cebc87a9d", "name": "Unused endpoint: GET /rides/:id", "shortDescription": {"text": "Unused endpoint: GET /rides/:id"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `GET /rides/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d7b9b3600ce8a08", "name": "Unused endpoint: PATCH /rides/:id/publish", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/publish"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/publish` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1927c0766910f574", "name": "Unused endpoint: PATCH /rides/:id/start", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/start"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6334823b5c2589f3", "name": "Unused endpoint: PATCH /rides/:id/complete", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/complete"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-257aea07f30cfa85", "name": "Unused endpoint: PATCH /rides/:id/edit", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/edit"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/edit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4a02cb03185053a", "name": "Unused endpoint: PATCH /rides/:id/no-show/:seekerId", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/no-show/:seekerId"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/no-show/:seekerId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0e03529be97b468", "name": "Unused endpoint: PATCH /rides/:id/board", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/board"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/board` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-61a302b2ade34736", "name": "Unused endpoint: PATCH /rides/:id/deboard", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/deboard"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/deboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28653a1f3fc52c0c", "name": "Unused endpoint: PATCH /rides/:id/abort", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/abort"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/abort` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9774de463fd19d79", "name": "Unused endpoint: PATCH /rides/:id/cancel", "shortDescription": {"text": "Unused endpoint: PATCH /rides/:id/cancel"}, "fullDescription": {"text": "`apps/api/src/modules/rides/rides.controller.ts` declares `PATCH /rides/:id/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a8b657222dd85be2", "name": "Unused endpoint: GET /users/me", "shortDescription": {"text": "Unused endpoint: GET /users/me"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `GET /users/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f06644688cd47af", "name": "Unused endpoint: PATCH /users/me", "shortDescription": {"text": "Unused endpoint: PATCH /users/me"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `PATCH /users/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-947efce9af77c6b4", "name": "Unused endpoint: GET /users/:id/public", "shortDescription": {"text": "Unused endpoint: GET /users/:id/public"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `GET /users/:id/public` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c26676b083ff088", "name": "Unused endpoint: GET /users/me/emergency-contacts", "shortDescription": {"text": "Unused endpoint: GET /users/me/emergency-contacts"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `GET /users/me/emergency-contacts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53210e73d6ad4343", "name": "Unused endpoint: POST /users/me/emergency-contacts", "shortDescription": {"text": "Unused endpoint: POST /users/me/emergency-contacts"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `POST /users/me/emergency-contacts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9892d7f268e6b1e1", "name": "Unused endpoint: DELETE /users/me/emergency-contacts/:id", "shortDescription": {"text": "Unused endpoint: DELETE /users/me/emergency-contacts/:id"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `DELETE /users/me/emergency-contacts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e908b7b2ac702124", "name": "Unused endpoint: POST /users/me/request-email-change", "shortDescription": {"text": "Unused endpoint: POST /users/me/request-email-change"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `POST /users/me/request-email-change` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c52b53adb90fff8", "name": "Unused endpoint: POST /users/confirm-email-change", "shortDescription": {"text": "Unused endpoint: POST /users/confirm-email-change"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `POST /users/confirm-email-change` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35d1c81fa192bdd7", "name": "Unused endpoint: POST /users/me/request-personal-email-change", "shortDescription": {"text": "Unused endpoint: POST /users/me/request-personal-email-change"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `POST /users/me/request-personal-email-change` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68dc2672e409defd", "name": "Unused endpoint: POST /users/confirm-personal-email-change", "shortDescription": {"text": "Unused endpoint: POST /users/confirm-personal-email-change"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `POST /users/confirm-personal-email-change` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5cbbef729352205", "name": "Unused endpoint: POST /users/me/change-password", "shortDescription": {"text": "Unused endpoint: POST /users/me/change-password"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `POST /users/me/change-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57ad79729de4dfa3", "name": "Unused endpoint: GET /users/me/trust-score", "shortDescription": {"text": "Unused endpoint: GET /users/me/trust-score"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `GET /users/me/trust-score` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c225f14bd3ca7937", "name": "Unused endpoint: GET /users/me/trust-score/history", "shortDescription": {"text": "Unused endpoint: GET /users/me/trust-score/history"}, "fullDescription": {"text": "`apps/api/src/modules/users/users.controller.ts` declares `GET /users/me/trust-score/history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9eec0d6a608d78c2", "name": "Unused endpoint: PATCH /notifications/:id/read", "shortDescription": {"text": "Unused endpoint: PATCH /notifications/:id/read"}, "fullDescription": {"text": "`apps/api/src/modules/notifications/notifications.controller.ts` declares `PATCH /notifications/:id/read` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9a7c59a4096ef36", "name": "Unused endpoint: PATCH /notifications/read-all", "shortDescription": {"text": "Unused endpoint: PATCH /notifications/read-all"}, "fullDescription": {"text": "`apps/api/src/modules/notifications/notifications.controller.ts` declares `PATCH /notifications/read-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1752505072c6634", "name": "Unused endpoint: GET /complaints/my", "shortDescription": {"text": "Unused endpoint: GET /complaints/my"}, "fullDescription": {"text": "`apps/api/src/modules/complaints/complaints.controller.ts` declares `GET /complaints/my` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79eeb5ce954cb642", "name": "Unused endpoint: GET /complaints/admin", "shortDescription": {"text": "Unused endpoint: GET /complaints/admin"}, "fullDescription": {"text": "`apps/api/src/modules/complaints/complaints.controller.ts` declares `GET /complaints/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23faf5bfa46f35fb", "name": "Unused endpoint: PATCH /complaints/admin/:id", "shortDescription": {"text": "Unused endpoint: PATCH /complaints/admin/:id"}, "fullDescription": {"text": "`apps/api/src/modules/complaints/complaints.controller.ts` declares `PATCH /complaints/admin/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-344d78e61d18537e", "name": "Unused endpoint: GET /auth/check-domain", "shortDescription": {"text": "Unused endpoint: GET /auth/check-domain"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `GET /auth/check-domain` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8292c0931391749a", "name": "Unused endpoint: POST /auth/register", "shortDescription": {"text": "Unused endpoint: POST /auth/register"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fdbacfe9430a6ed", "name": "Unused endpoint: POST /auth/login", "shortDescription": {"text": "Unused endpoint: POST /auth/login"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cdd0498f1a6e6340", "name": "Unused endpoint: POST /auth/google", "shortDescription": {"text": "Unused endpoint: POST /auth/google"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0fb6d31ae79638b5", "name": "Unused endpoint: GET /auth/verify-email", "shortDescription": {"text": "Unused endpoint: GET /auth/verify-email"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `GET /auth/verify-email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff5660488b9ce2ca", "name": "Unused endpoint: POST /auth/resend-verification", "shortDescription": {"text": "Unused endpoint: POST /auth/resend-verification"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/resend-verification` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07dcf03b1fb0755b", "name": "Unused endpoint: POST /auth/forgot-password/preview", "shortDescription": {"text": "Unused endpoint: POST /auth/forgot-password/preview"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/forgot-password/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2fe5b92648ca462", "name": "Unused endpoint: POST /auth/forgot-password", "shortDescription": {"text": "Unused endpoint: POST /auth/forgot-password"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/forgot-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4585c350da9e880d", "name": "Unused endpoint: POST /auth/change-password", "shortDescription": {"text": "Unused endpoint: POST /auth/change-password"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/change-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b36892106ecdc9aa", "name": "Unused endpoint: POST /auth/refresh", "shortDescription": {"text": "Unused endpoint: POST /auth/refresh"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7cc63000affeccd", "name": "Unused endpoint: POST /auth/exception-verification", "shortDescription": {"text": "Unused endpoint: POST /auth/exception-verification"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/exception-verification` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00a55307d43c8938", "name": "Unused endpoint: POST /auth/personal-email", "shortDescription": {"text": "Unused endpoint: POST /auth/personal-email"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/personal-email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50ac5c77a7455d32", "name": "Unused endpoint: GET /auth/verify-personal-email", "shortDescription": {"text": "Unused endpoint: GET /auth/verify-personal-email"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `GET /auth/verify-personal-email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00282946d5576548", "name": "Unused endpoint: POST /auth/resend-personal-verification", "shortDescription": {"text": "Unused endpoint: POST /auth/resend-personal-verification"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/resend-personal-verification` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e5c43219b6b41864", "name": "Unused endpoint: POST /auth/webhook/bounce", "shortDescription": {"text": "Unused endpoint: POST /auth/webhook/bounce"}, "fullDescription": {"text": "`apps/api/src/modules/auth/auth.controller.ts` declares `POST /auth/webhook/bounce` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d6d8740fc8e799ed", "name": "Unused endpoint: POST /verification/identity", "shortDescription": {"text": "Unused endpoint: POST /verification/identity"}, "fullDescription": {"text": "`apps/api/src/modules/verification/verification.controller.ts` declares `POST /verification/identity` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2c262ec24d2267b", "name": "Unused endpoint: POST /verification/driver", "shortDescription": {"text": "Unused endpoint: POST /verification/driver"}, "fullDescription": {"text": "`apps/api/src/modules/verification/verification.controller.ts` declares `POST /verification/driver` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96e1040d24573ce1", "name": "Unused endpoint: GET /verification/status", "shortDescription": {"text": "Unused endpoint: GET /verification/status"}, "fullDescription": {"text": "`apps/api/src/modules/verification/verification.controller.ts` declares `GET /verification/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19936"}, "properties": {"repository": "snrdigitalmarketingindia-web/techieride-webapp-v2", "repoUrl": "https://github.com/snrdigitalmarketingindia-web/techieride-webapp-v2", "branch": "main"}, "results": [{"ruleId": "scanner-89ad996084d827bc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-a.ts:41"}, "properties": {"repobilityId": "83af75954e95ffb3", "scanner": "scanner-primary", "fingerprint": "89ad996084d827bc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2e62ed6849282f68", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b2.ts:41"}, "properties": {"repobilityId": "dd4187fae14d50c4", "scanner": "scanner-primary", "fingerprint": "2e62ed6849282f68", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-16dfe0e34dd0c171", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-cancellation.ts:35"}, "properties": {"repobilityId": "506d34f8f5cb3dc9", "scanner": "scanner-primary", "fingerprint": "16dfe0e34dd0c171", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-43f0a4db788d8172", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-business-rules.ts:56"}, "properties": {"repobilityId": "db15a3fc64799e08", "scanner": "scanner-primary", "fingerprint": "43f0a4db788d8172", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e740c261f9f1b1b4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b1.ts:34"}, "properties": {"repobilityId": "2cd03bee30618349", "scanner": "scanner-primary", "fingerprint": "e740c261f9f1b1b4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ece733cb7a47f282", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-negative.ts:31"}, "properties": {"repobilityId": "d15fc1f462356130", "scanner": "scanner-primary", "fingerprint": "ece733cb7a47f282", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-106414007574c4ce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-coverage.ts:43"}, "properties": {"repobilityId": "205687ec95f0d686", "scanner": "scanner-primary", "fingerprint": "106414007574c4ce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-053e1bae165712d0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-notifications.ts:43"}, "properties": {"repobilityId": "633bd27139537661", "scanner": "scanner-primary", "fingerprint": "053e1bae165712d0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b4bd655bdabc730b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-boarding.ts:37"}, "properties": {"repobilityId": "c1b71db921ba0123", "scanner": "scanner-primary", "fingerprint": "b4bd655bdabc730b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-33f92e03980334c2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-ratings-sos.ts:41"}, "properties": {"repobilityId": "e19596afd7e1a0ad", "scanner": "scanner-primary", "fingerprint": "33f92e03980334c2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2a8bfb8638f4f90b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-security.ts:27"}, "properties": {"repobilityId": "dd1474832591a5ff", "scanner": "scanner-primary", "fingerprint": "2a8bfb8638f4f90b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d03c06b986408f59", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-complaints.ts:47"}, "properties": {"repobilityId": "bec661acc673e777", "scanner": "scanner-primary", "fingerprint": "d03c06b986408f59", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-76debd6b37bc095b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-audit-trail.ts:53"}, "properties": {"repobilityId": "1dced85d95f98dca", "scanner": "scanner-primary", "fingerprint": "76debd6b37bc095b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6cf7f4f144758873", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final.ts:48"}, "properties": {"repobilityId": "1f0439d019cfa714", "scanner": "scanner-primary", "fingerprint": "6cf7f4f144758873", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b5a09c4cb2525167", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-final-b.ts:42"}, "properties": {"repobilityId": "6a5fefbd0cf2fe1f", "scanner": "scanner-primary", "fingerprint": "b5a09c4cb2525167", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-54ec1522453b9b01", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-extended.ts:26"}, "properties": {"repobilityId": "581ed792f7f762cb", "scanner": "scanner-primary", "fingerprint": "54ec1522453b9b01", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a37ec196abfa2507", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api-edge-cases.ts:32"}, "properties": {"repobilityId": "6cf841804d644a01", "scanner": "scanner-primary", "fingerprint": "a37ec196abfa2507", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-03d964968b6d38bd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/e2e-api.ts:34"}, "properties": {"repobilityId": "b9b6bc9d78f61bba", "scanner": "scanner-primary", "fingerprint": "03d964968b6d38bd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fb1a32a874a5b131", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/main.ts:112"}, "properties": {"repobilityId": "1df3dab31f34a60f", "scanner": "scanner-primary", "fingerprint": "fb1a32a874a5b131", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-de5f4a03b9c42d43", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 apps/api/src/common/guards/email-verified.guard.ts:12"}, "properties": {"repobilityId": "938d25b754d106be", "scanner": "scanner-primary", "fingerprint": "de5f4a03b9c42d43", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-c102817e3dd748f0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/modules/sos/sos.service.ts:91"}, "properties": {"repobilityId": "1ab4347e64313b70", "scanner": "scanner-primary", "fingerprint": "c102817e3dd748f0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4116a6e907500a26", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/modules/registration/registration.service.ts:710"}, "properties": {"repobilityId": "cac16eae7c4a6cf6", "scanner": "scanner-primary", "fingerprint": "4116a6e907500a26", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e0d1e612e8672e19", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 apps/web/src/components/ui/ReportUserModal.tsx:57"}, "properties": {"repobilityId": "4aac2f376ee9e855", "scanner": "scanner-primary", "fingerprint": "e0d1e612e8672e19", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-6d171bb7ae590647", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/ContactCard.tsx:51"}, "properties": {"repobilityId": "a39b2c2c408b9f53", "scanner": "scanner-primary", "fingerprint": "6d171bb7ae590647", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d874ad835d47e735", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 apps/web/src/components/ui/MapPinModal.tsx:90"}, "properties": {"repobilityId": "187c15865b469c74", "scanner": "scanner-primary", "fingerprint": "d874ad835d47e735", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-2e39401d86835361", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/SavedLocationPicker.tsx:216"}, "properties": {"repobilityId": "df72f981ebe162f6", "scanner": "scanner-primary", "fingerprint": "2e39401d86835361", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-cece35153b3b3823", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/RideCard.tsx:60"}, "properties": {"repobilityId": "b72057c97afad9a2", "scanner": "scanner-primary", "fingerprint": "cece35153b3b3823", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a9c63f09b167ea06", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/ui/LocationInput.tsx:102"}, "properties": {"repobilityId": "e409c4b08d5d2ff2", "scanner": "scanner-primary", "fingerprint": "a9c63f09b167ea06", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-acdf1f838e228af9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/app/api/maps/place-details/route.ts:17"}, "properties": {"repobilityId": "7454783ec7b3b8a8", "scanner": "scanner-primary", "fingerprint": "acdf1f838e228af9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0a1ec5d4a3ebf537", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/app/api/maps/autocomplete/route.ts:76"}, "properties": {"repobilityId": "e2bfe4ec70d3f4e0", "scanner": "scanner-primary", "fingerprint": "0a1ec5d4a3ebf537", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-919b39a6e0a893d1", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/page.tsx:319"}, "properties": {"repobilityId": "779db788b08adabe", "scanner": "scanner-primary", "fingerprint": "919b39a6e0a893d1", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5a607791d011a134", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 apps/web/src/app/(dashboard)/rides/page.tsx:40"}, "properties": {"repobilityId": "331181eda3ff95ac", "scanner": "scanner-primary", "fingerprint": "5a607791d011a134", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-4d88289987d60d71", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 apps/web/src/app/(dashboard)/rides/search/page.tsx:96"}, "properties": {"repobilityId": "ab9c2efa2c0e757e", "scanner": "scanner-primary", "fingerprint": "4d88289987d60d71", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-67b8bf40afc7df5a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/search/page.tsx:254"}, "properties": {"repobilityId": "695e7e101d045cdd", "scanner": "scanner-primary", "fingerprint": "67b8bf40afc7df5a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9eafefdafe89b1e4", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/leaderboard/page.tsx:95"}, "properties": {"repobilityId": "796a4594b5606697", "scanner": "scanner-primary", "fingerprint": "9eafefdafe89b1e4", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b302b50e148348b2", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/rides/board/page.tsx:279"}, "properties": {"repobilityId": "eefaaefcb7e8da9c", "scanner": "scanner-primary", "fingerprint": "b302b50e148348b2", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-19a2ee176d385580", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/requests/page.tsx:130"}, "properties": {"repobilityId": "4c9c2933d7938ff2", "scanner": "scanner-primary", "fingerprint": "19a2ee176d385580", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0d11ca7c0794cdb5", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/dashboard/page.tsx:328"}, "properties": {"repobilityId": "6a0b67c89360c42e", "scanner": "scanner-primary", "fingerprint": "0d11ca7c0794cdb5", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-7d846b4aff5e04c0", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/profile/page.tsx:426"}, "properties": {"repobilityId": "05b62a9994227b06", "scanner": "scanner-primary", "fingerprint": "7d846b4aff5e04c0", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f371312ea0967abc", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/(dashboard)/profile/locations/page.tsx:243"}, "properties": {"repobilityId": "f268074440e505c9", "scanner": "scanner-primary", "fingerprint": "f371312ea0967abc", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-77314c7a1c7c4b8a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/layout.tsx:94"}, "properties": {"repobilityId": "1b5ec2f072bddfd7", "scanner": "scanner-primary", "fingerprint": "77314c7a1c7c4b8a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a405a85ddd6fa548", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/rides/page.tsx:289"}, "properties": {"repobilityId": "1576cda0e8e3dfb9", "scanner": "scanner-primary", "fingerprint": "a405a85ddd6fa548", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-689742d6e18e989d", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/rides/RideDetailPanel.tsx:288"}, "properties": {"repobilityId": "505e9ad1e9ecf9c8", "scanner": "scanner-primary", "fingerprint": "689742d6e18e989d", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d5810ef9d6f6d71a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/users/page.tsx:302"}, "properties": {"repobilityId": "5eda691735b07799", "scanner": "scanner-primary", "fingerprint": "d5810ef9d6f6d71a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-27c7bcefc75211b1", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/users/[id]/page.tsx:476"}, "properties": {"repobilityId": "bae52aabc0e55a70", "scanner": "scanner-primary", "fingerprint": "27c7bcefc75211b1", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f97c5c0ef736b744", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/verification/page.tsx:101"}, "properties": {"repobilityId": "1273ba5eea9ad458", "scanner": "scanner-primary", "fingerprint": "f97c5c0ef736b744", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a3c1e4dbeb030737", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/app/admin/audit-log/page.tsx:134"}, "properties": {"repobilityId": "58b684b9ae3c4980", "scanner": "scanner-primary", "fingerprint": "a3c1e4dbeb030737", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-dfc0725671f0525b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/web/src/lib/mappls-token.ts:33"}, "properties": {"repobilityId": "2a0d1ae6b076209c", "scanner": "scanner-primary", "fingerprint": "dfc0725671f0525b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8282458faae943c1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 prisma/reset-test-data.ts:70"}, "properties": {"repobilityId": "24a5d17ba6b7e59c", "scanner": "scanner-primary", "fingerprint": "8282458faae943c1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5398b5136990b23b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 prisma/seed.ts:14"}, "properties": {"repobilityId": "f77d7e0fb34b08e2", "scanner": "scanner-primary", "fingerprint": "5398b5136990b23b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-97af1a58ee38f687", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/shared/src/enums.ts:6"}, "properties": {"repobilityId": "42c4d085d440e2c4", "scanner": "scanner-primary", "fingerprint": "97af1a58ee38f687", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-00d35e9f7a0e9de7", "level": "error", "message": {"text": "Runtime dotenv file present in repo: .env.railway"}, "properties": {"repobilityId": "1277ea88f5f72ea4", "scanner": "scanner-primary", "fingerprint": "00d35e9f7a0e9de7", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets", "config", "env-file", "runtime-env", "env_file_with_secret"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".env.railway"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e611a3c1783f8baf", "level": "error", "message": {"text": "Runtime dotenv file present in repo: apps/web/.env.production"}, "properties": {"repobilityId": "73e02f1b896586eb", "scanner": "scanner-primary", "fingerprint": "e611a3c1783f8baf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["secrets", "config", "env-file", "runtime-env"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/.env.production"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7f4ad58d61f29078", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in package.json:47"}, "properties": {"repobilityId": "40fa5506c1a3b684", "scanner": "scanner-primary", "fingerprint": "7f4ad58d61f29078", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-bf5a5d066334f3e5", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in apps/api/src/modules/live-tracking/live-tracking.gateway.ts:17"}, "properties": {"repobilityId": "486326269311aacd", "scanner": "scanner-primary", "fingerprint": "bf5a5d066334f3e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/modules/live-tracking/live-tracking.gateway.ts"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-d80960f68dd8de34", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/lib/api.ts:35"}, "properties": {"repobilityId": "fe176b4484ff2bd4", "scanner": "scanner-primary", "fingerprint": "d80960f68dd8de34", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/lib/api.ts"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-050c63b8ef24880d", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in apps/web/src/store/auth.store.ts:54"}, "properties": {"repobilityId": "42dbaa7ff4a49ae8", "scanner": "scanner-primary", "fingerprint": "050c63b8ef24880d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/store/auth.store.ts"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-0441f4b4d2024658", "level": "error", "message": {"text": "Possible secret in prisma/seed.ts"}, "properties": {"repobilityId": "2c940e279f134002", "scanner": "scanner-primary", "fingerprint": "0441f4b4d2024658", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "prisma/seed.ts"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-895bbdf06dccad13", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5928ff8bd52f83ae", "scanner": "scanner-primary", "fingerprint": "895bbdf06dccad13", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-autofix.yml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-895bbdf06dccad13", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5928ff8bd52f83ae", "scanner": "scanner-primary", "fingerprint": "895bbdf06dccad13", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci-autofix.yml"}, "region": {"startLine": 135}}}]}, {"ruleId": "scanner-be86ca6298353713", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1fbd3bd09f71cc72", "scanner": "scanner-primary", "fingerprint": "be86ca6298353713", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-verify.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 275}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 382}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 516}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "bd7f3c1c34d83159", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 657}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 726}}}]}, {"ruleId": "scanner-64192a3c67110d01", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "87338a8bfcb6f435", "scanner": "scanner-primary", "fingerprint": "64192a3c67110d01", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-740b5c2d4050381e", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f92fc9e67da27ac2", "scanner": "scanner-primary", "fingerprint": "740b5c2d4050381e", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/fast-feedback.yml"}, "region": {"startLine": 170}}}]}, {"ruleId": "scanner-1a3483b30ccc8961", "level": "note", "message": {"text": "Very large file: tests/e2e-api-final-a.ts (980 lines)"}, "properties": {"repobilityId": "546e16c97993d3e8", "scanner": "scanner-primary", "fingerprint": "1a3483b30ccc8961", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b66b1ee2334dbcd3", "level": "note", "message": {"text": "Very large file: tests/e2e-api-final.ts (1774 lines)"}, "properties": {"repobilityId": "be2957faa8ba0010", "scanner": "scanner-primary", "fingerprint": "b66b1ee2334dbcd3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4e3af6e888f46162", "level": "note", "message": {"text": "Very large file: apps/api/src/modules/rides/rides.service.ts (1191 lines)"}, "properties": {"repobilityId": "aef17360fc9a2ddb", "scanner": "scanner-primary", "fingerprint": "4e3af6e888f46162", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e5093879ab8f10e9", "level": "note", "message": {"text": "Very large file: apps/web/src/app/(dashboard)/rides/[id]/page.tsx (1077 lines)"}, "properties": {"repobilityId": "7467a3c0683258ab", "scanner": "scanner-primary", "fingerprint": "e5093879ab8f10e9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-01f96f71d9907a8c", "level": "note", "message": {"text": "README lacks setup or run instructions"}, "properties": {"repobilityId": "b6a8cd5bd6b0dfff", "scanner": "scanner-primary", "fingerprint": "01f96f71d9907a8c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b06b8d86f24c77f9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "properties": {"repobilityId": "ce77cd34ed0306d4", "scanner": "scanner-primary", "fingerprint": "b06b8d86f24c77f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "63a55c94274d7a5a", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "55497359625d2e90", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "b353b3833a12d53f", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "b68e417f2be62679", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "0f746ae905ebf486", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "bf9f6ac158549876", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "c66c66bbbffb5edb", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2c5f98b152cddb6d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "properties": {"repobilityId": "0de48c0f4ab303d8", "scanner": "scanner-primary", "fingerprint": "2c5f98b152cddb6d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/launch.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-73e5cf83a2153f92", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/e2e/giver-flow.spec.ts:292"}, "properties": {"repobilityId": "6491ae0cd8c631f5", "scanner": "scanner-primary", "fingerprint": "73e5cf83a2153f92", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1e87284bad27e1a9", "level": "note", "message": {"text": "Legacy-named symbol `WrongOld` in tests/e2e/auth.spec.ts:185"}, "properties": {"repobilityId": "d75f7fa27d99d39f", "scanner": "scanner-primary", "fingerprint": "1e87284bad27e1a9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-55481955730ab264", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/e2e/lifecycle.spec.ts:94"}, "properties": {"repobilityId": "170a89eae74ef431", "scanner": "scanner-primary", "fingerprint": "55481955730ab264", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c279d1cf4e82e473", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/e2e/verification-bypass.spec.ts:9"}, "properties": {"repobilityId": "3ad4346932621604", "scanner": "scanner-primary", "fingerprint": "c279d1cf4e82e473", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-794bbe3efd737d0f", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/e2e/permission-leaks.spec.ts:179"}, "properties": {"repobilityId": "8d8d16bd688b32f8", "scanner": "scanner-primary", "fingerprint": "794bbe3efd737d0f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-22fdf6016ea5fba4", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/web/src/app/(dashboard)/rides/page.tsx:84"}, "properties": {"repobilityId": "605a903c3a259b28", "scanner": "scanner-primary", "fingerprint": "22fdf6016ea5fba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b0b5e7cb1208a7cd", "level": "note", "message": {"text": "13 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "2737b8666c1f7eeb", "scanner": "scanner-primary", "fingerprint": "b0b5e7cb1208a7cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-8ead3e453dba206f", "level": "error", "message": {"text": "Dangling fetch: GET /api/maps/autocomplete?input=${encodeURIComponent(input.trim())} (apps/web/src/components/ui/MapPinModal.tsx:56)"}, "properties": {"repobilityId": "410ad337215cd6e4", "scanner": "scanner-primary", "fingerprint": "8ead3e453dba206f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ea9bfa7935c50dc5", "level": "error", "message": {"text": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/components/ui/SavedLocationPicker.tsx:58)"}, "properties": {"repobilityId": "dd8d4d15b341fef1", "scanner": "scanner-primary", "fingerprint": "ea9bfa7935c50dc5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-88df9d1d53ade7ce", "level": "error", "message": {"text": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/app/api/maps/reverse-geocode/route.ts:30)"}, "properties": {"repobilityId": "574233cbbd72add7", "scanner": "scanner-primary", "fingerprint": "88df9d1d53ade7ce", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8642a4795e5754c9", "level": "error", "message": {"text": "Dangling fetch: GET https://atlas.mappls.com/api/places/place-details/json?placeId=${encodeURIComponent(placeId)} (apps/web/src/app/api/maps/place-details/route.ts:12)"}, "properties": {"repobilityId": "8ebb64b1944f24c6", "scanner": "scanner-primary", "fingerprint": "8642a4795e5754c9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c7cc9ba8af3650cf", "level": "error", "message": {"text": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/app/(dashboard)/rides/search/page.tsx:65)"}, "properties": {"repobilityId": "0d75805734670c0d", "scanner": "scanner-primary", "fingerprint": "c7cc9ba8af3650cf", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0c1b3557ab53e78e", "level": "error", "message": {"text": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/lib/geo.ts:19)"}, "properties": {"repobilityId": "67f6e2e129b5d937", "scanner": "scanner-primary", "fingerprint": "0c1b3557ab53e78e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-823d8d80fc45bb96", "level": "error", "message": {"text": "Dangling fetch: GET /api/maps/reverse-geocode?lat=${lat}&lng=${lng} (apps/web/src/lib/olamaps.ts:75)"}, "properties": {"repobilityId": "5fa27c35b4ceeabf", "scanner": "scanner-primary", "fingerprint": "823d8d80fc45bb96", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-47a6da54041fa200", "level": "error", "message": {"text": "Dangling fetch: GET https://nominatim.openstreetmap.org/reverse?lat=${lat}&lon=${lng}&format=json (apps/web/src/lib/olamaps.ts:83)"}, "properties": {"repobilityId": "e5324125b0f92390", "scanner": "scanner-primary", "fingerprint": "47a6da54041fa200", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2af91e6547bfe417", "level": "error", "message": {"text": "Dangling fetch: GET /api/maps/place-details?placeId=${encodeURIComponent(placeId)} (apps/web/src/lib/olamaps.ts:172)"}, "properties": {"repobilityId": "effaf32d7e42c7ce", "scanner": "scanner-primary", "fingerprint": "2af91e6547bfe417", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c36714694834f8aa", "level": "note", "message": {"text": "Unused endpoint: GET /rides/search"}, "properties": {"repobilityId": "5e7103eb5ef5ce21", "scanner": "scanner-primary", "fingerprint": "c36714694834f8aa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f6519acd87fcb8e1", "level": "note", "message": {"text": "Unused endpoint: GET /rides/community"}, "properties": {"repobilityId": "5e31bdedcebfe67e", "scanner": "scanner-primary", "fingerprint": "f6519acd87fcb8e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ef409e359be5a50d", "level": "note", "message": {"text": "Unused endpoint: GET /rides/given"}, "properties": {"repobilityId": "55b68da6871333dd", "scanner": "scanner-primary", "fingerprint": "ef409e359be5a50d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-802f432f48772487", "level": "note", "message": {"text": "Unused endpoint: GET /rides/taken"}, "properties": {"repobilityId": "793b16e6f2b35f3a", "scanner": "scanner-primary", "fingerprint": "802f432f48772487", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-931b365cebc87a9d", "level": "note", "message": {"text": "Unused endpoint: GET /rides/:id"}, "properties": {"repobilityId": "8ee22ed94bf08f06", "scanner": "scanner-primary", "fingerprint": "931b365cebc87a9d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d7b9b3600ce8a08", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/publish"}, "properties": {"repobilityId": "6c1a74b7515b4e2a", "scanner": "scanner-primary", "fingerprint": "9d7b9b3600ce8a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1927c0766910f574", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/start"}, "properties": {"repobilityId": "c5ead0f379149ce2", "scanner": "scanner-primary", "fingerprint": "1927c0766910f574", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6334823b5c2589f3", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/complete"}, "properties": {"repobilityId": "5ed019f3d3d8f26f", "scanner": "scanner-primary", "fingerprint": "6334823b5c2589f3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-257aea07f30cfa85", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/edit"}, "properties": {"repobilityId": "6aa5dde9d725be75", "scanner": "scanner-primary", "fingerprint": "257aea07f30cfa85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4a02cb03185053a", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/no-show/:seekerId"}, "properties": {"repobilityId": "8c56a87f08b69326", "scanner": "scanner-primary", "fingerprint": "b4a02cb03185053a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d0e03529be97b468", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/board"}, "properties": {"repobilityId": "537a8973cef7756d", "scanner": "scanner-primary", "fingerprint": "d0e03529be97b468", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-61a302b2ade34736", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/deboard"}, "properties": {"repobilityId": "127f48dad56d63d7", "scanner": "scanner-primary", "fingerprint": "61a302b2ade34736", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-28653a1f3fc52c0c", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/abort"}, "properties": {"repobilityId": "dae3a01fcb9b0d35", "scanner": "scanner-primary", "fingerprint": "28653a1f3fc52c0c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9774de463fd19d79", "level": "note", "message": {"text": "Unused endpoint: PATCH /rides/:id/cancel"}, "properties": {"repobilityId": "cc2b2d30f81e61de", "scanner": "scanner-primary", "fingerprint": "9774de463fd19d79", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a8b657222dd85be2", "level": "note", "message": {"text": "Unused endpoint: GET /users/me"}, "properties": {"repobilityId": "c9a9dcc7a229f34b", "scanner": "scanner-primary", "fingerprint": "a8b657222dd85be2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9f06644688cd47af", "level": "note", "message": {"text": "Unused endpoint: PATCH /users/me"}, "properties": {"repobilityId": "055170dd8ac07959", "scanner": "scanner-primary", "fingerprint": "9f06644688cd47af", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-947efce9af77c6b4", "level": "note", "message": {"text": "Unused endpoint: GET /users/:id/public"}, "properties": {"repobilityId": "466bece21fbc8123", "scanner": "scanner-primary", "fingerprint": "947efce9af77c6b4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c26676b083ff088", "level": "note", "message": {"text": "Unused endpoint: GET /users/me/emergency-contacts"}, "properties": {"repobilityId": "7399f33fcf88afb1", "scanner": "scanner-primary", "fingerprint": "6c26676b083ff088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-53210e73d6ad4343", "level": "note", "message": {"text": "Unused endpoint: POST /users/me/emergency-contacts"}, "properties": {"repobilityId": "18e72568c2354fea", "scanner": "scanner-primary", "fingerprint": "53210e73d6ad4343", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9892d7f268e6b1e1", "level": "note", "message": {"text": "Unused endpoint: DELETE /users/me/emergency-contacts/:id"}, "properties": {"repobilityId": "11b881ebb592ed2a", "scanner": "scanner-primary", "fingerprint": "9892d7f268e6b1e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e908b7b2ac702124", "level": "note", "message": {"text": "Unused endpoint: POST /users/me/request-email-change"}, "properties": {"repobilityId": "3be9a0805ec7a753", "scanner": "scanner-primary", "fingerprint": "e908b7b2ac702124", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c52b53adb90fff8", "level": "note", "message": {"text": "Unused endpoint: POST /users/confirm-email-change"}, "properties": {"repobilityId": "18d69331274a98ba", "scanner": "scanner-primary", "fingerprint": "2c52b53adb90fff8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-35d1c81fa192bdd7", "level": "note", "message": {"text": "Unused endpoint: POST /users/me/request-personal-email-change"}, "properties": {"repobilityId": "9f4e9c899fa5cb16", "scanner": "scanner-primary", "fingerprint": "35d1c81fa192bdd7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-68dc2672e409defd", "level": "note", "message": {"text": "Unused endpoint: POST /users/confirm-personal-email-change"}, "properties": {"repobilityId": "282baec8e0bd55f8", "scanner": "scanner-primary", "fingerprint": "68dc2672e409defd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5cbbef729352205", "level": "note", "message": {"text": "Unused endpoint: POST /users/me/change-password"}, "properties": {"repobilityId": "b33fb5fcec8740cb", "scanner": "scanner-primary", "fingerprint": "e5cbbef729352205", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-57ad79729de4dfa3", "level": "note", "message": {"text": "Unused endpoint: GET /users/me/trust-score"}, "properties": {"repobilityId": "541361d1cde0b3f8", "scanner": "scanner-primary", "fingerprint": "57ad79729de4dfa3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c225f14bd3ca7937", "level": "note", "message": {"text": "Unused endpoint: GET /users/me/trust-score/history"}, "properties": {"repobilityId": "343cc2e5b1392fc0", "scanner": "scanner-primary", "fingerprint": "c225f14bd3ca7937", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9eec0d6a608d78c2", "level": "note", "message": {"text": "Unused endpoint: PATCH /notifications/:id/read"}, "properties": {"repobilityId": "ef7ad35057fac038", "scanner": "scanner-primary", "fingerprint": "9eec0d6a608d78c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9a7c59a4096ef36", "level": "note", "message": {"text": "Unused endpoint: PATCH /notifications/read-all"}, "properties": {"repobilityId": "6d61084f380504dd", "scanner": "scanner-primary", "fingerprint": "c9a7c59a4096ef36", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1752505072c6634", "level": "note", "message": {"text": "Unused endpoint: GET /complaints/my"}, "properties": {"repobilityId": "d92376ac5db2ec1b", "scanner": "scanner-primary", "fingerprint": "e1752505072c6634", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-79eeb5ce954cb642", "level": "note", "message": {"text": "Unused endpoint: GET /complaints/admin"}, "properties": {"repobilityId": "ecb6e56acdfc2120", "scanner": "scanner-primary", "fingerprint": "79eeb5ce954cb642", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-23faf5bfa46f35fb", "level": "note", "message": {"text": "Unused endpoint: PATCH /complaints/admin/:id"}, "properties": {"repobilityId": "b1f87470d65fced5", "scanner": "scanner-primary", "fingerprint": "23faf5bfa46f35fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-344d78e61d18537e", "level": "note", "message": {"text": "Unused endpoint: GET /auth/check-domain"}, "properties": {"repobilityId": "286b2182c2aa5904", "scanner": "scanner-primary", "fingerprint": "344d78e61d18537e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8292c0931391749a", "level": "note", "message": {"text": "Unused endpoint: POST /auth/register"}, "properties": {"repobilityId": "ec68020e17376fbe", "scanner": "scanner-primary", "fingerprint": "8292c0931391749a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8fdbacfe9430a6ed", "level": "note", "message": {"text": "Unused endpoint: POST /auth/login"}, "properties": {"repobilityId": "4047eb078b786f80", "scanner": "scanner-primary", "fingerprint": "8fdbacfe9430a6ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cdd0498f1a6e6340", "level": "note", "message": {"text": "Unused endpoint: POST /auth/google"}, "properties": {"repobilityId": "1be6ef7c0c57dc58", "scanner": "scanner-primary", "fingerprint": "cdd0498f1a6e6340", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0fb6d31ae79638b5", "level": "note", "message": {"text": "Unused endpoint: GET /auth/verify-email"}, "properties": {"repobilityId": "6900ddc2bcc64902", "scanner": "scanner-primary", "fingerprint": "0fb6d31ae79638b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff5660488b9ce2ca", "level": "note", "message": {"text": "Unused endpoint: POST /auth/resend-verification"}, "properties": {"repobilityId": "cef3b154a46ded52", "scanner": "scanner-primary", "fingerprint": "ff5660488b9ce2ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07dcf03b1fb0755b", "level": "note", "message": {"text": "Unused endpoint: POST /auth/forgot-password/preview"}, "properties": {"repobilityId": "6ff2a0b0240c5e7a", "scanner": "scanner-primary", "fingerprint": "07dcf03b1fb0755b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e2fe5b92648ca462", "level": "note", "message": {"text": "Unused endpoint: POST /auth/forgot-password"}, "properties": {"repobilityId": "718612a9464860b6", "scanner": "scanner-primary", "fingerprint": "e2fe5b92648ca462", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4585c350da9e880d", "level": "note", "message": {"text": "Unused endpoint: POST /auth/change-password"}, "properties": {"repobilityId": "f1d4c96948853b4c", "scanner": "scanner-primary", "fingerprint": "4585c350da9e880d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b36892106ecdc9aa", "level": "note", "message": {"text": "Unused endpoint: POST /auth/refresh"}, "properties": {"repobilityId": "7497ad9ac944daf2", "scanner": "scanner-primary", "fingerprint": "b36892106ecdc9aa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f7cc63000affeccd", "level": "note", "message": {"text": "Unused endpoint: POST /auth/exception-verification"}, "properties": {"repobilityId": "190b1fdef5b2e55d", "scanner": "scanner-primary", "fingerprint": "f7cc63000affeccd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00a55307d43c8938", "level": "note", "message": {"text": "Unused endpoint: POST /auth/personal-email"}, "properties": {"repobilityId": "39c9bf97dc932f82", "scanner": "scanner-primary", "fingerprint": "00a55307d43c8938", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50ac5c77a7455d32", "level": "note", "message": {"text": "Unused endpoint: GET /auth/verify-personal-email"}, "properties": {"repobilityId": "d064a14d74078d3d", "scanner": "scanner-primary", "fingerprint": "50ac5c77a7455d32", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00282946d5576548", "level": "note", "message": {"text": "Unused endpoint: POST /auth/resend-personal-verification"}, "properties": {"repobilityId": "2641ab98df11898c", "scanner": "scanner-primary", "fingerprint": "00282946d5576548", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e5c43219b6b41864", "level": "note", "message": {"text": "Unused endpoint: POST /auth/webhook/bounce"}, "properties": {"repobilityId": "f9732412da09808e", "scanner": "scanner-primary", "fingerprint": "e5c43219b6b41864", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d6d8740fc8e799ed", "level": "note", "message": {"text": "Unused endpoint: POST /verification/identity"}, "properties": {"repobilityId": "a2e13e942368a4b7", "scanner": "scanner-primary", "fingerprint": "d6d8740fc8e799ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c2c262ec24d2267b", "level": "note", "message": {"text": "Unused endpoint: POST /verification/driver"}, "properties": {"repobilityId": "9d916b95a5fcc12b", "scanner": "scanner-primary", "fingerprint": "c2c262ec24d2267b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-96e1040d24573ce1", "level": "note", "message": {"text": "Unused endpoint: GET /verification/status"}, "properties": {"repobilityId": "e49f88fb195c47ec", "scanner": "scanner-primary", "fingerprint": "96e1040d24573ce1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}