{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-1e9f81140232c568", "name": "Possibly dead Python function: do_GET", "shortDescription": {"text": "Possibly dead Python function: do_GET"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43cfe345e51f3fba", "name": "Possibly dead Python function: log_message", "shortDescription": {"text": "Possibly dead Python function: log_message"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35bd43557d9bc746", "name": "Possibly dead Python function: resolve_blueprint", "shortDescription": {"text": "Possibly dead Python function: resolve_blueprint"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef29551256e07032", "name": "Possibly dead Python function: fetch_types_bulk", "shortDescription": {"text": "Possibly dead Python function: fetch_types_bulk"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76fe029101c3b74b", "name": "Possibly dead Python function: save_station_me_bonus", "shortDescription": {"text": "Possibly dead Python function: save_station_me_bonus"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-492ccc02da8dae3d", "name": "Possibly dead Python function: assets_at_locations", "shortDescription": {"text": "Possibly dead Python function: assets_at_locations"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a14dee99f28fe46f", "name": "Very large file: app/web/main.py (4015 lines)", "shortDescription": {"text": "Very large file: app/web/main.py (4015 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 41 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 23 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2d7f4f907fdef23f", "name": "Commented-code block (6 lines) in launcher.py:136", "shortDescription": {"text": "Commented-code block (6 lines) in launcher.py:136"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-815785dc02d0e7fd", "name": "Commented-code block (6 lines) in app/bom/resolver.py:78", "shortDescription": {"text": "Commented-code block (6 lines) in app/bom/resolver.py:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a7e4ae5f4bcd265e", "name": "Commented-code block (5 lines) in app/web/industry_helper.py:146", "shortDescription": {"text": "Commented-code block (5 lines) in app/web/industry_helper.py:146"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-419443bf968f94cb", "name": "Legacy-named symbol `need_copy` in app/web/main.py:226", "shortDescription": {"text": "Legacy-named symbol `need_copy` in app/web/main.py:226"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c282ee1cabbcbb3", "name": "Commented-code block (7 lines) in app/web/main.py:216", "shortDescription": {"text": "Commented-code block (7 lines) in app/web/main.py:216"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d36901291712a932", "name": "Network/subprocess call without timeout or try/except \u2014 app/web/main.py:4007", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 app/web/main.py:4007"}, "fullDescription": {"text": "`subprocess.Popen(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9702ecc4dcd1d46", "name": "Commented-code block (5 lines) in app/market/prices.py:17", "shortDescription": {"text": "Commented-code block (5 lines) in app/market/prices.py:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f42c96f3e622dc52", "name": "Commented-code block (5 lines) in app/db/database.py:35", "shortDescription": {"text": "Commented-code block (5 lines) in app/db/database.py:35"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9238fa5fe2d5e36c", "name": "Legacy-named symbol `is_blueprint_copy` in app/character/assets.py:24", "shortDescription": {"text": "Legacy-named symbol `is_blueprint_copy` in app/character/assets.py:24"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\napp/web/industry_helper.py:get_station_me_bonus_pct, app/web/industry_helper.py:get_station_me_bonus\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\napp/character/skills.py:fetch_skills, app/character/assets.py:fetch_assets, app/character/assets.py:fetch_corp_assets, app/character/blueprints.py:fetch_blueprints\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c3966e020c9c549", "name": "FastAPI POST `auth_cancel` without auth dependency \u2014 app/web/main.py:845", "shortDescription": {"text": "FastAPI POST `auth_cancel` without auth dependency \u2014 app/web/main.py:845"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-edca3e780b3c974a", "name": "FastAPI POST `api_activate_character` without auth dependency \u2014 app/web/main.py:950", "shortDescription": {"text": "FastAPI POST `api_activate_character` without auth dependency \u2014 app/web/main.py:950"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f236721802f932e1", "name": "FastAPI DELETE `api_delete_character` without auth dependency \u2014 app/web/main.py:965", "shortDescription": {"text": "FastAPI DELETE `api_delete_character` without auth dependency \u2014 app/web/main.py:965"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5967654909f70ff0", "name": "FastAPI POST `api_sync_start` without auth dependency \u2014 app/web/main.py:980", "shortDescription": {"text": "FastAPI POST `api_sync_start` without auth dependency \u2014 app/web/main.py:980"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b254f7b6da6c4bc", "name": "FastAPI POST `api_save_client_id` without auth dependency \u2014 app/web/main.py:1002", "shortDescription": {"text": "FastAPI POST `api_save_client_id` without auth dependency \u2014 app/web/main.py:1002"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-776436fabe9e8c3a", "name": "FastAPI POST `plan_result` without auth dependency \u2014 app/web/main.py:1224", "shortDescription": {"text": "FastAPI POST `plan_result` without auth dependency \u2014 app/web/main.py:1224"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c77b5f91eb47241", "name": "FastAPI POST `save_station_rigs` without auth dependency \u2014 app/web/main.py:2961", "shortDescription": {"text": "FastAPI POST `save_station_rigs` without auth dependency \u2014 app/web/main.py:2961"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ccc36a1b40df7852", "name": "FastAPI POST `add_station` without auth dependency \u2014 app/web/main.py:3146", "shortDescription": {"text": "FastAPI POST `add_station` without auth dependency \u2014 app/web/main.py:3146"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-507ed074c1308033", "name": "FastAPI POST `location_rename` without auth dependency \u2014 app/web/main.py:3214", "shortDescription": {"text": "FastAPI POST `location_rename` without auth dependency \u2014 app/web/main.py:3214"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a2d699cf4df6d6e8", "name": "FastAPI POST `api_project_new` without auth dependency \u2014 app/web/main.py:3397", "shortDescription": {"text": "FastAPI POST `api_project_new` without auth dependency \u2014 app/web/main.py:3397"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f0594d73eca2da17", "name": "FastAPI POST `api_project_add_plan` without auth dependency \u2014 app/web/main.py:3409", "shortDescription": {"text": "FastAPI POST `api_project_add_plan` without auth dependency \u2014 app/web/main.py:3409"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2d20529dcff50222", "name": "FastAPI POST `api_project_job_toggle` without auth dependency \u2014 app/web/main.py:3431", "shortDescription": {"text": "FastAPI POST `api_project_job_toggle` without auth dependency \u2014 app/web/main.py:3431"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4e80da781536a14", "name": "FastAPI POST `api_project_shopping_update` without auth dependency \u2014 app/web/main.py:3450", "shortDescription": {"text": "FastAPI POST `api_project_shopping_update` without auth dependency \u2014 app/web/main.py:3450"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-16b8606718d1ce66", "name": "FastAPI POST `api_project_shopping_mark_all` without auth dependency \u2014 app/web/main.py:3468", "shortDescription": {"text": "FastAPI POST `api_project_shopping_mark_all` without auth dependency \u2014 app/web/main.py:3468"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c29b613444671d5", "name": "FastAPI POST `api_project_plan_toggle` without auth dependency \u2014 app/web/main.py:3479", "shortDescription": {"text": "FastAPI POST `api_project_plan_toggle` without auth dependency \u2014 app/web/main.py:3479"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ec485018a158f57", "name": "FastAPI DELETE `api_project_delete` without auth dependency \u2014 app/web/main.py:3490", "shortDescription": {"text": "FastAPI DELETE `api_project_delete` without auth dependency \u2014 app/web/main.py:3490"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-893739028eee48ac", "name": "FastAPI POST `prices_refresh` without auth dependency \u2014 app/web/main.py:3623", "shortDescription": {"text": "FastAPI POST `prices_refresh` without auth dependency \u2014 app/web/main.py:3623"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7f42574bb4aa63d2", "name": "FastAPI POST `api_set_custom_price` without auth dependency \u2014 app/web/main.py:3778", "shortDescription": {"text": "FastAPI POST `api_set_custom_price` without auth dependency \u2014 app/web/main.py:3778"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0269863d19df6770", "name": "FastAPI POST `api_station_volume` without auth dependency \u2014 app/web/main.py:3790", "shortDescription": {"text": "FastAPI POST `api_station_volume` without auth dependency \u2014 app/web/main.py:3790"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-485613367e12bbd9", "name": "FastAPI POST `api_version_apply` without auth dependency \u2014 app/web/main.py:3995", "shortDescription": {"text": "FastAPI POST `api_version_apply` without auth dependency \u2014 app/web/main.py:3995"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d86afd7dd2beb431", "name": "Unused endpoint: GET /setup", "shortDescription": {"text": "Unused endpoint: GET /setup"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /setup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b11708281ac6830", "name": "Unused endpoint: GET /setup/download", "shortDescription": {"text": "Unused endpoint: GET /setup/download"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /setup/download` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76fe223a158845f6", "name": "Unused endpoint: GET /auth/login", "shortDescription": {"text": "Unused endpoint: GET /auth/login"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /auth/login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07c41e97767b4cd7", "name": "Unused endpoint: POST /auth/cancel", "shortDescription": {"text": "Unused endpoint: POST /auth/cancel"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /auth/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-562322a28c342d7f", "name": "Unused endpoint: GET /api/auth/status", "shortDescription": {"text": "Unused endpoint: GET /api/auth/status"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/auth/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c36af3a806b0b571", "name": "Unused endpoint: GET /auth/sync", "shortDescription": {"text": "Unused endpoint: GET /auth/sync"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /auth/sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8f3e64c11458579", "name": "Unused endpoint: GET /api/sync-status", "shortDescription": {"text": "Unused endpoint: GET /api/sync-status"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/sync-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77d77cea82433aee", "name": "Unused endpoint: POST /api/characters/{char_id}/activate", "shortDescription": {"text": "Unused endpoint: POST /api/characters/{char_id}/activate"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/characters/{char_id}/activate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff4a06a85471fb6f", "name": "Unused endpoint: DELETE /api/characters/{char_id}", "shortDescription": {"text": "Unused endpoint: DELETE /api/characters/{char_id}"}, "fullDescription": {"text": "`app/web/main.py` declares `DELETE /api/characters/{char_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0e7f2a2d32dd606", "name": "Unused endpoint: POST /api/sync/start", "shortDescription": {"text": "Unused endpoint: POST /api/sync/start"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/sync/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-512ccb0fd0b230ba", "name": "Unused endpoint: GET /settings", "shortDescription": {"text": "Unused endpoint: GET /settings"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc2c96104581d422", "name": "Unused endpoint: POST /api/settings/client-id", "shortDescription": {"text": "Unused endpoint: POST /api/settings/client-id"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/settings/client-id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0208f01be6b37c7e", "name": "Unused endpoint: GET /plan", "shortDescription": {"text": "Unused endpoint: GET /plan"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c35bdeabdbc78d85", "name": "Unused endpoint: POST /plan", "shortDescription": {"text": "Unused endpoint: POST /plan"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68c058e796a5439f", "name": "Unused endpoint: GET /assets", "shortDescription": {"text": "Unused endpoint: GET /assets"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /assets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1cfff18dcfbb8063", "name": "Unused endpoint: GET /api/assets/distances", "shortDescription": {"text": "Unused endpoint: GET /api/assets/distances"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/assets/distances` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e21df095acd1930", "name": "Unused endpoint: GET /blueprints", "shortDescription": {"text": "Unused endpoint: GET /blueprints"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /blueprints` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e2631495c43f2a81", "name": "Unused endpoint: GET /prices", "shortDescription": {"text": "Unused endpoint: GET /prices"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /prices` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e87c3aacc61282e0", "name": "Unused endpoint: GET /api/station-industry-info", "shortDescription": {"text": "Unused endpoint: GET /api/station-industry-info"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/station-industry-info` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-80bb82e232ab6982", "name": "Unused endpoint: POST /api/station-rigs", "shortDescription": {"text": "Unused endpoint: POST /api/station-rigs"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/station-rigs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ecb7be3cbff5e5a", "name": "Unused endpoint: GET /api/rig-types", "shortDescription": {"text": "Unused endpoint: GET /api/rig-types"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/rig-types` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb62e5ed917a068e", "name": "Unused endpoint: GET /api/suggest-station", "shortDescription": {"text": "Unused endpoint: GET /api/suggest-station"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/suggest-station` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03644bdd8c832fa6", "name": "Unused endpoint: POST /api/add-station", "shortDescription": {"text": "Unused endpoint: POST /api/add-station"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/add-station` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63428dd4d50d9266", "name": "Unused endpoint: POST /api/location/rename", "shortDescription": {"text": "Unused endpoint: POST /api/location/rename"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/location/rename` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0180fe16b060f478", "name": "Unused endpoint: GET /api/location/resolve", "shortDescription": {"text": "Unused endpoint: GET /api/location/resolve"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/location/resolve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a5fc1e09aeefa5a", "name": "Unused endpoint: GET /api/my-location", "shortDescription": {"text": "Unused endpoint: GET /api/my-location"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/my-location` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-177a826c297af42c", "name": "Unused endpoint: GET /api/plan/fetch-sell-price", "shortDescription": {"text": "Unused endpoint: GET /api/plan/fetch-sell-price"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/plan/fetch-sell-price` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1e1ee09590b0a49", "name": "Unused endpoint: GET /projects", "shortDescription": {"text": "Unused endpoint: GET /projects"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8276e9a42f5cb13a", "name": "Unused endpoint: GET /projects/{project_id}", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /projects/{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69d6e23c1dd18bf1", "name": "Unused endpoint: GET /api/projects/list", "shortDescription": {"text": "Unused endpoint: GET /api/projects/list"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/projects/list` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b788bcc11a9b8b85", "name": "Unused endpoint: POST /api/projects/new", "shortDescription": {"text": "Unused endpoint: POST /api/projects/new"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/projects/new` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8a576e725a46978", "name": "Unused endpoint: POST /api/projects/{project_id}/add-plan", "shortDescription": {"text": "Unused endpoint: POST /api/projects/{project_id}/add-plan"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/projects/{project_id}/add-plan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0d6faf006199e3c", "name": "Unused endpoint: POST /api/project-jobs/toggle", "shortDescription": {"text": "Unused endpoint: POST /api/project-jobs/toggle"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/project-jobs/toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30fe033e974ee329", "name": "Unused endpoint: POST /api/project-shopping/update", "shortDescription": {"text": "Unused endpoint: POST /api/project-shopping/update"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/project-shopping/update` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-609eb01c169ece49", "name": "Unused endpoint: POST /api/projects/{project_id}/shopping/mark-all", "shortDescription": {"text": "Unused endpoint: POST /api/projects/{project_id}/shopping/mark-all"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/projects/{project_id}/shopping/mark-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9740338e58c1ad27", "name": "Unused endpoint: POST /api/project-plans/{plan_id}/toggle", "shortDescription": {"text": "Unused endpoint: POST /api/project-plans/{plan_id}/toggle"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/project-plans/{plan_id}/toggle` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-910e7327fca49aff", "name": "Unused endpoint: DELETE /api/projects/{project_id}", "shortDescription": {"text": "Unused endpoint: DELETE /api/projects/{project_id}"}, "fullDescription": {"text": "`app/web/main.py` declares `DELETE /api/projects/{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60c31a6f721cf327", "name": "Unused endpoint: GET /api/suggest", "shortDescription": {"text": "Unused endpoint: GET /api/suggest"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/suggest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-186eae429c9925a3", "name": "Unused endpoint: POST /prices/refresh", "shortDescription": {"text": "Unused endpoint: POST /prices/refresh"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /prices/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1fa89eea071a1d2", "name": "Unused endpoint: GET /prices/refresh/stream", "shortDescription": {"text": "Unused endpoint: GET /prices/refresh/stream"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /prices/refresh/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7ac6ebb033da529", "name": "Unused endpoint: GET /api/prices/search", "shortDescription": {"text": "Unused endpoint: GET /api/prices/search"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/prices/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-381b54bf8def0a29", "name": "Unused endpoint: POST /api/prices/custom", "shortDescription": {"text": "Unused endpoint: POST /api/prices/custom"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/prices/custom` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa9c181ec5e7a2a6", "name": "Unused endpoint: POST /api/prices/station-volume", "shortDescription": {"text": "Unused endpoint: POST /api/prices/station-volume"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/prices/station-volume` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fff7d7c74ad81e4", "name": "Unused endpoint: GET /about", "shortDescription": {"text": "Unused endpoint: GET /about"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /about` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d9dedce65b545b08", "name": "Unused endpoint: GET /api/version/check", "shortDescription": {"text": "Unused endpoint: GET /api/version/check"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/version/check` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3dc6ca210267423", "name": "Unused endpoint: GET /api/version/download", "shortDescription": {"text": "Unused endpoint: GET /api/version/download"}, "fullDescription": {"text": "`app/web/main.py` declares `GET /api/version/download` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4eacc342a7420288", "name": "Unused endpoint: POST /api/version/apply", "shortDescription": {"text": "Unused endpoint: POST /api/version/apply"}, "fullDescription": {"text": "`app/web/main.py` declares `POST /api/version/apply` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19074"}, "properties": {"repository": "ScoopEMPRetro/Eve-retroindustry", "repoUrl": "https://github.com/ScoopEMPRetro/Eve-retroindustry", "branch": "main"}, "results": [{"ruleId": "scanner-1e9f81140232c568", "level": "note", "message": {"text": "Possibly dead Python function: do_GET"}, "properties": {"repobilityId": "2d943bb45e4f13bd", "scanner": "scanner-primary", "fingerprint": "1e9f81140232c568", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/auth/esi_oauth.py:109"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-43cfe345e51f3fba", "level": "note", "message": {"text": "Possibly dead Python function: log_message"}, "properties": {"repobilityId": "965f3150b4af5b2e", "scanner": "scanner-primary", "fingerprint": "43cfe345e51f3fba", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/auth/esi_oauth.py:154"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-35bd43557d9bc746", "level": "note", "message": {"text": "Possibly dead Python function: resolve_blueprint"}, "properties": {"repobilityId": "e589f40e407dd237", "scanner": "scanner-primary", "fingerprint": "35bd43557d9bc746", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/cache/blueprint_cache.py:64"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ef29551256e07032", "level": "note", "message": {"text": "Possibly dead Python function: fetch_types_bulk"}, "properties": {"repobilityId": "349d977d84b77ad4", "scanner": "scanner-primary", "fingerprint": "ef29551256e07032", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/esi/client.py:62"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76fe029101c3b74b", "level": "note", "message": {"text": "Possibly dead Python function: save_station_me_bonus"}, "properties": {"repobilityId": "d7144f11b3261ba6", "scanner": "scanner-primary", "fingerprint": "76fe029101c3b74b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/industry_helper.py:639"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-492ccc02da8dae3d", "level": "note", "message": {"text": "Possibly dead Python function: assets_at_locations"}, "properties": {"repobilityId": "a3f53990e662bba6", "scanner": "scanner-primary", "fingerprint": "492ccc02da8dae3d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/character/assets.py:200"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a14dee99f28fe46f", "level": "note", "message": {"text": "Very large file: app/web/main.py (4015 lines)"}, "properties": {"repobilityId": "9c0a580c3ab5ccd2", "scanner": "scanner-primary", "fingerprint": "a14dee99f28fe46f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "d0409797c796ba47", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "62d23f19f7d4c74a", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "d8a399eb6f097cde", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "4b9c4421c2bf9ac0", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "46f84df7fcff62bb", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d7f4f907fdef23f", "level": "none", "message": {"text": "Commented-code block (6 lines) in launcher.py:136"}, "properties": {"repobilityId": "e4866aaa3c5bc4a4", "scanner": "scanner-primary", "fingerprint": "2d7f4f907fdef23f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-815785dc02d0e7fd", "level": "none", "message": {"text": "Commented-code block (6 lines) in app/bom/resolver.py:78"}, "properties": {"repobilityId": "ceaa9a78fb3c54aa", "scanner": "scanner-primary", "fingerprint": "815785dc02d0e7fd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a7e4ae5f4bcd265e", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/web/industry_helper.py:146"}, "properties": {"repobilityId": "4aed5871a4781a52", "scanner": "scanner-primary", "fingerprint": "a7e4ae5f4bcd265e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-419443bf968f94cb", "level": "note", "message": {"text": "Legacy-named symbol `need_copy` in app/web/main.py:226"}, "properties": {"repobilityId": "a10a5a53aaba9631", "scanner": "scanner-primary", "fingerprint": "419443bf968f94cb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1c282ee1cabbcbb3", "level": "none", "message": {"text": "Commented-code block (7 lines) in app/web/main.py:216"}, "properties": {"repobilityId": "ec15bfa328b01cfb", "scanner": "scanner-primary", "fingerprint": "1c282ee1cabbcbb3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d36901291712a932", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 app/web/main.py:4007"}, "properties": {"repobilityId": "54a63f2c217f935d", "scanner": "scanner-primary", "fingerprint": "d36901291712a932", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c9702ecc4dcd1d46", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/market/prices.py:17"}, "properties": {"repobilityId": "a3a11a9301e982f9", "scanner": "scanner-primary", "fingerprint": "c9702ecc4dcd1d46", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f42c96f3e622dc52", "level": "none", "message": {"text": "Commented-code block (5 lines) in app/db/database.py:35"}, "properties": {"repobilityId": "6d79ee43524cd47c", "scanner": "scanner-primary", "fingerprint": "f42c96f3e622dc52", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9238fa5fe2d5e36c", "level": "note", "message": {"text": "Legacy-named symbol `is_blueprint_copy` in app/character/assets.py:24"}, "properties": {"repobilityId": "f84fd74387915312", "scanner": "scanner-primary", "fingerprint": "9238fa5fe2d5e36c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "2d5f0eb1d54de9a7", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "953e4300aedfd2fc", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "1c77a787834bebbe", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "7cda00e01ee6ef9b", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "c5d50a8b70ded46c", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-6c3966e020c9c549", "level": "error", "message": {"text": "FastAPI POST `auth_cancel` without auth dependency \u2014 app/web/main.py:845"}, "properties": {"repobilityId": "651f4dd05846e836", "scanner": "scanner-primary", "fingerprint": "6c3966e020c9c549", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 845}}}]}, {"ruleId": "scanner-edca3e780b3c974a", "level": "error", "message": {"text": "FastAPI POST `api_activate_character` without auth dependency \u2014 app/web/main.py:950"}, "properties": {"repobilityId": "c38b9fe9b9660fb1", "scanner": "scanner-primary", "fingerprint": "edca3e780b3c974a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 950}}}]}, {"ruleId": "scanner-f236721802f932e1", "level": "error", "message": {"text": "FastAPI DELETE `api_delete_character` without auth dependency \u2014 app/web/main.py:965"}, "properties": {"repobilityId": "5d3f4d4bef45ce11", "scanner": "scanner-primary", "fingerprint": "f236721802f932e1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 965}}}]}, {"ruleId": "scanner-5967654909f70ff0", "level": "error", "message": {"text": "FastAPI POST `api_sync_start` without auth dependency \u2014 app/web/main.py:980"}, "properties": {"repobilityId": "81a57e1725a86a02", "scanner": "scanner-primary", "fingerprint": "5967654909f70ff0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 980}}}]}, {"ruleId": "scanner-3b254f7b6da6c4bc", "level": "error", "message": {"text": "FastAPI POST `api_save_client_id` without auth dependency \u2014 app/web/main.py:1002"}, "properties": {"repobilityId": "b85d416743cc9a34", "scanner": "scanner-primary", "fingerprint": "3b254f7b6da6c4bc", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 1002}}}]}, {"ruleId": "scanner-776436fabe9e8c3a", "level": "error", "message": {"text": "FastAPI POST `plan_result` without auth dependency \u2014 app/web/main.py:1224"}, "properties": {"repobilityId": "6fd20b4326aae406", "scanner": "scanner-primary", "fingerprint": "776436fabe9e8c3a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 1224}}}]}, {"ruleId": "scanner-3c77b5f91eb47241", "level": "error", "message": {"text": "FastAPI POST `save_station_rigs` without auth dependency \u2014 app/web/main.py:2961"}, "properties": {"repobilityId": "d7ed26a22dde4977", "scanner": "scanner-primary", "fingerprint": "3c77b5f91eb47241", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 2961}}}]}, {"ruleId": "scanner-ccc36a1b40df7852", "level": "error", "message": {"text": "FastAPI POST `add_station` without auth dependency \u2014 app/web/main.py:3146"}, "properties": {"repobilityId": "6f9778c327391251", "scanner": "scanner-primary", "fingerprint": "ccc36a1b40df7852", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3146}}}]}, {"ruleId": "scanner-507ed074c1308033", "level": "error", "message": {"text": "FastAPI POST `location_rename` without auth dependency \u2014 app/web/main.py:3214"}, "properties": {"repobilityId": "33ba3e4ce0ff350d", "scanner": "scanner-primary", "fingerprint": "507ed074c1308033", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3214}}}]}, {"ruleId": "scanner-a2d699cf4df6d6e8", "level": "error", "message": {"text": "FastAPI POST `api_project_new` without auth dependency \u2014 app/web/main.py:3397"}, "properties": {"repobilityId": "9e311d9438e4e346", "scanner": "scanner-primary", "fingerprint": "a2d699cf4df6d6e8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3397}}}]}, {"ruleId": "scanner-f0594d73eca2da17", "level": "error", "message": {"text": "FastAPI POST `api_project_add_plan` without auth dependency \u2014 app/web/main.py:3409"}, "properties": {"repobilityId": "19f78edbad1b5a0e", "scanner": "scanner-primary", "fingerprint": "f0594d73eca2da17", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3409}}}]}, {"ruleId": "scanner-2d20529dcff50222", "level": "error", "message": {"text": "FastAPI POST `api_project_job_toggle` without auth dependency \u2014 app/web/main.py:3431"}, "properties": {"repobilityId": "446c620b7181d462", "scanner": "scanner-primary", "fingerprint": "2d20529dcff50222", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3431}}}]}, {"ruleId": "scanner-e4e80da781536a14", "level": "error", "message": {"text": "FastAPI POST `api_project_shopping_update` without auth dependency \u2014 app/web/main.py:3450"}, "properties": {"repobilityId": "da1afbbe1a6bddf0", "scanner": "scanner-primary", "fingerprint": "e4e80da781536a14", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3450}}}]}, {"ruleId": "scanner-16b8606718d1ce66", "level": "error", "message": {"text": "FastAPI POST `api_project_shopping_mark_all` without auth dependency \u2014 app/web/main.py:3468"}, "properties": {"repobilityId": "bdd4f7dc5c145bb4", "scanner": "scanner-primary", "fingerprint": "16b8606718d1ce66", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3468}}}]}, {"ruleId": "scanner-9c29b613444671d5", "level": "error", "message": {"text": "FastAPI POST `api_project_plan_toggle` without auth dependency \u2014 app/web/main.py:3479"}, "properties": {"repobilityId": "53479a49d9246855", "scanner": "scanner-primary", "fingerprint": "9c29b613444671d5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3479}}}]}, {"ruleId": "scanner-7ec485018a158f57", "level": "error", "message": {"text": "FastAPI DELETE `api_project_delete` without auth dependency \u2014 app/web/main.py:3490"}, "properties": {"repobilityId": "db9385c7057b8026", "scanner": "scanner-primary", "fingerprint": "7ec485018a158f57", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3490}}}]}, {"ruleId": "scanner-893739028eee48ac", "level": "error", "message": {"text": "FastAPI POST `prices_refresh` without auth dependency \u2014 app/web/main.py:3623"}, "properties": {"repobilityId": "a24b9687c06bb7b0", "scanner": "scanner-primary", "fingerprint": "893739028eee48ac", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3623}}}]}, {"ruleId": "scanner-7f42574bb4aa63d2", "level": "error", "message": {"text": "FastAPI POST `api_set_custom_price` without auth dependency \u2014 app/web/main.py:3778"}, "properties": {"repobilityId": "5fb39a1fa3c20adf", "scanner": "scanner-primary", "fingerprint": "7f42574bb4aa63d2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3778}}}]}, {"ruleId": "scanner-0269863d19df6770", "level": "error", "message": {"text": "FastAPI POST `api_station_volume` without auth dependency \u2014 app/web/main.py:3790"}, "properties": {"repobilityId": "072f6f8e93cac33b", "scanner": "scanner-primary", "fingerprint": "0269863d19df6770", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3790}}}]}, {"ruleId": "scanner-485613367e12bbd9", "level": "error", "message": {"text": "FastAPI POST `api_version_apply` without auth dependency \u2014 app/web/main.py:3995"}, "properties": {"repobilityId": "eba32111d437edc5", "scanner": "scanner-primary", "fingerprint": "485613367e12bbd9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "app/web/main.py"}, "region": {"startLine": 3995}}}]}, {"ruleId": "scanner-d86afd7dd2beb431", "level": "note", "message": {"text": "Unused endpoint: GET /setup"}, "properties": {"repobilityId": "d72492d27679e448", "scanner": "scanner-primary", "fingerprint": "d86afd7dd2beb431", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4b11708281ac6830", "level": "note", "message": {"text": "Unused endpoint: GET /setup/download"}, "properties": {"repobilityId": "d095c840c67ac71b", "scanner": "scanner-primary", "fingerprint": "4b11708281ac6830", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-76fe223a158845f6", "level": "note", "message": {"text": "Unused endpoint: GET /auth/login"}, "properties": {"repobilityId": "6146a8f232019205", "scanner": "scanner-primary", "fingerprint": "76fe223a158845f6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07c41e97767b4cd7", "level": "note", "message": {"text": "Unused endpoint: POST /auth/cancel"}, "properties": {"repobilityId": "3e2db35eded2b826", "scanner": "scanner-primary", "fingerprint": "07c41e97767b4cd7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-562322a28c342d7f", "level": "note", "message": {"text": "Unused endpoint: GET /api/auth/status"}, "properties": {"repobilityId": "07a27622799dcf75", "scanner": "scanner-primary", "fingerprint": "562322a28c342d7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c36af3a806b0b571", "level": "note", "message": {"text": "Unused endpoint: GET /auth/sync"}, "properties": {"repobilityId": "eaaec43392d2e639", "scanner": "scanner-primary", "fingerprint": "c36af3a806b0b571", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8f3e64c11458579", "level": "note", "message": {"text": "Unused endpoint: GET /api/sync-status"}, "properties": {"repobilityId": "9233ff2990957d0c", "scanner": "scanner-primary", "fingerprint": "f8f3e64c11458579", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77d77cea82433aee", "level": "note", "message": {"text": "Unused endpoint: POST /api/characters/{char_id}/activate"}, "properties": {"repobilityId": "5f7a9d12730dfd94", "scanner": "scanner-primary", "fingerprint": "77d77cea82433aee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff4a06a85471fb6f", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/characters/{char_id}"}, "properties": {"repobilityId": "d00eb2f2bb5824b4", "scanner": "scanner-primary", "fingerprint": "ff4a06a85471fb6f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0e7f2a2d32dd606", "level": "note", "message": {"text": "Unused endpoint: POST /api/sync/start"}, "properties": {"repobilityId": "fca1f064cf065ddc", "scanner": "scanner-primary", "fingerprint": "a0e7f2a2d32dd606", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-512ccb0fd0b230ba", "level": "note", "message": {"text": "Unused endpoint: GET /settings"}, "properties": {"repobilityId": "e672f32a10c56d41", "scanner": "scanner-primary", "fingerprint": "512ccb0fd0b230ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dc2c96104581d422", "level": "note", "message": {"text": "Unused endpoint: POST /api/settings/client-id"}, "properties": {"repobilityId": "e315bd6e4f3f1216", "scanner": "scanner-primary", "fingerprint": "dc2c96104581d422", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "640282befed3ec9e", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0208f01be6b37c7e", "level": "note", "message": {"text": "Unused endpoint: GET /plan"}, "properties": {"repobilityId": "c562b51e9801e1d2", "scanner": "scanner-primary", "fingerprint": "0208f01be6b37c7e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c35bdeabdbc78d85", "level": "note", "message": {"text": "Unused endpoint: POST /plan"}, "properties": {"repobilityId": "b3cbf057964be81f", "scanner": "scanner-primary", "fingerprint": "c35bdeabdbc78d85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-68c058e796a5439f", "level": "note", "message": {"text": "Unused endpoint: GET /assets"}, "properties": {"repobilityId": "f9a21fa5985a8743", "scanner": "scanner-primary", "fingerprint": "68c058e796a5439f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1cfff18dcfbb8063", "level": "note", "message": {"text": "Unused endpoint: GET /api/assets/distances"}, "properties": {"repobilityId": "c0091ff35aa49ab2", "scanner": "scanner-primary", "fingerprint": "1cfff18dcfbb8063", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1e21df095acd1930", "level": "note", "message": {"text": "Unused endpoint: GET /blueprints"}, "properties": {"repobilityId": "a6fdfa2c26b3b24b", "scanner": "scanner-primary", "fingerprint": "1e21df095acd1930", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e2631495c43f2a81", "level": "note", "message": {"text": "Unused endpoint: GET /prices"}, "properties": {"repobilityId": "c302f47890457164", "scanner": "scanner-primary", "fingerprint": "e2631495c43f2a81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e87c3aacc61282e0", "level": "note", "message": {"text": "Unused endpoint: GET /api/station-industry-info"}, "properties": {"repobilityId": "030d0ba932ceb159", "scanner": "scanner-primary", "fingerprint": "e87c3aacc61282e0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-80bb82e232ab6982", "level": "note", "message": {"text": "Unused endpoint: POST /api/station-rigs"}, "properties": {"repobilityId": "fe583f6c5a6341a1", "scanner": "scanner-primary", "fingerprint": "80bb82e232ab6982", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ecb7be3cbff5e5a", "level": "note", "message": {"text": "Unused endpoint: GET /api/rig-types"}, "properties": {"repobilityId": "84e549d8b462beed", "scanner": "scanner-primary", "fingerprint": "7ecb7be3cbff5e5a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cb62e5ed917a068e", "level": "note", "message": {"text": "Unused endpoint: GET /api/suggest-station"}, "properties": {"repobilityId": "41d45450773f5df5", "scanner": "scanner-primary", "fingerprint": "cb62e5ed917a068e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-03644bdd8c832fa6", "level": "note", "message": {"text": "Unused endpoint: POST /api/add-station"}, "properties": {"repobilityId": "83520734ddaf56f6", "scanner": "scanner-primary", "fingerprint": "03644bdd8c832fa6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-63428dd4d50d9266", "level": "note", "message": {"text": "Unused endpoint: POST /api/location/rename"}, "properties": {"repobilityId": "a26e9115120a35b9", "scanner": "scanner-primary", "fingerprint": "63428dd4d50d9266", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0180fe16b060f478", "level": "note", "message": {"text": "Unused endpoint: GET /api/location/resolve"}, "properties": {"repobilityId": "412e9c0635980a84", "scanner": "scanner-primary", "fingerprint": "0180fe16b060f478", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3a5fc1e09aeefa5a", "level": "note", "message": {"text": "Unused endpoint: GET /api/my-location"}, "properties": {"repobilityId": "5d6f6c993b098c22", "scanner": "scanner-primary", "fingerprint": "3a5fc1e09aeefa5a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-177a826c297af42c", "level": "note", "message": {"text": "Unused endpoint: GET /api/plan/fetch-sell-price"}, "properties": {"repobilityId": "91983c9aa5a015a3", "scanner": "scanner-primary", "fingerprint": "177a826c297af42c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1e1ee09590b0a49", "level": "note", "message": {"text": "Unused endpoint: GET /projects"}, "properties": {"repobilityId": "251d115350f94b7f", "scanner": "scanner-primary", "fingerprint": "c1e1ee09590b0a49", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8276e9a42f5cb13a", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}"}, "properties": {"repobilityId": "df0f0256a04469f4", "scanner": "scanner-primary", "fingerprint": "8276e9a42f5cb13a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-69d6e23c1dd18bf1", "level": "note", "message": {"text": "Unused endpoint: GET /api/projects/list"}, "properties": {"repobilityId": "325f98680c4ce582", "scanner": "scanner-primary", "fingerprint": "69d6e23c1dd18bf1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b788bcc11a9b8b85", "level": "note", "message": {"text": "Unused endpoint: POST /api/projects/new"}, "properties": {"repobilityId": "46d67e577eb08728", "scanner": "scanner-primary", "fingerprint": "b788bcc11a9b8b85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8a576e725a46978", "level": "note", "message": {"text": "Unused endpoint: POST /api/projects/{project_id}/add-plan"}, "properties": {"repobilityId": "f8ab8d332db6f146", "scanner": "scanner-primary", "fingerprint": "b8a576e725a46978", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0d6faf006199e3c", "level": "note", "message": {"text": "Unused endpoint: POST /api/project-jobs/toggle"}, "properties": {"repobilityId": "b68e9cffe9cb85c4", "scanner": "scanner-primary", "fingerprint": "a0d6faf006199e3c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-30fe033e974ee329", "level": "note", "message": {"text": "Unused endpoint: POST /api/project-shopping/update"}, "properties": {"repobilityId": "0d3a2581297dc78b", "scanner": "scanner-primary", "fingerprint": "30fe033e974ee329", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-609eb01c169ece49", "level": "note", "message": {"text": "Unused endpoint: POST /api/projects/{project_id}/shopping/mark-all"}, "properties": {"repobilityId": "f0ae372a14aeb408", "scanner": "scanner-primary", "fingerprint": "609eb01c169ece49", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9740338e58c1ad27", "level": "note", "message": {"text": "Unused endpoint: POST /api/project-plans/{plan_id}/toggle"}, "properties": {"repobilityId": "de044307769deaa3", "scanner": "scanner-primary", "fingerprint": "9740338e58c1ad27", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-910e7327fca49aff", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/projects/{project_id}"}, "properties": {"repobilityId": "3a865b2453b515b5", "scanner": "scanner-primary", "fingerprint": "910e7327fca49aff", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60c31a6f721cf327", "level": "note", "message": {"text": "Unused endpoint: GET /api/suggest"}, "properties": {"repobilityId": "e6abafb531d89fa9", "scanner": "scanner-primary", "fingerprint": "60c31a6f721cf327", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-186eae429c9925a3", "level": "note", "message": {"text": "Unused endpoint: POST /prices/refresh"}, "properties": {"repobilityId": "e06f51cbb76f52e8", "scanner": "scanner-primary", "fingerprint": "186eae429c9925a3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1fa89eea071a1d2", "level": "note", "message": {"text": "Unused endpoint: GET /prices/refresh/stream"}, "properties": {"repobilityId": "d4ccc6e70bd5a6cc", "scanner": "scanner-primary", "fingerprint": "e1fa89eea071a1d2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b7ac6ebb033da529", "level": "note", "message": {"text": "Unused endpoint: GET /api/prices/search"}, "properties": {"repobilityId": "65a304638d6d47c9", "scanner": "scanner-primary", "fingerprint": "b7ac6ebb033da529", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-381b54bf8def0a29", "level": "note", "message": {"text": "Unused endpoint: POST /api/prices/custom"}, "properties": {"repobilityId": "410aba98d8523ef0", "scanner": "scanner-primary", "fingerprint": "381b54bf8def0a29", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aa9c181ec5e7a2a6", "level": "note", "message": {"text": "Unused endpoint: POST /api/prices/station-volume"}, "properties": {"repobilityId": "e13354d51e3fa8a3", "scanner": "scanner-primary", "fingerprint": "aa9c181ec5e7a2a6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5fff7d7c74ad81e4", "level": "note", "message": {"text": "Unused endpoint: GET /about"}, "properties": {"repobilityId": "97ea046caf606dcb", "scanner": "scanner-primary", "fingerprint": "5fff7d7c74ad81e4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d9dedce65b545b08", "level": "note", "message": {"text": "Unused endpoint: GET /api/version/check"}, "properties": {"repobilityId": "de2f64a957bd3130", "scanner": "scanner-primary", "fingerprint": "d9dedce65b545b08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f3dc6ca210267423", "level": "note", "message": {"text": "Unused endpoint: GET /api/version/download"}, "properties": {"repobilityId": "33dff30d30d94aa2", "scanner": "scanner-primary", "fingerprint": "f3dc6ca210267423", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4eacc342a7420288", "level": "note", "message": {"text": "Unused endpoint: POST /api/version/apply"}, "properties": {"repobilityId": "6180e3239bb7107d", "scanner": "scanner-primary", "fingerprint": "4eacc342a7420288", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}