{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-08f9ddfd93cf002f", "name": "Stray `console.log` in TS/JS \u2014 QuickronsApp/App.js:189", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 QuickronsApp/App.js:189"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c07c7292349a50a", "name": "Stray `console.log` in TS/JS \u2014 QuickronsApp/src/state/AuthContext.js:45", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 QuickronsApp/src/state/AuthContext.js:45"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-727cf94ba730d3f1", "name": "Stray `console.log` in TS/JS \u2014 QuickronsApp/src/lib/socket.js:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 QuickronsApp/src/lib/socket.js:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e2e51de8d368448", "name": "Stray `console.log` in TS/JS \u2014 backend/scripts/qa-launch-blockers.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/scripts/qa-launch-blockers.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-915ebed951d6d819", "name": "Stray `console.log` in TS/JS \u2014 backend/prisma/backfill-images.js:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/prisma/backfill-images.js:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f4e3be9bd025f419", "name": "Stray `console.log` in TS/JS \u2014 backend/prisma/seed.js:386", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/prisma/seed.js:386"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2a15e3555a7f5c4", "name": "Stray `console.log` in TS/JS \u2014 backend/src/socket.js:53", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/socket.js:53"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5bf5295436d4dce", "name": "Stray `console.log` in TS/JS \u2014 backend/src/index.js:69", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/index.js:69"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66dd4aeca573df98", "name": "Stray `console.log` in TS/JS \u2014 backend/src/lib/upload.js:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/lib/upload.js:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92c27aa07ddc2395", "name": "TODO/FIXME marker in shipping code \u2014 backend/src/routes/auth.js:156", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 backend/src/routes/auth.js:156"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dc72d196d56254a6", "name": "Stray `console.log` in TS/JS \u2014 backend/src/routes/auth.js:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/auth.js:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f66ad88286ca30a", "name": "Dockerfile runs as root: backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3d2a6283f9ebab24", "name": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88b36ba7c3c4a9f2", "name": "Insecure pattern 'direct_innerhtml_assignment' in backend/admin/index.html:228", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in backend/admin/index.html:228"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 82 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 45 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 43 placeholder/mock markers across 17 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ae8a6341bffdd598", "name": "`fetch()` without try/.catch or AbortSignal \u2014 admin/app/lib/api.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 admin/app/lib/api.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f41c9502ce25a0f8", "name": "Commented-code block (7 lines) in QuickronsApp/metro.config.js:3", "shortDescription": {"text": "Commented-code block (7 lines) in QuickronsApp/metro.config.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5792ea9a6612ab18", "name": "Commented-code block (5 lines) in QuickronsApp/src/i18n/index.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/i18n/index.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a389da7802b066c1", "name": "Commented-code block (5 lines) in QuickronsApp/src/state/CartContext.js:40", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/state/CartContext.js:40"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-05f22db41bf1a6e8", "name": "Commented-code block (10 lines) in QuickronsApp/src/screens/RiderOpsScreen.js:1", "shortDescription": {"text": "Commented-code block (10 lines) in QuickronsApp/src/screens/RiderOpsScreen.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-64cd82431ae62318", "name": "Commented-code block (5 lines) in QuickronsApp/src/screens/HomeScreen.js:50", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/screens/HomeScreen.js:50"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-288367a709bc2cc0", "name": "Commented-code block (6 lines) in QuickronsApp/src/screens/PartnerMenuScreen.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in QuickronsApp/src/screens/PartnerMenuScreen.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe1333b41a4ddb08", "name": "Commented-code block (5 lines) in QuickronsApp/src/screens/SearchScreen.js:3", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/screens/SearchScreen.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5a977e1aa4dc2525", "name": "Commented-code block (8 lines) in QuickronsApp/src/screens/PartnerOpsScreen.js:1", "shortDescription": {"text": "Commented-code block (8 lines) in QuickronsApp/src/screens/PartnerOpsScreen.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-20fb161d7123eec7", "name": "Commented-code block (5 lines) in QuickronsApp/src/screens/PartnerBrandingScreen.js:7", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/screens/PartnerBrandingScreen.js:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14de3f2536e1de52", "name": "Commented-code block (6 lines) in QuickronsApp/src/components/SmartImage.js:3", "shortDescription": {"text": "Commented-code block (6 lines) in QuickronsApp/src/components/SmartImage.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0160dae6f68deecd", "name": "Commented-code block (5 lines) in QuickronsApp/src/lib/confirm.js:8", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/lib/confirm.js:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cb782c61c9537f79", "name": "Commented-code block (5 lines) in QuickronsApp/src/lib/socket.js:6", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/lib/socket.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f4599bd6a4590de8", "name": "Commented-code block (8 lines) in QuickronsApp/src/lib/api.js:10", "shortDescription": {"text": "Commented-code block (8 lines) in QuickronsApp/src/lib/api.js:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e1c81f21c03f28c", "name": "Commented-code block (7 lines) in QuickronsApp/src/lib/imagePick.js:4", "shortDescription": {"text": "Commented-code block (7 lines) in QuickronsApp/src/lib/imagePick.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-86345e2c7c9dfce2", "name": "Commented-code block (5 lines) in QuickronsApp/src/lib/layout.js:3", "shortDescription": {"text": "Commented-code block (5 lines) in QuickronsApp/src/lib/layout.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9209c906294771f7", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/scripts/qa-launch-blockers.js:59", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/scripts/qa-launch-blockers.js:59"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fc332f7260bb0604", "name": "Commented-code block (6 lines) in backend/prisma/seed.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in backend/prisma/seed.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a40a57ab13b459b9", "name": "Commented-code block (9 lines) in backend/src/socket.js:3", "shortDescription": {"text": "Commented-code block (9 lines) in backend/src/socket.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ab23b922fe8169a3", "name": "Commented-code block (5 lines) in backend/src/lib/calling.js:3", "shortDescription": {"text": "Commented-code block (5 lines) in backend/src/lib/calling.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a52f649fb033ff91", "name": "Commented-code block (8 lines) in backend/src/routes/admin.js:88", "shortDescription": {"text": "Commented-code block (8 lines) in backend/src/routes/admin.js:88"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2b60980268610667", "name": "Commented-code block (9 lines) in backend/src/routes/orders.js:75", "shortDescription": {"text": "Commented-code block (9 lines) in backend/src/routes/orders.js:75"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f0d50d20328d64a0", "name": "Commented-code block (8 lines) in backend/src/routes/menu.js:6", "shortDescription": {"text": "Commented-code block (8 lines) in backend/src/routes/menu.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e7038a64bf33ca8c", "name": "Commented-code block (6 lines) in backend/src/routes/partner.js:4", "shortDescription": {"text": "Commented-code block (6 lines) in backend/src/routes/partner.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-de851d25c48d2cea", "name": "Commented-code block (6 lines) in backend/src/routes/auth.js:204", "shortDescription": {"text": "Commented-code block (6 lines) in backend/src/routes/auth.js:204"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0defd32c43dc017f", "name": "Commented-code block (5 lines) in backend/src/routes/addresses.js:3", "shortDescription": {"text": "Commented-code block (5 lines) in backend/src/routes/addresses.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b7c7ba0205003c0f", "name": "Commented-code block (7 lines) in backend/src/routes/rider.js:4", "shortDescription": {"text": "Commented-code block (7 lines) in backend/src/routes/rider.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5d03605b97c99206", "name": "Commented-code block (7 lines) in backend/src/routes/kitchens.js:8", "shortDescription": {"text": "Commented-code block (7 lines) in backend/src/routes/kitchens.js:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cce61981e8badaed", "name": "Dangling fetch: POST /api/v1/auth/send-otp (QuickronsAppV2/src/lib/api.js:45)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/auth/send-otp (QuickronsAppV2/src/lib/api.js:45)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:45` calls `POST /api/v1/auth/send-otp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/auth/send-otp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-15d9055974423b71", "name": "Dangling fetch: POST /api/v1/auth/verify-otp (QuickronsAppV2/src/lib/api.js:48)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/auth/verify-otp (QuickronsAppV2/src/lib/api.js:48)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:48` calls `POST /api/v1/auth/verify-otp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/auth/verify-otp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0a3a211f3f247b65", "name": "Dangling fetch: GET /api/v1/menu (QuickronsAppV2/src/lib/api.js:53)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/menu (QuickronsAppV2/src/lib/api.js:53)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:53` calls `GET /api/v1/menu` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/menu`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b21dc1004f236ba", "name": "Dangling fetch: POST /api/v1/orders (QuickronsAppV2/src/lib/api.js:57)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/orders (QuickronsAppV2/src/lib/api.js:57)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:57` calls `POST /api/v1/orders` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/orders`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9fb9ca3d814e12b2", "name": "Dangling fetch: GET /api/v1/orders/${encodeURIComponent(idOrNumber)} (QuickronsAppV2/src/lib/api.js:63)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/orders/${encodeURIComponent(idOrNumber)} (QuickronsAppV2/src/lib/api.js:63)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:63` calls `GET /api/v1/orders/${encodeURIComponent(idOrNumber)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/orders/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d25e5aadc488d284", "name": "Dangling fetch: POST /api/v1/riders/apply (QuickronsAppV2/src/lib/api.js:67)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/riders/apply (QuickronsAppV2/src/lib/api.js:67)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:67` calls `POST /api/v1/riders/apply` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/riders/apply`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-008b183820a97f28", "name": "Dangling fetch: POST /api/v1/partners/apply (QuickronsAppV2/src/lib/api.js:73)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/partners/apply (QuickronsAppV2/src/lib/api.js:73)"}, "fullDescription": {"text": "`QuickronsAppV2/src/lib/api.js:73` calls `POST /api/v1/partners/apply` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partners/apply`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c0284b705df84623", "name": "Dangling fetch: POST /api/v1/auth/send-otp (QuickronsApp/src/lib/api.js:119)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/auth/send-otp (QuickronsApp/src/lib/api.js:119)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:119` calls `POST /api/v1/auth/send-otp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/auth/send-otp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f8d7eb27e0a4144f", "name": "Dangling fetch: POST /api/v1/auth/verify-otp (QuickronsApp/src/lib/api.js:122)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/auth/verify-otp (QuickronsApp/src/lib/api.js:122)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:122` calls `POST /api/v1/auth/verify-otp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/auth/verify-otp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b21663bd29f6d775", "name": "Dangling fetch: GET /api/v1/auth/me (QuickronsApp/src/lib/api.js:127)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/auth/me (QuickronsApp/src/lib/api.js:127)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:127` calls `GET /api/v1/auth/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/auth/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-32f753255d4101dd", "name": "Dangling fetch: GET /api/v1/kitchens (QuickronsApp/src/lib/api.js:138)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/kitchens (QuickronsApp/src/lib/api.js:138)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:138` calls `GET /api/v1/kitchens` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/kitchens`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e186f47158fe1547", "name": "Dangling fetch: GET /api/v1/kitchens?q=${encodeURIComponent(q)}&limit=20 (QuickronsApp/src/lib/api.js:144)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/kitchens?q=${encodeURIComponent(q)}&limit=20 (QuickronsApp/src/lib/api.js:144)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:144` calls `GET /api/v1/kitchens?q=${encodeURIComponent(q)}&limit=20` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/kitchens`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b7672c4e8d033e88", "name": "Dangling fetch: GET /api/v1/kitchens/${id} (QuickronsApp/src/lib/api.js:147)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/kitchens/${id} (QuickronsApp/src/lib/api.js:147)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:147` calls `GET /api/v1/kitchens/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/kitchens/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ab5f265d97f25a8", "name": "Dangling fetch: GET /api/v1/kitchens/${id}/menu (QuickronsApp/src/lib/api.js:150)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/kitchens/${id}/menu (QuickronsApp/src/lib/api.js:150)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:150` calls `GET /api/v1/kitchens/${id}/menu` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/kitchens/<p>/menu`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4243c96bd5c44ec", "name": "Dangling fetch: GET /api/v1/menu?q=${encodeURIComponent(q)}&limit=20 (QuickronsApp/src/lib/api.js:159)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/menu?q=${encodeURIComponent(q)}&limit=20 (QuickronsApp/src/lib/api.js:159)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:159` calls `GET /api/v1/menu?q=${encodeURIComponent(q)}&limit=20` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/menu`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1ba51f296601399", "name": "Dangling fetch: GET /api/v1/addresses (QuickronsApp/src/lib/api.js:166)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/addresses (QuickronsApp/src/lib/api.js:166)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:166` calls `GET /api/v1/addresses` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/addresses`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-02072f09e59cafc8", "name": "Dangling fetch: POST /api/v1/orders (QuickronsApp/src/lib/api.js:173)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/orders (QuickronsApp/src/lib/api.js:173)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:173` calls `POST /api/v1/orders` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/orders`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-21ec64a4a65b6fd0", "name": "Dangling fetch: GET /api/v1/orders/${id} (QuickronsApp/src/lib/api.js:176)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/orders/${id} (QuickronsApp/src/lib/api.js:176)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:176` calls `GET /api/v1/orders/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/orders/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6db0edbc01f9ae7", "name": "Dangling fetch: POST /api/v1/orders/${id}/rating (QuickronsApp/src/lib/api.js:188)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/orders/${id}/rating (QuickronsApp/src/lib/api.js:188)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:188` calls `POST /api/v1/orders/${id}/rating` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/orders/<p>/rating`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0086360b37f14e5d", "name": "Dangling fetch: POST /api/v1/orders/${id}/contact (QuickronsApp/src/lib/api.js:194)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/orders/${id}/contact (QuickronsApp/src/lib/api.js:194)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:194` calls `POST /api/v1/orders/${id}/contact` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/orders/<p>/contact`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0b56cb1be88f2e49", "name": "Dangling fetch: GET /api/v1/partner/me (QuickronsApp/src/lib/api.js:201)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/partner/me (QuickronsApp/src/lib/api.js:201)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:201` calls `GET /api/v1/partner/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d8af7195de8a3f2f", "name": "Dangling fetch: PATCH /api/v1/partner/me (QuickronsApp/src/lib/api.js:204)", "shortDescription": {"text": "Dangling fetch: PATCH /api/v1/partner/me (QuickronsApp/src/lib/api.js:204)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:204` calls `PATCH /api/v1/partner/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9e4e860830c035b2", "name": "Dangling fetch: GET /api/v1/partner/orders${qs} (QuickronsApp/src/lib/api.js:207)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/partner/orders${qs} (QuickronsApp/src/lib/api.js:207)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:207` calls `GET /api/v1/partner/orders${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/orders/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0f13a90178f083c0", "name": "Dangling fetch: POST /api/v1/partner/orders/${id}/accept (QuickronsApp/src/lib/api.js:210)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/accept (QuickronsApp/src/lib/api.js:210)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:210` calls `POST /api/v1/partner/orders/${id}/accept` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/orders/<p>/accept`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75b9aad5b668ec84", "name": "Dangling fetch: POST /api/v1/partner/orders/${id}/reject (QuickronsApp/src/lib/api.js:212)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/reject (QuickronsApp/src/lib/api.js:212)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:212` calls `POST /api/v1/partner/orders/${id}/reject` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/orders/<p>/reject`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4129bd4d66a99ea", "name": "Dangling fetch: POST /api/v1/partner/orders/${id}/preparing (QuickronsApp/src/lib/api.js:214)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/preparing (QuickronsApp/src/lib/api.js:214)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:214` calls `POST /api/v1/partner/orders/${id}/preparing` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/orders/<p>/preparing`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-895864cae859196e", "name": "Dangling fetch: POST /api/v1/partner/orders/${id}/ready (QuickronsApp/src/lib/api.js:216)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/ready (QuickronsApp/src/lib/api.js:216)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:216` calls `POST /api/v1/partner/orders/${id}/ready` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/orders/<p>/ready`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-930359a820816f84", "name": "Dangling fetch: GET /api/v1/partner/wallet (QuickronsApp/src/lib/api.js:218)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/partner/wallet (QuickronsApp/src/lib/api.js:218)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:218` calls `GET /api/v1/partner/wallet` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/wallet`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4ea7ad0b492628c7", "name": "Dangling fetch: GET /api/v1/partner/menu (QuickronsApp/src/lib/api.js:228)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/partner/menu (QuickronsApp/src/lib/api.js:228)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:228` calls `GET /api/v1/partner/menu` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/menu`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8eaf9e7f02d3626e", "name": "Dangling fetch: POST /api/v1/partner/menu (QuickronsApp/src/lib/api.js:230)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/partner/menu (QuickronsApp/src/lib/api.js:230)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:230` calls `POST /api/v1/partner/menu` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/menu`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d5717050ca118aeb", "name": "Dangling fetch: PATCH /api/v1/partner/menu/${id} (QuickronsApp/src/lib/api.js:232)", "shortDescription": {"text": "Dangling fetch: PATCH /api/v1/partner/menu/${id} (QuickronsApp/src/lib/api.js:232)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:232` calls `PATCH /api/v1/partner/menu/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/menu/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a9e31bf2d6207641", "name": "Dangling fetch: DELETE /api/v1/partner/menu/${id} (QuickronsApp/src/lib/api.js:234)", "shortDescription": {"text": "Dangling fetch: DELETE /api/v1/partner/menu/${id} (QuickronsApp/src/lib/api.js:234)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:234` calls `DELETE /api/v1/partner/menu/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/partner/menu/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-76a47783f8a16cab", "name": "Dangling fetch: GET /api/v1/rider/me (QuickronsApp/src/lib/api.js:278)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/rider/me (QuickronsApp/src/lib/api.js:278)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:278` calls `GET /api/v1/rider/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6671214c7fc1cbb5", "name": "Dangling fetch: POST /api/v1/rider/me/online (QuickronsApp/src/lib/api.js:280)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/rider/me/online (QuickronsApp/src/lib/api.js:280)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:280` calls `POST /api/v1/rider/me/online` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/me/online`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-540e3dc92bb379b4", "name": "Dangling fetch: GET /api/v1/rider/orders/available (QuickronsApp/src/lib/api.js:282)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/rider/orders/available (QuickronsApp/src/lib/api.js:282)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:282` calls `GET /api/v1/rider/orders/available` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/orders/available`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3fe63fd60573a1e9", "name": "Dangling fetch: GET /api/v1/rider/me/orders${qs} (QuickronsApp/src/lib/api.js:285)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/rider/me/orders${qs} (QuickronsApp/src/lib/api.js:285)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:285` calls `GET /api/v1/rider/me/orders${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/me/orders/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35406215f68d65a2", "name": "Dangling fetch: POST /api/v1/rider/orders/${id}/accept (QuickronsApp/src/lib/api.js:288)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/rider/orders/${id}/accept (QuickronsApp/src/lib/api.js:288)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:288` calls `POST /api/v1/rider/orders/${id}/accept` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/orders/<p>/accept`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5410407dfed72109", "name": "Dangling fetch: POST /api/v1/rider/orders/${id}/picked-up (QuickronsApp/src/lib/api.js:290)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/rider/orders/${id}/picked-up (QuickronsApp/src/lib/api.js:290)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:290` calls `POST /api/v1/rider/orders/${id}/picked-up` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/orders/<p>/picked-up`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f7c65fa8c728cba", "name": "Dangling fetch: POST /api/v1/rider/orders/${id}/delivered (QuickronsApp/src/lib/api.js:292)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/rider/orders/${id}/delivered (QuickronsApp/src/lib/api.js:292)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:292` calls `POST /api/v1/rider/orders/${id}/delivered` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/orders/<p>/delivered`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4c509af315ed723f", "name": "Dangling fetch: GET /api/v1/rider/wallet (QuickronsApp/src/lib/api.js:294)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/rider/wallet (QuickronsApp/src/lib/api.js:294)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:294` calls `GET /api/v1/rider/wallet` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/rider/wallet`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b46c08f514c44b73", "name": "Dangling fetch: GET /api/v1/admin/orders${qs} (QuickronsApp/src/lib/api.js:302)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/orders${qs} (QuickronsApp/src/lib/api.js:302)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:302` calls `GET /api/v1/admin/orders${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/orders/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-661e7aceed56ce90", "name": "Dangling fetch: GET /api/v1/admin/analytics (QuickronsApp/src/lib/api.js:305)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/analytics (QuickronsApp/src/lib/api.js:305)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:305` calls `GET /api/v1/admin/analytics` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/analytics`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac786c35ac83fa82", "name": "Dangling fetch: GET /api/v1/admin/wallets (QuickronsApp/src/lib/api.js:307)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/wallets (QuickronsApp/src/lib/api.js:307)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:307` calls `GET /api/v1/admin/wallets` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/wallets`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f98d65669d26016e", "name": "Dangling fetch: GET /api/v1/admin/partners (QuickronsApp/src/lib/api.js:309)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/partners (QuickronsApp/src/lib/api.js:309)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:309` calls `GET /api/v1/admin/partners` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/partners`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-716e797a89699d38", "name": "Dangling fetch: GET /api/v1/admin/riders (QuickronsApp/src/lib/api.js:311)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/riders (QuickronsApp/src/lib/api.js:311)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:311` calls `GET /api/v1/admin/riders` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/riders`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5489a505312a10e", "name": "Dangling fetch: POST /api/v1/admin/orders/${id}/cancel (QuickronsApp/src/lib/api.js:313)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/admin/orders/${id}/cancel (QuickronsApp/src/lib/api.js:313)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:313` calls `POST /api/v1/admin/orders/${id}/cancel` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/orders/<p>/cancel`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d07181830b6e829", "name": "Dangling fetch: POST /api/v1/admin/orders/${id}/payment/mark-paid (QuickronsApp/src/lib/api.js:315)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/admin/orders/${id}/payment/mark-paid (QuickronsApp/src/lib/api.js:315)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:315` calls `POST /api/v1/admin/orders/${id}/payment/mark-paid` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/orders/<p>/payment/mark-paid`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e0b62dedfa95d734", "name": "Dangling fetch: POST /api/v1/admin/orders/${id}/payment/reject (QuickronsApp/src/lib/api.js:317)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/admin/orders/${id}/payment/reject (QuickronsApp/src/lib/api.js:317)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:317` calls `POST /api/v1/admin/orders/${id}/payment/reject` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/orders/<p>/payment/reject`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b643eb1e986844cd", "name": "Dangling fetch: GET /api/v1/admin/orders/stuck (QuickronsApp/src/lib/api.js:319)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/orders/stuck (QuickronsApp/src/lib/api.js:319)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:319` calls `GET /api/v1/admin/orders/stuck` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/orders/stuck`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-68e0befb8239c8f0", "name": "Dangling fetch: GET /api/v1/admin/ratings?limit=50 (QuickronsApp/src/lib/api.js:321)", "shortDescription": {"text": "Dangling fetch: GET /api/v1/admin/ratings?limit=50 (QuickronsApp/src/lib/api.js:321)"}, "fullDescription": {"text": "`QuickronsApp/src/lib/api.js:321` calls `GET /api/v1/admin/ratings?limit=50` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/v1/admin/ratings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3bec7ccd0b909bea", "name": "Unused endpoint: USE /api/v1/auth", "shortDescription": {"text": "Unused endpoint: USE /api/v1/auth"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b641976b97f9f46", "name": "Unused endpoint: USE /api/v1/menu", "shortDescription": {"text": "Unused endpoint: USE /api/v1/menu"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/menu` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc490902ad849182", "name": "Unused endpoint: USE /api/v1/orders", "shortDescription": {"text": "Unused endpoint: USE /api/v1/orders"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/orders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b3f1ebf385294f2", "name": "Unused endpoint: USE /api/v1/riders", "shortDescription": {"text": "Unused endpoint: USE /api/v1/riders"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/riders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b801ba178074486a", "name": "Unused endpoint: USE /api/v1/partners", "shortDescription": {"text": "Unused endpoint: USE /api/v1/partners"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/partners` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e72710ab38f6107b", "name": "Unused endpoint: USE /api/v1/customers", "shortDescription": {"text": "Unused endpoint: USE /api/v1/customers"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/customers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0562818aae427bca", "name": "Unused endpoint: USE /api/v1/addresses", "shortDescription": {"text": "Unused endpoint: USE /api/v1/addresses"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/addresses` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0510d224d50267e", "name": "Unused endpoint: USE /api/v1/kitchens", "shortDescription": {"text": "Unused endpoint: USE /api/v1/kitchens"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/kitchens` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-529f7e01f1f485a4", "name": "Unused endpoint: USE /api/v1/partner", "shortDescription": {"text": "Unused endpoint: USE /api/v1/partner"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/partner` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a25220164abe0b09", "name": "Unused endpoint: USE /api/v1/rider", "shortDescription": {"text": "Unused endpoint: USE /api/v1/rider"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/rider` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2cc7f440e42eac79", "name": "Unused endpoint: USE /api/v1/admin", "shortDescription": {"text": "Unused endpoint: USE /api/v1/admin"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /api/v1/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2d8849fb6b1ac47", "name": "Unused endpoint: USE /admin", "shortDescription": {"text": "Unused endpoint: USE /admin"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bc898b3b7565990", "name": "Unused endpoint: USE /uploads", "shortDescription": {"text": "Unused endpoint: USE /uploads"}, "fullDescription": {"text": "`backend/src/index.js` declares `USE /uploads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6685d40686d63393", "name": "Unused endpoint: GET /protected", "shortDescription": {"text": "Unused endpoint: GET /protected"}, "fullDescription": {"text": "`backend/src/middleware/auth.js` declares `GET /protected` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-953ec1a0ee6df50d", "name": "Unused endpoint: GET /admin", "shortDescription": {"text": "Unused endpoint: GET /admin"}, "fullDescription": {"text": "`backend/src/middleware/auth.js` declares `GET /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6236b283b79811b8", "name": "Unused endpoint: POST /upload", "shortDescription": {"text": "Unused endpoint: POST /upload"}, "fullDescription": {"text": "`backend/src/lib/upload.js` declares `POST /upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`backend/src/routes/customers.js` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea575b61c121b733", "name": "Unused endpoint: PATCH /me", "shortDescription": {"text": "Unused endpoint: PATCH /me"}, "fullDescription": {"text": "`backend/src/routes/customers.js` declares `PATCH /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0df8ff151f6b3f6", "name": "Unused endpoint: GET /me/orders", "shortDescription": {"text": "Unused endpoint: GET /me/orders"}, "fullDescription": {"text": "`backend/src/routes/customers.js` declares `GET /me/orders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a88e32ba95dda7c", "name": "Unused endpoint: POST /apply", "shortDescription": {"text": "Unused endpoint: POST /apply"}, "fullDescription": {"text": "`backend/src/routes/partners.js` declares `POST /apply` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84b751e72dbdae91", "name": "Unused endpoint: GET /applications", "shortDescription": {"text": "Unused endpoint: GET /applications"}, "fullDescription": {"text": "`backend/src/routes/partners.js` declares `GET /applications` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bce5bddd09c8537", "name": "Unused endpoint: POST /applications/:id/status", "shortDescription": {"text": "Unused endpoint: POST /applications/:id/status"}, "fullDescription": {"text": "`backend/src/routes/partners.js` declares `POST /applications/:id/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0328e9bdbb61fa68", "name": "Unused endpoint: GET /orders", "shortDescription": {"text": "Unused endpoint: GET /orders"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /orders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60fc1ff96f72a908", "name": "Unused endpoint: POST /orders/:id/payment/mark-paid", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/payment/mark-paid"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `POST /orders/:id/payment/mark-paid` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3872d067e687c52e", "name": "Unused endpoint: POST /orders/:id/payment/reject", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/payment/reject"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `POST /orders/:id/payment/reject` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0e0dd6830b7e9fd", "name": "Unused endpoint: GET /orders/stuck", "shortDescription": {"text": "Unused endpoint: GET /orders/stuck"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /orders/stuck` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0469dbf43c1a9621", "name": "Unused endpoint: GET /orders/:id", "shortDescription": {"text": "Unused endpoint: GET /orders/:id"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /orders/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-090df84af01d788e", "name": "Unused endpoint: POST /orders/:id/cancel", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/cancel"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `POST /orders/:id/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a70c45950e6280f1", "name": "Unused endpoint: POST /orders/:id/assign-rider", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/assign-rider"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `POST /orders/:id/assign-rider` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2619d5118de8711", "name": "Unused endpoint: GET /partners", "shortDescription": {"text": "Unused endpoint: GET /partners"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /partners` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-250dbd13097c1db7", "name": "Unused endpoint: POST /partners/:id/suspend", "shortDescription": {"text": "Unused endpoint: POST /partners/:id/suspend"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `POST /partners/:id/suspend` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06ed76ee925dc356", "name": "Unused endpoint: GET /riders", "shortDescription": {"text": "Unused endpoint: GET /riders"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /riders` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1726e9f33416858a", "name": "Unused endpoint: POST /riders/:id/suspend", "shortDescription": {"text": "Unused endpoint: POST /riders/:id/suspend"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `POST /riders/:id/suspend` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dab50891d7bd7cf1", "name": "Unused endpoint: GET /wallets", "shortDescription": {"text": "Unused endpoint: GET /wallets"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /wallets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4629fc2f2a182ac9", "name": "Unused endpoint: GET /analytics", "shortDescription": {"text": "Unused endpoint: GET /analytics"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /analytics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0b31504b2943535", "name": "Unused endpoint: GET /ratings", "shortDescription": {"text": "Unused endpoint: GET /ratings"}, "fullDescription": {"text": "`backend/src/routes/admin.js` declares `GET /ratings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca5756175765b49d", "name": "Unused endpoint: GET /:id", "shortDescription": {"text": "Unused endpoint: GET /:id"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `GET /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cb78db4e7bafb1c", "name": "Unused endpoint: POST /:id/cancel", "shortDescription": {"text": "Unused endpoint: POST /:id/cancel"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `POST /:id/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-447e8bc858284a26", "name": "Unused endpoint: POST /:id/contact", "shortDescription": {"text": "Unused endpoint: POST /:id/contact"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `POST /:id/contact` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43c0d00a16a281e7", "name": "Unused endpoint: POST /:id/rating", "shortDescription": {"text": "Unused endpoint: POST /:id/rating"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `POST /:id/rating` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09d71208c4545c30", "name": "Unused endpoint: POST /:id/status", "shortDescription": {"text": "Unused endpoint: POST /:id/status"}, "fullDescription": {"text": "`backend/src/routes/orders.js` declares `POST /:id/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6351e20de3c7a488", "name": "Unused endpoint: GET /featured", "shortDescription": {"text": "Unused endpoint: GET /featured"}, "fullDescription": {"text": "`backend/src/routes/menu.js` declares `GET /featured` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e17696780f3811f9", "name": "Unused endpoint: POST /orders/:id/accept", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/accept"}, "fullDescription": {"text": "`backend/src/routes/partner.js` declares `POST /orders/:id/accept` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-789b7d797e982514", "name": "Unused endpoint: POST /orders/:id/reject", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/reject"}, "fullDescription": {"text": "`backend/src/routes/partner.js` declares `POST /orders/:id/reject` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c8131979f4b44a56", "name": "Unused endpoint: POST /orders/:id/preparing", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/preparing"}, "fullDescription": {"text": "`backend/src/routes/partner.js` declares `POST /orders/:id/preparing` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1579a654670c852a", "name": "Unused endpoint: POST /orders/:id/ready", "shortDescription": {"text": "Unused endpoint: POST /orders/:id/ready"}, "fullDescription": {"text": "`backend/src/routes/partner.js` declares `POST /orders/:id/ready` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18579730be0a88bf", "name": "Unused endpoint: POST /menu/upload", "shortDescription": {"text": "Unused endpoint: POST /menu/upload"}, "fullDescription": {"text": "`backend/src/routes/partner.js` declares `POST /menu/upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29e0ed54344aaa81", "name": "Unused endpoint: GET /menu", "shortDescription": {"text": "Unused endpoint: GET /menu"}, "fullDescription": {"text": "`backend/src/routes/partner.js` declares `GET /menu` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/17645"}, "properties": {"repository": "quickronserp/Quickrons", "repoUrl": "https://github.com/quickronserp/Quickrons", "branch": "main"}, "results": [{"ruleId": "scanner-08f9ddfd93cf002f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 QuickronsApp/App.js:189"}, "properties": {"repobilityId": "b0661643df4209e4", "scanner": "scanner-primary", "fingerprint": "08f9ddfd93cf002f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4c07c7292349a50a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 QuickronsApp/src/state/AuthContext.js:45"}, "properties": {"repobilityId": "3edc5b15dd883a18", "scanner": "scanner-primary", "fingerprint": "4c07c7292349a50a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-727cf94ba730d3f1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 QuickronsApp/src/lib/socket.js:44"}, "properties": {"repobilityId": "93e7b5b6a4376dc3", "scanner": "scanner-primary", "fingerprint": "727cf94ba730d3f1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7e2e51de8d368448", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/scripts/qa-launch-blockers.js:23"}, "properties": {"repobilityId": "948cd21cad3e31ac", "scanner": "scanner-primary", "fingerprint": "7e2e51de8d368448", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-915ebed951d6d819", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/prisma/backfill-images.js:54"}, "properties": {"repobilityId": "6657e7124ecbab11", "scanner": "scanner-primary", "fingerprint": "915ebed951d6d819", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f4e3be9bd025f419", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/prisma/seed.js:386"}, "properties": {"repobilityId": "55188a29aa49039e", "scanner": "scanner-primary", "fingerprint": "f4e3be9bd025f419", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b2a15e3555a7f5c4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/socket.js:53"}, "properties": {"repobilityId": "3b8bd160c49dd060", "scanner": "scanner-primary", "fingerprint": "b2a15e3555a7f5c4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f5bf5295436d4dce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/index.js:69"}, "properties": {"repobilityId": "03d5d680343d7d14", "scanner": "scanner-primary", "fingerprint": "f5bf5295436d4dce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-66dd4aeca573df98", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/lib/upload.js:74"}, "properties": {"repobilityId": "f30456ccb52a5353", "scanner": "scanner-primary", "fingerprint": "66dd4aeca573df98", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-92c27aa07ddc2395", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 backend/src/routes/auth.js:156"}, "properties": {"repobilityId": "0dd5c7f5526784f7", "scanner": "scanner-primary", "fingerprint": "92c27aa07ddc2395", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-dc72d196d56254a6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/src/routes/auth.js:28"}, "properties": {"repobilityId": "660f51473a9dc5e9", "scanner": "scanner-primary", "fingerprint": "dc72d196d56254a6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1f66ad88286ca30a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "properties": {"repobilityId": "7afd2b0e8a8c9eeb", "scanner": "scanner-primary", "fingerprint": "1f66ad88286ca30a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-3d2a6283f9ebab24", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20-alpine"}, "properties": {"repobilityId": "e866ff9772e76d62", "scanner": "scanner-primary", "fingerprint": "3d2a6283f9ebab24", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-88b36ba7c3c4a9f2", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in backend/admin/index.html:228"}, "properties": {"repobilityId": "5e53b6d307bbe660", "scanner": "scanner-primary", "fingerprint": "88b36ba7c3c4a9f2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/admin/index.html"}, "region": {"startLine": 228}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "88e06325bc8387dc", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "6426d85cc8811b94", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "e4022288d830a0c4", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "bc5de4b98d9045f3", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "c63ec8a973c1d497", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "e624be5b0ba4b532", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "23bc372d61ece576", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-ae8a6341bffdd598", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 admin/app/lib/api.ts:10"}, "properties": {"repobilityId": "1555402b7831a5c1", "scanner": "scanner-primary", "fingerprint": "ae8a6341bffdd598", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f41c9502ce25a0f8", "level": "none", "message": {"text": "Commented-code block (7 lines) in QuickronsApp/metro.config.js:3"}, "properties": {"repobilityId": "b6927042dc21cf78", "scanner": "scanner-primary", "fingerprint": "f41c9502ce25a0f8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5792ea9a6612ab18", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/i18n/index.js:1"}, "properties": {"repobilityId": "103746b2d147a10d", "scanner": "scanner-primary", "fingerprint": "5792ea9a6612ab18", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a389da7802b066c1", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/state/CartContext.js:40"}, "properties": {"repobilityId": "de63c2c5f057366e", "scanner": "scanner-primary", "fingerprint": "a389da7802b066c1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-05f22db41bf1a6e8", "level": "none", "message": {"text": "Commented-code block (10 lines) in QuickronsApp/src/screens/RiderOpsScreen.js:1"}, "properties": {"repobilityId": "960a1f536d6fd8db", "scanner": "scanner-primary", "fingerprint": "05f22db41bf1a6e8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-64cd82431ae62318", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/screens/HomeScreen.js:50"}, "properties": {"repobilityId": "b4c85b26f92ba2cd", "scanner": "scanner-primary", "fingerprint": "64cd82431ae62318", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-288367a709bc2cc0", "level": "none", "message": {"text": "Commented-code block (6 lines) in QuickronsApp/src/screens/PartnerMenuScreen.js:5"}, "properties": {"repobilityId": "d28db47ad12aa9aa", "scanner": "scanner-primary", "fingerprint": "288367a709bc2cc0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fe1333b41a4ddb08", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/screens/SearchScreen.js:3"}, "properties": {"repobilityId": "be6d9c9ed130f35e", "scanner": "scanner-primary", "fingerprint": "fe1333b41a4ddb08", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5a977e1aa4dc2525", "level": "none", "message": {"text": "Commented-code block (8 lines) in QuickronsApp/src/screens/PartnerOpsScreen.js:1"}, "properties": {"repobilityId": "20650bd27e14bcb3", "scanner": "scanner-primary", "fingerprint": "5a977e1aa4dc2525", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-20fb161d7123eec7", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/screens/PartnerBrandingScreen.js:7"}, "properties": {"repobilityId": "462d101278dd491c", "scanner": "scanner-primary", "fingerprint": "20fb161d7123eec7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-14de3f2536e1de52", "level": "none", "message": {"text": "Commented-code block (6 lines) in QuickronsApp/src/components/SmartImage.js:3"}, "properties": {"repobilityId": "3db12166bc95d420", "scanner": "scanner-primary", "fingerprint": "14de3f2536e1de52", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0160dae6f68deecd", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/lib/confirm.js:8"}, "properties": {"repobilityId": "392940226aca678f", "scanner": "scanner-primary", "fingerprint": "0160dae6f68deecd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cb782c61c9537f79", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/lib/socket.js:6"}, "properties": {"repobilityId": "2ece42350c7d9406", "scanner": "scanner-primary", "fingerprint": "cb782c61c9537f79", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f4599bd6a4590de8", "level": "none", "message": {"text": "Commented-code block (8 lines) in QuickronsApp/src/lib/api.js:10"}, "properties": {"repobilityId": "d73a8430ec3cb477", "scanner": "scanner-primary", "fingerprint": "f4599bd6a4590de8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1e1c81f21c03f28c", "level": "none", "message": {"text": "Commented-code block (7 lines) in QuickronsApp/src/lib/imagePick.js:4"}, "properties": {"repobilityId": "7c8741a2a6377f2d", "scanner": "scanner-primary", "fingerprint": "1e1c81f21c03f28c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-86345e2c7c9dfce2", "level": "none", "message": {"text": "Commented-code block (5 lines) in QuickronsApp/src/lib/layout.js:3"}, "properties": {"repobilityId": "d496888c2918cbed", "scanner": "scanner-primary", "fingerprint": "86345e2c7c9dfce2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9209c906294771f7", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/scripts/qa-launch-blockers.js:59"}, "properties": {"repobilityId": "104975b2663b67d7", "scanner": "scanner-primary", "fingerprint": "9209c906294771f7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-fc332f7260bb0604", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/prisma/seed.js:5"}, "properties": {"repobilityId": "05d05fcb6ee73c47", "scanner": "scanner-primary", "fingerprint": "fc332f7260bb0604", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a40a57ab13b459b9", "level": "none", "message": {"text": "Commented-code block (9 lines) in backend/src/socket.js:3"}, "properties": {"repobilityId": "e7b9d86c7e231e29", "scanner": "scanner-primary", "fingerprint": "a40a57ab13b459b9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ab23b922fe8169a3", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/src/lib/calling.js:3"}, "properties": {"repobilityId": "c3818ecca14dc147", "scanner": "scanner-primary", "fingerprint": "ab23b922fe8169a3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a52f649fb033ff91", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/src/routes/admin.js:88"}, "properties": {"repobilityId": "2750c325c13d8aa6", "scanner": "scanner-primary", "fingerprint": "a52f649fb033ff91", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2b60980268610667", "level": "none", "message": {"text": "Commented-code block (9 lines) in backend/src/routes/orders.js:75"}, "properties": {"repobilityId": "92ba44df83cd719b", "scanner": "scanner-primary", "fingerprint": "2b60980268610667", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f0d50d20328d64a0", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/src/routes/menu.js:6"}, "properties": {"repobilityId": "dfa4ef866f1d431e", "scanner": "scanner-primary", "fingerprint": "f0d50d20328d64a0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e7038a64bf33ca8c", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/src/routes/partner.js:4"}, "properties": {"repobilityId": "05da103cae7cf45b", "scanner": "scanner-primary", "fingerprint": "e7038a64bf33ca8c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-de851d25c48d2cea", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/src/routes/auth.js:204"}, "properties": {"repobilityId": "5bafa3be8942d719", "scanner": "scanner-primary", "fingerprint": "de851d25c48d2cea", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0defd32c43dc017f", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/src/routes/addresses.js:3"}, "properties": {"repobilityId": "554861a2b9222462", "scanner": "scanner-primary", "fingerprint": "0defd32c43dc017f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b7c7ba0205003c0f", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/src/routes/rider.js:4"}, "properties": {"repobilityId": "7a147a8eb660b1bf", "scanner": "scanner-primary", "fingerprint": "b7c7ba0205003c0f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5d03605b97c99206", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/src/routes/kitchens.js:8"}, "properties": {"repobilityId": "8a803c8e974cc73b", "scanner": "scanner-primary", "fingerprint": "5d03605b97c99206", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cce61981e8badaed", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/auth/send-otp (QuickronsAppV2/src/lib/api.js:45)"}, "properties": {"repobilityId": "bf75784bbc3a26af", "scanner": "scanner-primary", "fingerprint": "cce61981e8badaed", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-15d9055974423b71", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/auth/verify-otp (QuickronsAppV2/src/lib/api.js:48)"}, "properties": {"repobilityId": "0164e8528d940489", "scanner": "scanner-primary", "fingerprint": "15d9055974423b71", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0a3a211f3f247b65", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/menu (QuickronsAppV2/src/lib/api.js:53)"}, "properties": {"repobilityId": "73cb3c0ed7f44852", "scanner": "scanner-primary", "fingerprint": "0a3a211f3f247b65", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3b21dc1004f236ba", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/orders (QuickronsAppV2/src/lib/api.js:57)"}, "properties": {"repobilityId": "cdb01426f4a484a5", "scanner": "scanner-primary", "fingerprint": "3b21dc1004f236ba", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9fb9ca3d814e12b2", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/orders/${encodeURIComponent(idOrNumber)} (QuickronsAppV2/src/lib/api.js:63)"}, "properties": {"repobilityId": "2f0aea266a6cd148", "scanner": "scanner-primary", "fingerprint": "9fb9ca3d814e12b2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d25e5aadc488d284", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/riders/apply (QuickronsAppV2/src/lib/api.js:67)"}, "properties": {"repobilityId": "28fe5854ba4e52c0", "scanner": "scanner-primary", "fingerprint": "d25e5aadc488d284", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-008b183820a97f28", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/partners/apply (QuickronsAppV2/src/lib/api.js:73)"}, "properties": {"repobilityId": "491f0f8a040c808a", "scanner": "scanner-primary", "fingerprint": "008b183820a97f28", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c0284b705df84623", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/auth/send-otp (QuickronsApp/src/lib/api.js:119)"}, "properties": {"repobilityId": "17c4bf6468805cea", "scanner": "scanner-primary", "fingerprint": "c0284b705df84623", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f8d7eb27e0a4144f", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/auth/verify-otp (QuickronsApp/src/lib/api.js:122)"}, "properties": {"repobilityId": "6fbc8576f1e1ddcf", "scanner": "scanner-primary", "fingerprint": "f8d7eb27e0a4144f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b21663bd29f6d775", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/auth/me (QuickronsApp/src/lib/api.js:127)"}, "properties": {"repobilityId": "c5261dc48da785a8", "scanner": "scanner-primary", "fingerprint": "b21663bd29f6d775", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-32f753255d4101dd", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/kitchens (QuickronsApp/src/lib/api.js:138)"}, "properties": {"repobilityId": "28a64a3b5b4673dc", "scanner": "scanner-primary", "fingerprint": "32f753255d4101dd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e186f47158fe1547", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/kitchens?q=${encodeURIComponent(q)}&limit=20 (QuickronsApp/src/lib/api.js:144)"}, "properties": {"repobilityId": "bdffbd518c35e7ff", "scanner": "scanner-primary", "fingerprint": "e186f47158fe1547", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b7672c4e8d033e88", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/kitchens/${id} (QuickronsApp/src/lib/api.js:147)"}, "properties": {"repobilityId": "336aeb2b04c1592e", "scanner": "scanner-primary", "fingerprint": "b7672c4e8d033e88", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6ab5f265d97f25a8", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/kitchens/${id}/menu (QuickronsApp/src/lib/api.js:150)"}, "properties": {"repobilityId": "ebcf9bd62793b06f", "scanner": "scanner-primary", "fingerprint": "6ab5f265d97f25a8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e4243c96bd5c44ec", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/menu?q=${encodeURIComponent(q)}&limit=20 (QuickronsApp/src/lib/api.js:159)"}, "properties": {"repobilityId": "eeecc8f48db1219c", "scanner": "scanner-primary", "fingerprint": "e4243c96bd5c44ec", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c1ba51f296601399", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/addresses (QuickronsApp/src/lib/api.js:166)"}, "properties": {"repobilityId": "388165863a5fb3de", "scanner": "scanner-primary", "fingerprint": "c1ba51f296601399", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-02072f09e59cafc8", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/orders (QuickronsApp/src/lib/api.js:173)"}, "properties": {"repobilityId": "ce03a8a8d4347a3b", "scanner": "scanner-primary", "fingerprint": "02072f09e59cafc8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-21ec64a4a65b6fd0", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/orders/${id} (QuickronsApp/src/lib/api.js:176)"}, "properties": {"repobilityId": "b03660ba4b59e1a2", "scanner": "scanner-primary", "fingerprint": "21ec64a4a65b6fd0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f6db0edbc01f9ae7", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/orders/${id}/rating (QuickronsApp/src/lib/api.js:188)"}, "properties": {"repobilityId": "a9d95c195162621a", "scanner": "scanner-primary", "fingerprint": "f6db0edbc01f9ae7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0086360b37f14e5d", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/orders/${id}/contact (QuickronsApp/src/lib/api.js:194)"}, "properties": {"repobilityId": "f161b0ed5b567908", "scanner": "scanner-primary", "fingerprint": "0086360b37f14e5d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0b56cb1be88f2e49", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/partner/me (QuickronsApp/src/lib/api.js:201)"}, "properties": {"repobilityId": "e138e5970a6cb220", "scanner": "scanner-primary", "fingerprint": "0b56cb1be88f2e49", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d8af7195de8a3f2f", "level": "error", "message": {"text": "Dangling fetch: PATCH /api/v1/partner/me (QuickronsApp/src/lib/api.js:204)"}, "properties": {"repobilityId": "f4186d9fb76700ad", "scanner": "scanner-primary", "fingerprint": "d8af7195de8a3f2f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9e4e860830c035b2", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/partner/orders${qs} (QuickronsApp/src/lib/api.js:207)"}, "properties": {"repobilityId": "9797d548c8d53df6", "scanner": "scanner-primary", "fingerprint": "9e4e860830c035b2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0f13a90178f083c0", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/accept (QuickronsApp/src/lib/api.js:210)"}, "properties": {"repobilityId": "cb981e32ea0fa1a7", "scanner": "scanner-primary", "fingerprint": "0f13a90178f083c0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-75b9aad5b668ec84", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/reject (QuickronsApp/src/lib/api.js:212)"}, "properties": {"repobilityId": "292ed8a5d67fb1ff", "scanner": "scanner-primary", "fingerprint": "75b9aad5b668ec84", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d4129bd4d66a99ea", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/preparing (QuickronsApp/src/lib/api.js:214)"}, "properties": {"repobilityId": "f97d7267a79a5f8c", "scanner": "scanner-primary", "fingerprint": "d4129bd4d66a99ea", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-895864cae859196e", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/partner/orders/${id}/ready (QuickronsApp/src/lib/api.js:216)"}, "properties": {"repobilityId": "cc09befc3bcf93dc", "scanner": "scanner-primary", "fingerprint": "895864cae859196e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-930359a820816f84", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/partner/wallet (QuickronsApp/src/lib/api.js:218)"}, "properties": {"repobilityId": "1ec9efaeb8258685", "scanner": "scanner-primary", "fingerprint": "930359a820816f84", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4ea7ad0b492628c7", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/partner/menu (QuickronsApp/src/lib/api.js:228)"}, "properties": {"repobilityId": "da6d7b67ce341365", "scanner": "scanner-primary", "fingerprint": "4ea7ad0b492628c7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8eaf9e7f02d3626e", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/partner/menu (QuickronsApp/src/lib/api.js:230)"}, "properties": {"repobilityId": "e8f334a11963a766", "scanner": "scanner-primary", "fingerprint": "8eaf9e7f02d3626e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d5717050ca118aeb", "level": "error", "message": {"text": "Dangling fetch: PATCH /api/v1/partner/menu/${id} (QuickronsApp/src/lib/api.js:232)"}, "properties": {"repobilityId": "bd7c0810fd3a0a38", "scanner": "scanner-primary", "fingerprint": "d5717050ca118aeb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-a9e31bf2d6207641", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/v1/partner/menu/${id} (QuickronsApp/src/lib/api.js:234)"}, "properties": {"repobilityId": "703d4a78a9b8956f", "scanner": "scanner-primary", "fingerprint": "a9e31bf2d6207641", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-76a47783f8a16cab", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/rider/me (QuickronsApp/src/lib/api.js:278)"}, "properties": {"repobilityId": "b792f309c9a934f4", "scanner": "scanner-primary", "fingerprint": "76a47783f8a16cab", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6671214c7fc1cbb5", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/rider/me/online (QuickronsApp/src/lib/api.js:280)"}, "properties": {"repobilityId": "a68399775f001d6d", "scanner": "scanner-primary", "fingerprint": "6671214c7fc1cbb5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-540e3dc92bb379b4", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/rider/orders/available (QuickronsApp/src/lib/api.js:282)"}, "properties": {"repobilityId": "3164861e03131e97", "scanner": "scanner-primary", "fingerprint": "540e3dc92bb379b4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3fe63fd60573a1e9", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/rider/me/orders${qs} (QuickronsApp/src/lib/api.js:285)"}, "properties": {"repobilityId": "7f26c11e6b75b0df", "scanner": "scanner-primary", "fingerprint": "3fe63fd60573a1e9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-35406215f68d65a2", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/rider/orders/${id}/accept (QuickronsApp/src/lib/api.js:288)"}, "properties": {"repobilityId": "4f006ec4034dd109", "scanner": "scanner-primary", "fingerprint": "35406215f68d65a2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5410407dfed72109", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/rider/orders/${id}/picked-up (QuickronsApp/src/lib/api.js:290)"}, "properties": {"repobilityId": "aca93137c13dd38b", "scanner": "scanner-primary", "fingerprint": "5410407dfed72109", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3f7c65fa8c728cba", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/rider/orders/${id}/delivered (QuickronsApp/src/lib/api.js:292)"}, "properties": {"repobilityId": "d6e3a807d9304ab3", "scanner": "scanner-primary", "fingerprint": "3f7c65fa8c728cba", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4c509af315ed723f", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/rider/wallet (QuickronsApp/src/lib/api.js:294)"}, "properties": {"repobilityId": "bc9895d4a1e45b72", "scanner": "scanner-primary", "fingerprint": "4c509af315ed723f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b46c08f514c44b73", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/orders${qs} (QuickronsApp/src/lib/api.js:302)"}, "properties": {"repobilityId": "89892673fa947e2c", "scanner": "scanner-primary", "fingerprint": "b46c08f514c44b73", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-661e7aceed56ce90", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/analytics (QuickronsApp/src/lib/api.js:305)"}, "properties": {"repobilityId": "009caf60d5c4b373", "scanner": "scanner-primary", "fingerprint": "661e7aceed56ce90", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ac786c35ac83fa82", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/wallets (QuickronsApp/src/lib/api.js:307)"}, "properties": {"repobilityId": "03960b71e814ca0e", "scanner": "scanner-primary", "fingerprint": "ac786c35ac83fa82", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f98d65669d26016e", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/partners (QuickronsApp/src/lib/api.js:309)"}, "properties": {"repobilityId": "75685717025d643c", "scanner": "scanner-primary", "fingerprint": "f98d65669d26016e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-716e797a89699d38", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/riders (QuickronsApp/src/lib/api.js:311)"}, "properties": {"repobilityId": "8375e23525ff9376", "scanner": "scanner-primary", "fingerprint": "716e797a89699d38", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c5489a505312a10e", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/admin/orders/${id}/cancel (QuickronsApp/src/lib/api.js:313)"}, "properties": {"repobilityId": "f6b4f13500448e31", "scanner": "scanner-primary", "fingerprint": "c5489a505312a10e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7d07181830b6e829", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/admin/orders/${id}/payment/mark-paid (QuickronsApp/src/lib/api.js:315)"}, "properties": {"repobilityId": "b88482d3f7e80a9c", "scanner": "scanner-primary", "fingerprint": "7d07181830b6e829", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e0b62dedfa95d734", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/admin/orders/${id}/payment/reject (QuickronsApp/src/lib/api.js:317)"}, "properties": {"repobilityId": "21c25b3e198220d0", "scanner": "scanner-primary", "fingerprint": "e0b62dedfa95d734", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b643eb1e986844cd", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/orders/stuck (QuickronsApp/src/lib/api.js:319)"}, "properties": {"repobilityId": "90a2c696c2f4dfd8", "scanner": "scanner-primary", "fingerprint": "b643eb1e986844cd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-68e0befb8239c8f0", "level": "error", "message": {"text": "Dangling fetch: GET /api/v1/admin/ratings?limit=50 (QuickronsApp/src/lib/api.js:321)"}, "properties": {"repobilityId": "6197ef7a9f41821c", "scanner": "scanner-primary", "fingerprint": "68e0befb8239c8f0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3bec7ccd0b909bea", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/auth"}, "properties": {"repobilityId": "8de8243b6c3e3be0", "scanner": "scanner-primary", "fingerprint": "3bec7ccd0b909bea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b641976b97f9f46", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/menu"}, "properties": {"repobilityId": "31aad71abefdf6b6", "scanner": "scanner-primary", "fingerprint": "1b641976b97f9f46", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bc490902ad849182", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/orders"}, "properties": {"repobilityId": "3ed9e20f18153326", "scanner": "scanner-primary", "fingerprint": "bc490902ad849182", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b3f1ebf385294f2", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/riders"}, "properties": {"repobilityId": "599c17f7d6a67138", "scanner": "scanner-primary", "fingerprint": "1b3f1ebf385294f2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b801ba178074486a", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/partners"}, "properties": {"repobilityId": "8fd791b0e1212a39", "scanner": "scanner-primary", "fingerprint": "b801ba178074486a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e72710ab38f6107b", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/customers"}, "properties": {"repobilityId": "bf8ed0abb3dc807a", "scanner": "scanner-primary", "fingerprint": "e72710ab38f6107b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0562818aae427bca", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/addresses"}, "properties": {"repobilityId": "1d5818ce8c6f31d5", "scanner": "scanner-primary", "fingerprint": "0562818aae427bca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c0510d224d50267e", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/kitchens"}, "properties": {"repobilityId": "277f47e7e0910dca", "scanner": "scanner-primary", "fingerprint": "c0510d224d50267e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-529f7e01f1f485a4", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/partner"}, "properties": {"repobilityId": "9f9b69586290684f", "scanner": "scanner-primary", "fingerprint": "529f7e01f1f485a4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a25220164abe0b09", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/rider"}, "properties": {"repobilityId": "340c280cda21494a", "scanner": "scanner-primary", "fingerprint": "a25220164abe0b09", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2cc7f440e42eac79", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1/admin"}, "properties": {"repobilityId": "0292f6e25503265c", "scanner": "scanner-primary", "fingerprint": "2cc7f440e42eac79", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2d8849fb6b1ac47", "level": "note", "message": {"text": "Unused endpoint: USE /admin"}, "properties": {"repobilityId": "92a750619c0437fd", "scanner": "scanner-primary", "fingerprint": "b2d8849fb6b1ac47", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bc898b3b7565990", "level": "note", "message": {"text": "Unused endpoint: USE /uploads"}, "properties": {"repobilityId": "6a761febc97f84d3", "scanner": "scanner-primary", "fingerprint": "1bc898b3b7565990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6685d40686d63393", "level": "note", "message": {"text": "Unused endpoint: GET /protected"}, "properties": {"repobilityId": "64b0c6567e03da90", "scanner": "scanner-primary", "fingerprint": "6685d40686d63393", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-953ec1a0ee6df50d", "level": "note", "message": {"text": "Unused endpoint: GET /admin"}, "properties": {"repobilityId": "289d96ef8cdac2eb", "scanner": "scanner-primary", "fingerprint": "953ec1a0ee6df50d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6236b283b79811b8", "level": "note", "message": {"text": "Unused endpoint: POST /upload"}, "properties": {"repobilityId": "4f791fc71de2087b", "scanner": "scanner-primary", "fingerprint": "6236b283b79811b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "ba5ba4d93e6acbf0", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea575b61c121b733", "level": "note", "message": {"text": "Unused endpoint: PATCH /me"}, "properties": {"repobilityId": "30296f9083c43369", "scanner": "scanner-primary", "fingerprint": "ea575b61c121b733", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c0df8ff151f6b3f6", "level": "note", "message": {"text": "Unused endpoint: GET /me/orders"}, "properties": {"repobilityId": "2c0f0e66043ec428", "scanner": "scanner-primary", "fingerprint": "c0df8ff151f6b3f6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a88e32ba95dda7c", "level": "note", "message": {"text": "Unused endpoint: POST /apply"}, "properties": {"repobilityId": "70477e836e060c04", "scanner": "scanner-primary", "fingerprint": "9a88e32ba95dda7c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-84b751e72dbdae91", "level": "note", "message": {"text": "Unused endpoint: GET /applications"}, "properties": {"repobilityId": "65feaa880dfd10f2", "scanner": "scanner-primary", "fingerprint": "84b751e72dbdae91", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bce5bddd09c8537", "level": "note", "message": {"text": "Unused endpoint: POST /applications/:id/status"}, "properties": {"repobilityId": "2d7e0d2d3a49b5b4", "scanner": "scanner-primary", "fingerprint": "1bce5bddd09c8537", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0328e9bdbb61fa68", "level": "note", "message": {"text": "Unused endpoint: GET /orders"}, "properties": {"repobilityId": "d40aa8828565aee8", "scanner": "scanner-primary", "fingerprint": "0328e9bdbb61fa68", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60fc1ff96f72a908", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/payment/mark-paid"}, "properties": {"repobilityId": "9198e4bd1aa6db1f", "scanner": "scanner-primary", "fingerprint": "60fc1ff96f72a908", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3872d067e687c52e", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/payment/reject"}, "properties": {"repobilityId": "4e5364c182420631", "scanner": "scanner-primary", "fingerprint": "3872d067e687c52e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0e0dd6830b7e9fd", "level": "note", "message": {"text": "Unused endpoint: GET /orders/stuck"}, "properties": {"repobilityId": "79ab673fe2c97452", "scanner": "scanner-primary", "fingerprint": "a0e0dd6830b7e9fd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0469dbf43c1a9621", "level": "note", "message": {"text": "Unused endpoint: GET /orders/:id"}, "properties": {"repobilityId": "f1dbba20815166bc", "scanner": "scanner-primary", "fingerprint": "0469dbf43c1a9621", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-090df84af01d788e", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/cancel"}, "properties": {"repobilityId": "67fe9f0339fb0679", "scanner": "scanner-primary", "fingerprint": "090df84af01d788e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a70c45950e6280f1", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/assign-rider"}, "properties": {"repobilityId": "c7d39c6642360d4d", "scanner": "scanner-primary", "fingerprint": "a70c45950e6280f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b2619d5118de8711", "level": "note", "message": {"text": "Unused endpoint: GET /partners"}, "properties": {"repobilityId": "cd911f1ed71f6444", "scanner": "scanner-primary", "fingerprint": "b2619d5118de8711", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-250dbd13097c1db7", "level": "note", "message": {"text": "Unused endpoint: POST /partners/:id/suspend"}, "properties": {"repobilityId": "616354a6151c150b", "scanner": "scanner-primary", "fingerprint": "250dbd13097c1db7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-06ed76ee925dc356", "level": "note", "message": {"text": "Unused endpoint: GET /riders"}, "properties": {"repobilityId": "156e34e26d7bfebc", "scanner": "scanner-primary", "fingerprint": "06ed76ee925dc356", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1726e9f33416858a", "level": "note", "message": {"text": "Unused endpoint: POST /riders/:id/suspend"}, "properties": {"repobilityId": "629cc16e22651e01", "scanner": "scanner-primary", "fingerprint": "1726e9f33416858a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dab50891d7bd7cf1", "level": "note", "message": {"text": "Unused endpoint: GET /wallets"}, "properties": {"repobilityId": "0eaac7f094041e31", "scanner": "scanner-primary", "fingerprint": "dab50891d7bd7cf1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4629fc2f2a182ac9", "level": "note", "message": {"text": "Unused endpoint: GET /analytics"}, "properties": {"repobilityId": "8902af78cad36d3a", "scanner": "scanner-primary", "fingerprint": "4629fc2f2a182ac9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0b31504b2943535", "level": "note", "message": {"text": "Unused endpoint: GET /ratings"}, "properties": {"repobilityId": "34d20dab2152b75a", "scanner": "scanner-primary", "fingerprint": "e0b31504b2943535", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "d1f60557f6ccbac2", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca5756175765b49d", "level": "note", "message": {"text": "Unused endpoint: GET /:id"}, "properties": {"repobilityId": "b44f0a427552e661", "scanner": "scanner-primary", "fingerprint": "ca5756175765b49d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0cb78db4e7bafb1c", "level": "note", "message": {"text": "Unused endpoint: POST /:id/cancel"}, "properties": {"repobilityId": "1d241ab66e9eae94", "scanner": "scanner-primary", "fingerprint": "0cb78db4e7bafb1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-447e8bc858284a26", "level": "note", "message": {"text": "Unused endpoint: POST /:id/contact"}, "properties": {"repobilityId": "fe1b161f8ee46a51", "scanner": "scanner-primary", "fingerprint": "447e8bc858284a26", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43c0d00a16a281e7", "level": "note", "message": {"text": "Unused endpoint: POST /:id/rating"}, "properties": {"repobilityId": "d40e3be423efca49", "scanner": "scanner-primary", "fingerprint": "43c0d00a16a281e7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "6a208fa47974c89e", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09d71208c4545c30", "level": "note", "message": {"text": "Unused endpoint: POST /:id/status"}, "properties": {"repobilityId": "cf59111d7596ea95", "scanner": "scanner-primary", "fingerprint": "09d71208c4545c30", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6351e20de3c7a488", "level": "note", "message": {"text": "Unused endpoint: GET /featured"}, "properties": {"repobilityId": "1d62ff75174afca7", "scanner": "scanner-primary", "fingerprint": "6351e20de3c7a488", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e17696780f3811f9", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/accept"}, "properties": {"repobilityId": "b1bbd9ce0e0b88f3", "scanner": "scanner-primary", "fingerprint": "e17696780f3811f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-789b7d797e982514", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/reject"}, "properties": {"repobilityId": "2580f5747de7b68b", "scanner": "scanner-primary", "fingerprint": "789b7d797e982514", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c8131979f4b44a56", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/preparing"}, "properties": {"repobilityId": "247cd07eed53e52e", "scanner": "scanner-primary", "fingerprint": "c8131979f4b44a56", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1579a654670c852a", "level": "note", "message": {"text": "Unused endpoint: POST /orders/:id/ready"}, "properties": {"repobilityId": "6da64f6969afd65c", "scanner": "scanner-primary", "fingerprint": "1579a654670c852a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-18579730be0a88bf", "level": "note", "message": {"text": "Unused endpoint: POST /menu/upload"}, "properties": {"repobilityId": "a64b164699c656bb", "scanner": "scanner-primary", "fingerprint": "18579730be0a88bf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-29e0ed54344aaa81", "level": "note", "message": {"text": "Unused endpoint: GET /menu"}, "properties": {"repobilityId": "ddc78a07ecdc3ccb", "scanner": "scanner-primary", "fingerprint": "29e0ed54344aaa81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}