{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-43a61c957333e753", "name": "Stray `console.log` in TS/JS \u2014 instrument.js:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 instrument.js:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2213f9c854068456", "name": "Stray `console.log` in TS/JS \u2014 scripts/cleanup-game.js:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/cleanup-game.js:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1de92372e8dcba83", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-follow-prompt.js:104", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-follow-prompt.js:104"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc7f6d4774b2711d", "name": "Stray `console.log` in TS/JS \u2014 scripts/printUserBucket.js:45", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/printUserBucket.js:45"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e866be88e7a9617", "name": "Stray `console.log` in TS/JS \u2014 scripts/backfill-followed-at.js:53", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-followed-at.js:53"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d6a5bf3e091aaff", "name": "Stray `console.log` in TS/JS \u2014 scripts/trigger-family-test.js:35", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/trigger-family-test.js:35"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28d2848d3e28a75d", "name": "Stray `console.log` in TS/JS \u2014 scripts/smoke-agenda.js:49", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/smoke-agenda.js:49"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d6a711b7fe30998", "name": "Stray `console.log` in TS/JS \u2014 scripts/trigger-real-notification.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/trigger-real-notification.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab5eb5d368962b54", "name": "Stray `console.log` in TS/JS \u2014 scripts/_listSubs.js:13", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/_listSubs.js:13"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e84b2957f9ffa52", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-admin-password.js:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-admin-password.js:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df51d039f0230d14", "name": "Stray `console.log` in TS/JS \u2014 scripts/reset-news-seen.js:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/reset-news-seen.js:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b49504a9dd5ee13", "name": "Stray `console.log` in TS/JS \u2014 scripts/_findUser.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/_findUser.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a70278e46fad7b88", "name": "Stray `console.log` in TS/JS \u2014 scripts/repair-missing-images.js:57", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/repair-missing-images.js:57"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7299ff9a3f966a63", "name": "Stray `console.log` in TS/JS \u2014 scripts/list-feed-types.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/list-feed-types.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b1511cf6fd622be", "name": "Stray `console.log` in TS/JS \u2014 scripts/test-notification.js:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-notification.js:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d48895e2d4900230", "name": "Stray `console.log` in TS/JS \u2014 coverage/prettify.js:2", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 coverage/prettify.js:2"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6240f941a3b056d2", "name": "Stray `console.log` in TS/JS \u2014 coverage/lcov-report/prettify.js:2", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 coverage/lcov-report/prettify.js:2"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f0dc834baf25425", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/views/feed-app/assets/index-7CEE7Y_I.js:33", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/views/feed-app/assets/index-7CEE7Y_I.js:33"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9f7df8552d21e4cb", "name": "Insecure pattern 'local_storage_auth_token' in web/src/api.ts:58", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in web/src/api.ts:58"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-25fda8c70eedf8c6", "name": "Insecure pattern 'direct_innerhtml_assignment' in coverage/sorter.js:84", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/sorter.js:84"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-63702a5241aaf793", "name": "Insecure pattern 'direct_innerhtml_assignment' in coverage/prettify.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/prettify.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-561cf4fb66e16a0c", "name": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/sorter.js:84", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/sorter.js:84"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d38ab4c821f6de46", "name": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/prettify.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/prettify.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e7b3f23e68a8b5ed", "name": "Insecure pattern 'local_storage_auth_token' in src/routes/auth.js:260", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/routes/auth.js:260"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cd94a9a4343e4c2c", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/views/admin.html:524", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/views/admin.html:524"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a05707580585ad8f", "name": "Insecure pattern 'direct_innerhtml_assignment' in src/views/feed-app/assets/index-7CEE7Y_I.js:37", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/views/feed-app/assets/index-7CEE7Y_I.js:37"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27cc4ac84092bbaf", "name": "Insecure pattern 'local_storage_auth_token' in src/views/feed-app/assets/index-7CEE7Y_I.js:40", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/views/feed-app/assets/index-7CEE7Y_I.js:40"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 166 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 17 placeholder/mock markers across 9 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a1d674e16fbe90f3", "name": "Commented-code block (5 lines) in server.js:11", "shortDescription": {"text": "Commented-code block (5 lines) in server.js:11"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ef72cf9e65d8906d", "name": "Commented-code block (5 lines) in tests/integration/routes/users.test.js:126", "shortDescription": {"text": "Commented-code block (5 lines) in tests/integration/routes/users.test.js:126"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-58ee860711fcb341", "name": "Commented-code block (5 lines) in tests/integration/routes/webApiAuth.test.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in tests/integration/routes/webApiAuth.test.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1b9d7bf0369a81d1", "name": "Legacy-named symbol `sLegacy` in tests/unit/services/newsRotationService.test.js:282", "shortDescription": {"text": "Legacy-named symbol `sLegacy` in tests/unit/services/newsRotationService.test.js:282"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f93f877203e1727", "name": "Commented-code block (5 lines) in web/src/api.ts:47", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/api.ts:47"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cba80aa5d2f34911", "name": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/api.ts:214", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/api.ts:214"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-78770e2888af0fc3", "name": "Commented-code block (7 lines) in web/src/auth.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in web/src/auth.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-495786625c733424", "name": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/auth.ts:58", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/auth.ts:58"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f38bdeaccd0cf3cd", "name": "Commented-code block (7 lines) in web/src/host.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in web/src/host.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-34ffe127aa057ec5", "name": "Commented-code block (5 lines) in web/src/format.ts:24", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/format.ts:24"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c4d693bc7e669d6", "name": "Commented-code block (5 lines) in web/src/useFollow.ts:24", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/useFollow.ts:24"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6e5618a4af47228e", "name": "Commented-code block (5 lines) in web/src/gameImage.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/gameImage.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c4a4e859a4600fc4", "name": "Commented-code block (6 lines) in web/src/App.tsx:59", "shortDescription": {"text": "Commented-code block (6 lines) in web/src/App.tsx:59"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a38402bf2c49652c", "name": "Commented-code block (5 lines) in web/src/useUnfollowGuard.ts:17", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/useUnfollowGuard.ts:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-216d606d7fe7f2cd", "name": "Commented-code block (5 lines) in web/src/components/GameRow.tsx:25", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/components/GameRow.tsx:25"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eacb2394ac65077a", "name": "Commented-code block (5 lines) in web/src/components/FollowBell.tsx:4", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/components/FollowBell.tsx:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-138b3a6d3a7d2d54", "name": "Commented-code block (5 lines) in web/src/tabs/ActuTab.tsx:205", "shortDescription": {"text": "Commented-code block (5 lines) in web/src/tabs/ActuTab.tsx:205"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7eb2376e81c90cab", "name": "Commented-code block (5 lines) in src/models/UserNewsState.js:25", "shortDescription": {"text": "Commented-code block (5 lines) in src/models/UserNewsState.js:25"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0bcf09c3672cd366", "name": "Commented-code block (7 lines) in src/models/User.js:154", "shortDescription": {"text": "Commented-code block (7 lines) in src/models/User.js:154"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e5cb95a7a628b587", "name": "Commented-code block (7 lines) in src/config/app.js:72", "shortDescription": {"text": "Commented-code block (7 lines) in src/config/app.js:72"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-33c6f08ee5661a7d", "name": "Commented-code block (5 lines) in src/middleware/webPairSecret.js:16", "shortDescription": {"text": "Commented-code block (5 lines) in src/middleware/webPairSecret.js:16"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-471d513d05e73a83", "name": "Commented-code block (6 lines) in src/routes/feedPage.js:42", "shortDescription": {"text": "Commented-code block (6 lines) in src/routes/feedPage.js:42"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e77e6fb58f7d5047", "name": "Commented-code block (10 lines) in src/routes/admin.js:52", "shortDescription": {"text": "Commented-code block (10 lines) in src/routes/admin.js:52"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4575f7762eebb1df", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/routes/admin.js:57", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/routes/admin.js:57"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9856b8442bd2ba2b", "name": "Commented-code block (6 lines) in src/routes/news.js:109", "shortDescription": {"text": "Commented-code block (6 lines) in src/routes/news.js:109"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8ac150fe18f7b7c6", "name": "Commented-code block (11 lines) in src/routes/auth.js:214", "shortDescription": {"text": "Commented-code block (11 lines) in src/routes/auth.js:214"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e9c295876b0949b3", "name": "Commented-code block (9 lines) in src/routes/webApi.js:37", "shortDescription": {"text": "Commented-code block (9 lines) in src/routes/webApi.js:37"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-284852addb1a25d9", "name": "Commented-code block (5 lines) in src/routes/users.js:40", "shortDescription": {"text": "Commented-code block (5 lines) in src/routes/users.js:40"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5bad2a1ebcda3d46", "name": "Commented-code block (5 lines) in src/services/newsRotationService.js:165", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/newsRotationService.js:165"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-17e81b75085c214b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/feedbackMailService.js:140", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/feedbackMailService.js:140"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c104257ca4504ad7", "name": "Commented-code block (5 lines) in src/services/desktopToastService.js:121", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/desktopToastService.js:121"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b0bfda7503f42c09", "name": "Commented-code block (5 lines) in src/services/newsFeedService.js:207", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/newsFeedService.js:207"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-09860ac30f982f15", "name": "Commented-code block (9 lines) in src/services/gamesSync/userProcessor.js:466", "shortDescription": {"text": "Commented-code block (9 lines) in src/services/gamesSync/userProcessor.js:466"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4decc5fb966cfb32", "name": "Commented-code block (5 lines) in src/services/newsFeed/newsProcessor.js:10", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/newsFeed/newsProcessor.js:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b3c9cc775e569ab3", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/feed-app/assets/index-7CEE7Y_I.js:1", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/feed-app/assets/index-7CEE7Y_I.js:1"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f808a4ef3e1071fb", "name": "14 env vars used in code but missing from .env.example", "shortDescription": {"text": "14 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `API_AUTH_KEY`, `APP_UPDATE_URL`, `BACKEND_DNS_SERVERS`, `CRON_GROUPS_TOTAL`, `CRON_TIMEZONE`, `FEEDBACK_FROM_EMAIL`, `FIREBASE_SERVICE_ACCOUNT_JSON`, `FIREBASE_SERVICE_ACCOUNT_PATH` + 6 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c93e5ab5cd42558a", "name": "Dangling fetch: GET https://store.steampowered.com/api/appdetails (src/services/steam/apiClient.js:239)", "shortDescription": {"text": "Dangling fetch: GET https://store.steampowered.com/api/appdetails (src/services/steam/apiClient.js:239)"}, "fullDescription": {"text": "`src/services/steam/apiClient.js:239` calls `GET https://store.steampowered.com/api/appdetails` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/store.steampowered.com/api/appdetails`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b5ddabfbf8991aa", "name": "Dangling fetch: GET https://steamcommunity.com/actions/SearchApps/${encodeURIComponent(query)} (src/services/steam/apiCl", "shortDescription": {"text": "Dangling fetch: GET https://steamcommunity.com/actions/SearchApps/${encodeURIComponent(query)} (src/services/steam/apiClient.js:310)"}, "fullDescription": {"text": "`src/services/steam/apiClient.js:310` calls `GET https://steamcommunity.com/actions/SearchApps/${encodeURIComponent(query)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/steamcommunity.com/actions/searchapps/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-faa755bf71287161", "name": "Dangling fetch: POST /api/feedback (src/views/feed-app/assets/index-7CEE7Y_I.js:40)", "shortDescription": {"text": "Dangling fetch: POST /api/feedback (src/views/feed-app/assets/index-7CEE7Y_I.js:40)"}, "fullDescription": {"text": "`src/views/feed-app/assets/index-7CEE7Y_I.js:40` calls `POST /api/feedback` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/feedback`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60308214e8579b0b", "name": "Dangling fetch: GET /api/steam/search?q=${encodeURIComponent(t)}&limit=20 (src/views/feed-app/assets/index-7CEE7Y_I.js:4", "shortDescription": {"text": "Dangling fetch: GET /api/steam/search?q=${encodeURIComponent(t)}&limit=20 (src/views/feed-app/assets/index-7CEE7Y_I.js:40)"}, "fullDescription": {"text": "`src/views/feed-app/assets/index-7CEE7Y_I.js:40` calls `GET /api/steam/search?q=${encodeURIComponent(t)}&limit=20` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/steam/search`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-836433293dd5d0e0", "name": "Dangling fetch: POST /auth/steam/start (src/views/feed-app/assets/index-7CEE7Y_I.js:40)", "shortDescription": {"text": "Dangling fetch: POST /auth/steam/start (src/views/feed-app/assets/index-7CEE7Y_I.js:40)"}, "fullDescription": {"text": "`src/views/feed-app/assets/index-7CEE7Y_I.js:40` calls `POST /auth/steam/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/steam/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-defc6dc6506c00c6", "name": "Dangling fetch: POST /api/feedback (web/src/api.ts:151)", "shortDescription": {"text": "Dangling fetch: POST /api/feedback (web/src/api.ts:151)"}, "fullDescription": {"text": "`web/src/api.ts:151` calls `POST /api/feedback` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/feedback`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ba5b021df36dfe6", "name": "Dangling fetch: GET /api/steam/search?q=${encodeURIComponent(q)}&limit=20 (web/src/api.ts:281)", "shortDescription": {"text": "Dangling fetch: GET /api/steam/search?q=${encodeURIComponent(q)}&limit=20 (web/src/api.ts:281)"}, "fullDescription": {"text": "`web/src/api.ts:281` calls `GET /api/steam/search?q=${encodeURIComponent(q)}&limit=20` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/steam/search`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-575fb0a6eaf8ee08", "name": "Dangling fetch: POST /auth/steam/start (web/src/auth.ts:58)", "shortDescription": {"text": "Dangling fetch: POST /auth/steam/start (web/src/auth.ts:58)"}, "fullDescription": {"text": "`web/src/auth.ts:58` calls `POST /auth/steam/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/auth/steam/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b2d8849fb6b1ac47", "name": "Unused endpoint: USE /admin", "shortDescription": {"text": "Unused endpoint: USE /admin"}, "fullDescription": {"text": "`server.js` declares `USE /admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`server.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f02a079c69b52f2d", "name": "Unused endpoint: USE /", "shortDescription": {"text": "Unused endpoint: USE /"}, "fullDescription": {"text": "`server.js` declares `USE /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1362bc9550078bb9", "name": "Unused endpoint: USE /feed-app", "shortDescription": {"text": "Unused endpoint: USE /feed-app"}, "fullDescription": {"text": "`server.js` declares `USE /feed-app` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b28d92215a503990", "name": "Unused endpoint: USE /auth", "shortDescription": {"text": "Unused endpoint: USE /auth"}, "fullDescription": {"text": "`server.js` declares `USE /auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09094aa309d68e72", "name": "Unused endpoint: USE /api/version", "shortDescription": {"text": "Unused endpoint: USE /api/version"}, "fullDescription": {"text": "`server.js` declares `USE /api/version` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ff40cb10f7c8519", "name": "Unused endpoint: USE /api/users", "shortDescription": {"text": "Unused endpoint: USE /api/users"}, "fullDescription": {"text": "`server.js` declares `USE /api/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f341e4d9d8b12a36", "name": "Unused endpoint: USE /api/news", "shortDescription": {"text": "Unused endpoint: USE /api/news"}, "fullDescription": {"text": "`server.js` declares `USE /api/news` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2aaf8a7b5042fce5", "name": "Unused endpoint: USE /api/web", "shortDescription": {"text": "Unused endpoint: USE /api/web"}, "fullDescription": {"text": "`server.js` declares `USE /api/web` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb6727a9e46c458c", "name": "Unused endpoint: USE /api/steam", "shortDescription": {"text": "Unused endpoint: USE /api/steam"}, "fullDescription": {"text": "`server.js` declares `USE /api/steam` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6c42c2627e519e8", "name": "Unused endpoint: USE /api/feedback", "shortDescription": {"text": "Unused endpoint: USE /api/feedback"}, "fullDescription": {"text": "`server.js` declares `USE /api/feedback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d93a530ce10d47d9", "name": "Unused endpoint: USE /api/admin", "shortDescription": {"text": "Unused endpoint: USE /api/admin"}, "fullDescription": {"text": "`server.js` declares `USE /api/admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46c26a891155c272", "name": "Unused endpoint: USE /api/debug", "shortDescription": {"text": "Unused endpoint: USE /api/debug"}, "fullDescription": {"text": "`server.js` declares `USE /api/debug` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9daee89b78e9ceac", "name": "Unused endpoint: GET /privacy", "shortDescription": {"text": "Unused endpoint: GET /privacy"}, "fullDescription": {"text": "`src/routes/legal.js` declares `GET /privacy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ebe3481a27b770a5", "name": "Unused endpoint: GET /terms", "shortDescription": {"text": "Unused endpoint: GET /terms"}, "fullDescription": {"text": "`src/routes/legal.js` declares `GET /terms` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a8337e51d1283cfe", "name": "Unused endpoint: GET /feed/:steamId", "shortDescription": {"text": "Unused endpoint: GET /feed/:steamId"}, "fullDescription": {"text": "`src/routes/feedPage.js` declares `GET /feed/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f2d978a040e04bd", "name": "Unused endpoint: GET /games/:steamId", "shortDescription": {"text": "Unused endpoint: GET /games/:steamId"}, "fullDescription": {"text": "`src/routes/steam.js` declares `GET /games/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f2cf00422934a87", "name": "Unused endpoint: GET /profile/:steamId", "shortDescription": {"text": "Unused endpoint: GET /profile/:steamId"}, "fullDescription": {"text": "`src/routes/steam.js` declares `GET /profile/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-05c31915e90cd4ce", "name": "Unused endpoint: GET /wishlist/:steamId", "shortDescription": {"text": "Unused endpoint: GET /wishlist/:steamId"}, "fullDescription": {"text": "`src/routes/steam.js` declares `GET /wishlist/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d16e4fa529c520e9", "name": "Unused endpoint: GET /search", "shortDescription": {"text": "Unused endpoint: GET /search"}, "fullDescription": {"text": "`src/routes/steam.js` declares `GET /search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82701814000677dd", "name": "Unused endpoint: POST /check-visibility/:steamId", "shortDescription": {"text": "Unused endpoint: POST /check-visibility/:steamId"}, "fullDescription": {"text": "`src/routes/steam.js` declares `POST /check-visibility/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-347290265681603c", "name": "Unused endpoint: POST /check-wishlist-visibility/:steamId", "shortDescription": {"text": "Unused endpoint: POST /check-wishlist-visibility/:steamId"}, "fullDescription": {"text": "`src/routes/steam.js` declares `POST /check-wishlist-visibility/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`src/routes/admin.js` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`src/routes/admin.js` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5032e3144ad00d34", "name": "Unused endpoint: GET /stats/overview", "shortDescription": {"text": "Unused endpoint: GET /stats/overview"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /stats/overview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-689a54d9330f8297", "name": "Unused endpoint: GET /stats/polling", "shortDescription": {"text": "Unused endpoint: GET /stats/polling"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /stats/polling` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb49685200445bb2", "name": "Unused endpoint: GET /stats/crons", "shortDescription": {"text": "Unused endpoint: GET /stats/crons"}, "fullDescription": {"text": "`src/routes/admin.js` declares `GET /stats/crons` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`src/routes/feedback.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3be6f8d515bb27e8", "name": "Unused endpoint: GET /game/:appId", "shortDescription": {"text": "Unused endpoint: GET /game/:appId"}, "fullDescription": {"text": "`src/routes/news.js` declares `GET /game/:appId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bfada129ce5bb026", "name": "Unused endpoint: GET /feed", "shortDescription": {"text": "Unused endpoint: GET /feed"}, "fullDescription": {"text": "`src/routes/news.js` declares `GET /feed` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf73b1b94a15568e", "name": "Unused endpoint: GET /feed-by-steamid/:steamId", "shortDescription": {"text": "Unused endpoint: GET /feed-by-steamid/:steamId"}, "fullDescription": {"text": "`src/routes/news.js` declares `GET /feed-by-steamid/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a4521b3e4b67418", "name": "Unused endpoint: GET /desktop-toasts/:steamId", "shortDescription": {"text": "Unused endpoint: GET /desktop-toasts/:steamId"}, "fullDescription": {"text": "`src/routes/news.js` declares `GET /desktop-toasts/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5bb7d07bba646a1", "name": "Unused endpoint: POST /steam/start", "shortDescription": {"text": "Unused endpoint: POST /steam/start"}, "fullDescription": {"text": "`src/routes/auth.js` declares `POST /steam/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0f28c885e36843c0", "name": "Unused endpoint: GET /steam/status/:authToken", "shortDescription": {"text": "Unused endpoint: GET /steam/status/:authToken"}, "fullDescription": {"text": "`src/routes/auth.js` declares `GET /steam/status/:authToken` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8c1c9bca48cd934", "name": "Unused endpoint: GET /steam/return", "shortDescription": {"text": "Unused endpoint: GET /steam/return"}, "fullDescription": {"text": "`src/routes/auth.js` declares `GET /steam/return` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c31bc3c0bf684b6a", "name": "Unused endpoint: GET /access", "shortDescription": {"text": "Unused endpoint: GET /access"}, "fullDescription": {"text": "`src/routes/mobileAdmin.js` declares `GET /access` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c0733182c5ef4e97", "name": "Unused endpoint: POST /refresh-account", "shortDescription": {"text": "Unused endpoint: POST /refresh-account"}, "fullDescription": {"text": "`src/routes/mobileAdmin.js` declares `POST /refresh-account` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f279069c5e862217", "name": "Unused endpoint: GET /pair", "shortDescription": {"text": "Unused endpoint: GET /pair"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /pair` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e343c1fa58c93a21", "name": "Unused endpoint: POST /pair", "shortDescription": {"text": "Unused endpoint: POST /pair"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `POST /pair` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d4181f465597e93", "name": "Unused endpoint: GET /heartbeat/:steamId", "shortDescription": {"text": "Unused endpoint: GET /heartbeat/:steamId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /heartbeat/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141259381bdcd44f", "name": "Unused endpoint: GET /follow-prompts/:steamId", "shortDescription": {"text": "Unused endpoint: GET /follow-prompts/:steamId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /follow-prompts/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-490baf05c72cdecd", "name": "Unused endpoint: GET /settings/:steamId", "shortDescription": {"text": "Unused endpoint: GET /settings/:steamId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /settings/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d461b8a973d7a80d", "name": "Unused endpoint: GET /follow", "shortDescription": {"text": "Unused endpoint: GET /follow"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /follow` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e494a389a6f2b3e", "name": "Unused endpoint: POST /follow", "shortDescription": {"text": "Unused endpoint: POST /follow"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `POST /follow` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b1b5b9ea0beae452", "name": "Unused endpoint: GET /follow-state/:steamId/:appId", "shortDescription": {"text": "Unused endpoint: GET /follow-state/:steamId/:appId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /follow-state/:steamId/:appId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06b0ae96e72fe993", "name": "Unused endpoint: GET /follow-notifications/:steamId/:appId", "shortDescription": {"text": "Unused endpoint: GET /follow-notifications/:steamId/:appId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /follow-notifications/:steamId/:appId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9500263f7cde8da9", "name": "Unused endpoint: POST /follow-notifications/:steamId/:appId", "shortDescription": {"text": "Unused endpoint: POST /follow-notifications/:steamId/:appId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `POST /follow-notifications/:steamId/:appId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-949f074ffe2be361", "name": "Unused endpoint: GET /register/:steamId", "shortDescription": {"text": "Unused endpoint: GET /register/:steamId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `GET /register/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8de1234e2a5e16", "name": "Unused endpoint: POST /register/:steamId", "shortDescription": {"text": "Unused endpoint: POST /register/:steamId"}, "fullDescription": {"text": "`src/routes/webApi.js` declares `POST /register/:steamId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23141"}, "properties": {"repository": "YannisFouzi/SteamActu-Back", "repoUrl": "https://github.com/YannisFouzi/SteamActu-Back", "branch": "main"}, "results": [{"ruleId": "scanner-43a61c957333e753", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 instrument.js:26"}, "properties": {"repobilityId": "02fb7cbd753c6973", "scanner": "scanner-primary", "fingerprint": "43a61c957333e753", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2213f9c854068456", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/cleanup-game.js:33"}, "properties": {"repobilityId": "16cfa708f2685c4d", "scanner": "scanner-primary", "fingerprint": "2213f9c854068456", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1de92372e8dcba83", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-follow-prompt.js:104"}, "properties": {"repobilityId": "b5bc573f14815484", "scanner": "scanner-primary", "fingerprint": "1de92372e8dcba83", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cc7f6d4774b2711d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/printUserBucket.js:45"}, "properties": {"repobilityId": "03f6d80eb07a5439", "scanner": "scanner-primary", "fingerprint": "cc7f6d4774b2711d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7e866be88e7a9617", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/backfill-followed-at.js:53"}, "properties": {"repobilityId": "d2ccdfacfdcc1567", "scanner": "scanner-primary", "fingerprint": "7e866be88e7a9617", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4d6a5bf3e091aaff", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/trigger-family-test.js:35"}, "properties": {"repobilityId": "9c7d5aee2fc4fa15", "scanner": "scanner-primary", "fingerprint": "4d6a5bf3e091aaff", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-28d2848d3e28a75d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/smoke-agenda.js:49"}, "properties": {"repobilityId": "98d1a376c9f98b76", "scanner": "scanner-primary", "fingerprint": "28d2848d3e28a75d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5d6a711b7fe30998", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/trigger-real-notification.js:20"}, "properties": {"repobilityId": "b15969fdce71a217", "scanner": "scanner-primary", "fingerprint": "5d6a711b7fe30998", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ab5eb5d368962b54", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/_listSubs.js:13"}, "properties": {"repobilityId": "9de02a216ca896a3", "scanner": "scanner-primary", "fingerprint": "ab5eb5d368962b54", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2e84b2957f9ffa52", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-admin-password.js:26"}, "properties": {"repobilityId": "cdffb9d2860a3003", "scanner": "scanner-primary", "fingerprint": "2e84b2957f9ffa52", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-df51d039f0230d14", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/reset-news-seen.js:12"}, "properties": {"repobilityId": "662e23ac4135953a", "scanner": "scanner-primary", "fingerprint": "df51d039f0230d14", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2b49504a9dd5ee13", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/_findUser.js:20"}, "properties": {"repobilityId": "10d2cf23198a230d", "scanner": "scanner-primary", "fingerprint": "2b49504a9dd5ee13", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a70278e46fad7b88", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/repair-missing-images.js:57"}, "properties": {"repobilityId": "4ab0dc01e2524aa6", "scanner": "scanner-primary", "fingerprint": "a70278e46fad7b88", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7299ff9a3f966a63", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/list-feed-types.js:41"}, "properties": {"repobilityId": "38e3b706bfa52c4e", "scanner": "scanner-primary", "fingerprint": "7299ff9a3f966a63", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5b1511cf6fd622be", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/test-notification.js:33"}, "properties": {"repobilityId": "b817be4184535e0f", "scanner": "scanner-primary", "fingerprint": "5b1511cf6fd622be", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d48895e2d4900230", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 coverage/prettify.js:2"}, "properties": {"repobilityId": "7ae131d34d4f067b", "scanner": "scanner-primary", "fingerprint": "d48895e2d4900230", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6240f941a3b056d2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 coverage/lcov-report/prettify.js:2"}, "properties": {"repobilityId": "f5469c712b31777f", "scanner": "scanner-primary", "fingerprint": "6240f941a3b056d2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3f0dc834baf25425", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/views/feed-app/assets/index-7CEE7Y_I.js:33"}, "properties": {"repobilityId": "c26999104b31b692", "scanner": "scanner-primary", "fingerprint": "3f0dc834baf25425", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-9f7df8552d21e4cb", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in web/src/api.ts:58"}, "properties": {"repobilityId": "6519df9a116097f6", "scanner": "scanner-primary", "fingerprint": "9f7df8552d21e4cb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "web/src/api.ts"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-25fda8c70eedf8c6", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/sorter.js:84"}, "properties": {"repobilityId": "39766a562195c1af", "scanner": "scanner-primary", "fingerprint": "25fda8c70eedf8c6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "coverage/sorter.js"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-63702a5241aaf793", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/prettify.js:2"}, "properties": {"repobilityId": "bf1b26c03160b291", "scanner": "scanner-primary", "fingerprint": "63702a5241aaf793", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "coverage/prettify.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-561cf4fb66e16a0c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/sorter.js:84"}, "properties": {"repobilityId": "3e42e111e0f73064", "scanner": "scanner-primary", "fingerprint": "561cf4fb66e16a0c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "coverage/lcov-report/sorter.js"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-d38ab4c821f6de46", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/prettify.js:2"}, "properties": {"repobilityId": "f20a7741f511e6ea", "scanner": "scanner-primary", "fingerprint": "d38ab4c821f6de46", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "coverage/lcov-report/prettify.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-e7b3f23e68a8b5ed", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/routes/auth.js:260"}, "properties": {"repobilityId": "39a2ced8f11c5a76", "scanner": "scanner-primary", "fingerprint": "e7b3f23e68a8b5ed", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/auth.js"}, "region": {"startLine": 260}}}]}, {"ruleId": "scanner-cd94a9a4343e4c2c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/views/admin.html:524"}, "properties": {"repobilityId": "86c72b097aa60203", "scanner": "scanner-primary", "fingerprint": "cd94a9a4343e4c2c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/views/admin.html"}, "region": {"startLine": 524}}}]}, {"ruleId": "scanner-a05707580585ad8f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in src/views/feed-app/assets/index-7CEE7Y_I.js:37"}, "properties": {"repobilityId": "ac6b01e40a67f173", "scanner": "scanner-primary", "fingerprint": "a05707580585ad8f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/views/feed-app/assets/index-7CEE7Y_I.js"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-27cc4ac84092bbaf", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/views/feed-app/assets/index-7CEE7Y_I.js:40"}, "properties": {"repobilityId": "61d7057b7e1e66ea", "scanner": "scanner-primary", "fingerprint": "27cc4ac84092bbaf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/views/feed-app/assets/index-7CEE7Y_I.js"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "3b196d30a935904c", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "27ab8b2b89baa5d8", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "0f4178b13757e26b", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "d4b8519319608a3c", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "155089070233a790", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "53fe5680885642c4", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "9cbe0374f6fa4a8b", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-a1d674e16fbe90f3", "level": "none", "message": {"text": "Commented-code block (5 lines) in server.js:11"}, "properties": {"repobilityId": "ffdda70a4301b64a", "scanner": "scanner-primary", "fingerprint": "a1d674e16fbe90f3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ef72cf9e65d8906d", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/integration/routes/users.test.js:126"}, "properties": {"repobilityId": "b8bbce8d48e91e78", "scanner": "scanner-primary", "fingerprint": "ef72cf9e65d8906d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-58ee860711fcb341", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/integration/routes/webApiAuth.test.js:1"}, "properties": {"repobilityId": "f75bc338f44bf7c5", "scanner": "scanner-primary", "fingerprint": "58ee860711fcb341", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1b9d7bf0369a81d1", "level": "note", "message": {"text": "Legacy-named symbol `sLegacy` in tests/unit/services/newsRotationService.test.js:282"}, "properties": {"repobilityId": "0a5f1ee05e07ea77", "scanner": "scanner-primary", "fingerprint": "1b9d7bf0369a81d1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3f93f877203e1727", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/api.ts:47"}, "properties": {"repobilityId": "2a47892206e4cb5b", "scanner": "scanner-primary", "fingerprint": "3f93f877203e1727", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cba80aa5d2f34911", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/api.ts:214"}, "properties": {"repobilityId": "11c9c9e904a3d048", "scanner": "scanner-primary", "fingerprint": "cba80aa5d2f34911", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-78770e2888af0fc3", "level": "none", "message": {"text": "Commented-code block (7 lines) in web/src/auth.ts:1"}, "properties": {"repobilityId": "634555955d35a121", "scanner": "scanner-primary", "fingerprint": "78770e2888af0fc3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-495786625c733424", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 web/src/auth.ts:58"}, "properties": {"repobilityId": "d41331e5a357cc97", "scanner": "scanner-primary", "fingerprint": "495786625c733424", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f38bdeaccd0cf3cd", "level": "none", "message": {"text": "Commented-code block (7 lines) in web/src/host.ts:1"}, "properties": {"repobilityId": "72946dee6088bc47", "scanner": "scanner-primary", "fingerprint": "f38bdeaccd0cf3cd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-34ffe127aa057ec5", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/format.ts:24"}, "properties": {"repobilityId": "cf2687e524339ea0", "scanner": "scanner-primary", "fingerprint": "34ffe127aa057ec5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0c4d693bc7e669d6", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/useFollow.ts:24"}, "properties": {"repobilityId": "94965e85299c6196", "scanner": "scanner-primary", "fingerprint": "0c4d693bc7e669d6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6e5618a4af47228e", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/gameImage.ts:1"}, "properties": {"repobilityId": "2949b5a965aec79d", "scanner": "scanner-primary", "fingerprint": "6e5618a4af47228e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c4a4e859a4600fc4", "level": "none", "message": {"text": "Commented-code block (6 lines) in web/src/App.tsx:59"}, "properties": {"repobilityId": "7e53a437d716c41d", "scanner": "scanner-primary", "fingerprint": "c4a4e859a4600fc4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a38402bf2c49652c", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/useUnfollowGuard.ts:17"}, "properties": {"repobilityId": "816d3d6ad91b86ef", "scanner": "scanner-primary", "fingerprint": "a38402bf2c49652c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-216d606d7fe7f2cd", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/components/GameRow.tsx:25"}, "properties": {"repobilityId": "e5648c456afdae60", "scanner": "scanner-primary", "fingerprint": "216d606d7fe7f2cd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-eacb2394ac65077a", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/components/FollowBell.tsx:4"}, "properties": {"repobilityId": "34877e921a40b02e", "scanner": "scanner-primary", "fingerprint": "eacb2394ac65077a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-138b3a6d3a7d2d54", "level": "none", "message": {"text": "Commented-code block (5 lines) in web/src/tabs/ActuTab.tsx:205"}, "properties": {"repobilityId": "9d9b020c1c57fb6f", "scanner": "scanner-primary", "fingerprint": "138b3a6d3a7d2d54", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7eb2376e81c90cab", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/models/UserNewsState.js:25"}, "properties": {"repobilityId": "211b09a40a4fc6bb", "scanner": "scanner-primary", "fingerprint": "7eb2376e81c90cab", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0bcf09c3672cd366", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/models/User.js:154"}, "properties": {"repobilityId": "a72629d4db034fab", "scanner": "scanner-primary", "fingerprint": "0bcf09c3672cd366", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e5cb95a7a628b587", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/config/app.js:72"}, "properties": {"repobilityId": "e69c88bfc9a23608", "scanner": "scanner-primary", "fingerprint": "e5cb95a7a628b587", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-33c6f08ee5661a7d", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/middleware/webPairSecret.js:16"}, "properties": {"repobilityId": "4b7691170bc629b4", "scanner": "scanner-primary", "fingerprint": "33c6f08ee5661a7d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-471d513d05e73a83", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/routes/feedPage.js:42"}, "properties": {"repobilityId": "4137ab8e08b2fe4d", "scanner": "scanner-primary", "fingerprint": "471d513d05e73a83", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e77e6fb58f7d5047", "level": "none", "message": {"text": "Commented-code block (10 lines) in src/routes/admin.js:52"}, "properties": {"repobilityId": "78af2513011fe02a", "scanner": "scanner-primary", "fingerprint": "e77e6fb58f7d5047", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4575f7762eebb1df", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/routes/admin.js:57"}, "properties": {"repobilityId": "1cc377756c34996a", "scanner": "scanner-primary", "fingerprint": "4575f7762eebb1df", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9856b8442bd2ba2b", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/routes/news.js:109"}, "properties": {"repobilityId": "9ac7f5cb538352ff", "scanner": "scanner-primary", "fingerprint": "9856b8442bd2ba2b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8ac150fe18f7b7c6", "level": "none", "message": {"text": "Commented-code block (11 lines) in src/routes/auth.js:214"}, "properties": {"repobilityId": "ac100bc61f7836f9", "scanner": "scanner-primary", "fingerprint": "8ac150fe18f7b7c6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e9c295876b0949b3", "level": "none", "message": {"text": "Commented-code block (9 lines) in src/routes/webApi.js:37"}, "properties": {"repobilityId": "fe7e891070138779", "scanner": "scanner-primary", "fingerprint": "e9c295876b0949b3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-284852addb1a25d9", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/routes/users.js:40"}, "properties": {"repobilityId": "5e06985c53ed751a", "scanner": "scanner-primary", "fingerprint": "284852addb1a25d9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5bad2a1ebcda3d46", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/newsRotationService.js:165"}, "properties": {"repobilityId": "794d83694bee3ac2", "scanner": "scanner-primary", "fingerprint": "5bad2a1ebcda3d46", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-17e81b75085c214b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/feedbackMailService.js:140"}, "properties": {"repobilityId": "a061461e1d84ee31", "scanner": "scanner-primary", "fingerprint": "17e81b75085c214b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c104257ca4504ad7", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/desktopToastService.js:121"}, "properties": {"repobilityId": "3441434fad1947f2", "scanner": "scanner-primary", "fingerprint": "c104257ca4504ad7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b0bfda7503f42c09", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/newsFeedService.js:207"}, "properties": {"repobilityId": "abc0a44e2f4cf483", "scanner": "scanner-primary", "fingerprint": "b0bfda7503f42c09", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-09860ac30f982f15", "level": "none", "message": {"text": "Commented-code block (9 lines) in src/services/gamesSync/userProcessor.js:466"}, "properties": {"repobilityId": "bf9091b226b33aee", "scanner": "scanner-primary", "fingerprint": "09860ac30f982f15", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4decc5fb966cfb32", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/newsFeed/newsProcessor.js:10"}, "properties": {"repobilityId": "d3209868d8a44cfe", "scanner": "scanner-primary", "fingerprint": "4decc5fb966cfb32", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b3c9cc775e569ab3", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/feed-app/assets/index-7CEE7Y_I.js:1"}, "properties": {"repobilityId": "1e21910876b8cb8e", "scanner": "scanner-primary", "fingerprint": "b3c9cc775e569ab3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f808a4ef3e1071fb", "level": "note", "message": {"text": "14 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "ce6b2ec4be4ec75a", "scanner": "scanner-primary", "fingerprint": "f808a4ef3e1071fb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-c93e5ab5cd42558a", "level": "error", "message": {"text": "Dangling fetch: GET https://store.steampowered.com/api/appdetails (src/services/steam/apiClient.js:239)"}, "properties": {"repobilityId": "1373dee6f5a91243", "scanner": "scanner-primary", "fingerprint": "c93e5ab5cd42558a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-1b5ddabfbf8991aa", "level": "error", "message": {"text": "Dangling fetch: GET https://steamcommunity.com/actions/SearchApps/${encodeURIComponent(query)} (src/services/steam/apiClient.js:310)"}, "properties": {"repobilityId": "4437da8eac210805", "scanner": "scanner-primary", "fingerprint": "1b5ddabfbf8991aa", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-faa755bf71287161", "level": "error", "message": {"text": "Dangling fetch: POST /api/feedback (src/views/feed-app/assets/index-7CEE7Y_I.js:40)"}, "properties": {"repobilityId": "eca670d79fe5fc43", "scanner": "scanner-primary", "fingerprint": "faa755bf71287161", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-60308214e8579b0b", "level": "error", "message": {"text": "Dangling fetch: GET /api/steam/search?q=${encodeURIComponent(t)}&limit=20 (src/views/feed-app/assets/index-7CEE7Y_I.js:40)"}, "properties": {"repobilityId": "645ec23ba22ba330", "scanner": "scanner-primary", "fingerprint": "60308214e8579b0b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-836433293dd5d0e0", "level": "error", "message": {"text": "Dangling fetch: POST /auth/steam/start (src/views/feed-app/assets/index-7CEE7Y_I.js:40)"}, "properties": {"repobilityId": "7de72b2c26672e5f", "scanner": "scanner-primary", "fingerprint": "836433293dd5d0e0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-defc6dc6506c00c6", "level": "error", "message": {"text": "Dangling fetch: POST /api/feedback (web/src/api.ts:151)"}, "properties": {"repobilityId": "c10e99d700a5029e", "scanner": "scanner-primary", "fingerprint": "defc6dc6506c00c6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9ba5b021df36dfe6", "level": "error", "message": {"text": "Dangling fetch: GET /api/steam/search?q=${encodeURIComponent(q)}&limit=20 (web/src/api.ts:281)"}, "properties": {"repobilityId": "b7bbc612e05dc6df", "scanner": "scanner-primary", "fingerprint": "9ba5b021df36dfe6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-575fb0a6eaf8ee08", "level": "error", "message": {"text": "Dangling fetch: POST /auth/steam/start (web/src/auth.ts:58)"}, "properties": {"repobilityId": "e064f4165a0e9847", "scanner": "scanner-primary", "fingerprint": "575fb0a6eaf8ee08", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b2d8849fb6b1ac47", "level": "note", "message": {"text": "Unused endpoint: USE /admin"}, "properties": {"repobilityId": "2752bb9f19ba5dbb", "scanner": "scanner-primary", "fingerprint": "b2d8849fb6b1ac47", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9b883326e67da4e4", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f02a079c69b52f2d", "level": "note", "message": {"text": "Unused endpoint: USE /"}, "properties": {"repobilityId": "11b055fa2670dbdf", "scanner": "scanner-primary", "fingerprint": "f02a079c69b52f2d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1362bc9550078bb9", "level": "note", "message": {"text": "Unused endpoint: USE /feed-app"}, "properties": {"repobilityId": "7e8b0f21c83de29d", "scanner": "scanner-primary", "fingerprint": "1362bc9550078bb9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b28d92215a503990", "level": "note", "message": {"text": "Unused endpoint: USE /auth"}, "properties": {"repobilityId": "3d8cc00505339c17", "scanner": "scanner-primary", "fingerprint": "b28d92215a503990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09094aa309d68e72", "level": "note", "message": {"text": "Unused endpoint: USE /api/version"}, "properties": {"repobilityId": "c487ee1fc1cf8e2c", "scanner": "scanner-primary", "fingerprint": "09094aa309d68e72", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ff40cb10f7c8519", "level": "note", "message": {"text": "Unused endpoint: USE /api/users"}, "properties": {"repobilityId": "4e24dcf29e3db514", "scanner": "scanner-primary", "fingerprint": "4ff40cb10f7c8519", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f341e4d9d8b12a36", "level": "note", "message": {"text": "Unused endpoint: USE /api/news"}, "properties": {"repobilityId": "d97b2e89b540b687", "scanner": "scanner-primary", "fingerprint": "f341e4d9d8b12a36", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2aaf8a7b5042fce5", "level": "note", "message": {"text": "Unused endpoint: USE /api/web"}, "properties": {"repobilityId": "809ff2c991d46649", "scanner": "scanner-primary", "fingerprint": "2aaf8a7b5042fce5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bb6727a9e46c458c", "level": "note", "message": {"text": "Unused endpoint: USE /api/steam"}, "properties": {"repobilityId": "660979fdfc0b5351", "scanner": "scanner-primary", "fingerprint": "bb6727a9e46c458c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e6c42c2627e519e8", "level": "note", "message": {"text": "Unused endpoint: USE /api/feedback"}, "properties": {"repobilityId": "f518f28073c1beea", "scanner": "scanner-primary", "fingerprint": "e6c42c2627e519e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d93a530ce10d47d9", "level": "note", "message": {"text": "Unused endpoint: USE /api/admin"}, "properties": {"repobilityId": "7cf1ce4709c13e8a", "scanner": "scanner-primary", "fingerprint": "d93a530ce10d47d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-46c26a891155c272", "level": "note", "message": {"text": "Unused endpoint: USE /api/debug"}, "properties": {"repobilityId": "c7c1b076fc65d563", "scanner": "scanner-primary", "fingerprint": "46c26a891155c272", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9daee89b78e9ceac", "level": "note", "message": {"text": "Unused endpoint: GET /privacy"}, "properties": {"repobilityId": "066b93bfdabf13b0", "scanner": "scanner-primary", "fingerprint": "9daee89b78e9ceac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ebe3481a27b770a5", "level": "note", "message": {"text": "Unused endpoint: GET /terms"}, "properties": {"repobilityId": "15e6bd28578a2d87", "scanner": "scanner-primary", "fingerprint": "ebe3481a27b770a5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a8337e51d1283cfe", "level": "note", "message": {"text": "Unused endpoint: GET /feed/:steamId"}, "properties": {"repobilityId": "53d309939c7f743a", "scanner": "scanner-primary", "fingerprint": "a8337e51d1283cfe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0f2d978a040e04bd", "level": "note", "message": {"text": "Unused endpoint: GET /games/:steamId"}, "properties": {"repobilityId": "f05cb6b93041a89c", "scanner": "scanner-primary", "fingerprint": "0f2d978a040e04bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f2cf00422934a87", "level": "note", "message": {"text": "Unused endpoint: GET /profile/:steamId"}, "properties": {"repobilityId": "638097266ef20aad", "scanner": "scanner-primary", "fingerprint": "2f2cf00422934a87", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-05c31915e90cd4ce", "level": "note", "message": {"text": "Unused endpoint: GET /wishlist/:steamId"}, "properties": {"repobilityId": "c68f7b2cf8d2634e", "scanner": "scanner-primary", "fingerprint": "05c31915e90cd4ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d16e4fa529c520e9", "level": "note", "message": {"text": "Unused endpoint: GET /search"}, "properties": {"repobilityId": "5973784426b3f87e", "scanner": "scanner-primary", "fingerprint": "d16e4fa529c520e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-82701814000677dd", "level": "note", "message": {"text": "Unused endpoint: POST /check-visibility/:steamId"}, "properties": {"repobilityId": "7aa447ffa5ec9c65", "scanner": "scanner-primary", "fingerprint": "82701814000677dd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-347290265681603c", "level": "note", "message": {"text": "Unused endpoint: POST /check-wishlist-visibility/:steamId"}, "properties": {"repobilityId": "3c3bef6660dafed7", "scanner": "scanner-primary", "fingerprint": "347290265681603c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "3b8ca51b571a953f", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "5ab83e10f84fb18f", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "fe6fb0ed375ee8fc", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5032e3144ad00d34", "level": "note", "message": {"text": "Unused endpoint: GET /stats/overview"}, "properties": {"repobilityId": "f1665cfb89b95c29", "scanner": "scanner-primary", "fingerprint": "5032e3144ad00d34", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-689a54d9330f8297", "level": "note", "message": {"text": "Unused endpoint: GET /stats/polling"}, "properties": {"repobilityId": "bd9a89cd0a8249b0", "scanner": "scanner-primary", "fingerprint": "689a54d9330f8297", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fb49685200445bb2", "level": "note", "message": {"text": "Unused endpoint: GET /stats/crons"}, "properties": {"repobilityId": "130e9fdfb5be66c5", "scanner": "scanner-primary", "fingerprint": "fb49685200445bb2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "be5d5f0b80f0315d", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3be6f8d515bb27e8", "level": "note", "message": {"text": "Unused endpoint: GET /game/:appId"}, "properties": {"repobilityId": "a5120c31491ef7e1", "scanner": "scanner-primary", "fingerprint": "3be6f8d515bb27e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bfada129ce5bb026", "level": "note", "message": {"text": "Unused endpoint: GET /feed"}, "properties": {"repobilityId": "7b11132bc6b0d255", "scanner": "scanner-primary", "fingerprint": "bfada129ce5bb026", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cf73b1b94a15568e", "level": "note", "message": {"text": "Unused endpoint: GET /feed-by-steamid/:steamId"}, "properties": {"repobilityId": "186fbe9bcccc227b", "scanner": "scanner-primary", "fingerprint": "cf73b1b94a15568e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5a4521b3e4b67418", "level": "note", "message": {"text": "Unused endpoint: GET /desktop-toasts/:steamId"}, "properties": {"repobilityId": "575679cc2080ff9c", "scanner": "scanner-primary", "fingerprint": "5a4521b3e4b67418", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a5bb7d07bba646a1", "level": "note", "message": {"text": "Unused endpoint: POST /steam/start"}, "properties": {"repobilityId": "03c6466c26323ea0", "scanner": "scanner-primary", "fingerprint": "a5bb7d07bba646a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0f28c885e36843c0", "level": "note", "message": {"text": "Unused endpoint: GET /steam/status/:authToken"}, "properties": {"repobilityId": "5f7ee5a1b70ee4e0", "scanner": "scanner-primary", "fingerprint": "0f28c885e36843c0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d8c1c9bca48cd934", "level": "note", "message": {"text": "Unused endpoint: GET /steam/return"}, "properties": {"repobilityId": "9c2341e1181f10f6", "scanner": "scanner-primary", "fingerprint": "d8c1c9bca48cd934", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c31bc3c0bf684b6a", "level": "note", "message": {"text": "Unused endpoint: GET /access"}, "properties": {"repobilityId": "273eb6070c6ccb7c", "scanner": "scanner-primary", "fingerprint": "c31bc3c0bf684b6a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c0733182c5ef4e97", "level": "note", "message": {"text": "Unused endpoint: POST /refresh-account"}, "properties": {"repobilityId": "1e4c77308803f0d1", "scanner": "scanner-primary", "fingerprint": "c0733182c5ef4e97", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f279069c5e862217", "level": "note", "message": {"text": "Unused endpoint: GET /pair"}, "properties": {"repobilityId": "d6005606adbed5bf", "scanner": "scanner-primary", "fingerprint": "f279069c5e862217", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e343c1fa58c93a21", "level": "note", "message": {"text": "Unused endpoint: POST /pair"}, "properties": {"repobilityId": "574538a73514836c", "scanner": "scanner-primary", "fingerprint": "e343c1fa58c93a21", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d4181f465597e93", "level": "note", "message": {"text": "Unused endpoint: GET /heartbeat/:steamId"}, "properties": {"repobilityId": "65a9e39949f1be78", "scanner": "scanner-primary", "fingerprint": "5d4181f465597e93", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-141259381bdcd44f", "level": "note", "message": {"text": "Unused endpoint: GET /follow-prompts/:steamId"}, "properties": {"repobilityId": "61377fba64aa537d", "scanner": "scanner-primary", "fingerprint": "141259381bdcd44f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-490baf05c72cdecd", "level": "note", "message": {"text": "Unused endpoint: GET /settings/:steamId"}, "properties": {"repobilityId": "33d53f6b02e68892", "scanner": "scanner-primary", "fingerprint": "490baf05c72cdecd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d461b8a973d7a80d", "level": "note", "message": {"text": "Unused endpoint: GET /follow"}, "properties": {"repobilityId": "bbae90302a2dec73", "scanner": "scanner-primary", "fingerprint": "d461b8a973d7a80d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2e494a389a6f2b3e", "level": "note", "message": {"text": "Unused endpoint: POST /follow"}, "properties": {"repobilityId": "54f7c1c761496415", "scanner": "scanner-primary", "fingerprint": "2e494a389a6f2b3e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b1b5b9ea0beae452", "level": "note", "message": {"text": "Unused endpoint: GET /follow-state/:steamId/:appId"}, "properties": {"repobilityId": "31646a332da167dd", "scanner": "scanner-primary", "fingerprint": "b1b5b9ea0beae452", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-06b0ae96e72fe993", "level": "note", "message": {"text": "Unused endpoint: GET /follow-notifications/:steamId/:appId"}, "properties": {"repobilityId": "dcfbc5e7755e2427", "scanner": "scanner-primary", "fingerprint": "06b0ae96e72fe993", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9500263f7cde8da9", "level": "note", "message": {"text": "Unused endpoint: POST /follow-notifications/:steamId/:appId"}, "properties": {"repobilityId": "078e2fa5f791bc5c", "scanner": "scanner-primary", "fingerprint": "9500263f7cde8da9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-949f074ffe2be361", "level": "note", "message": {"text": "Unused endpoint: GET /register/:steamId"}, "properties": {"repobilityId": "38000c32b8911a6f", "scanner": "scanner-primary", "fingerprint": "949f074ffe2be361", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea8de1234e2a5e16", "level": "note", "message": {"text": "Unused endpoint: POST /register/:steamId"}, "properties": {"repobilityId": "3f13481848bdb6be", "scanner": "scanner-primary", "fingerprint": "ea8de1234e2a5e16", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}