{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-bdf8460b0ea1bab6", "name": "Possibly dead Python function: version_key", "shortDescription": {"text": "Possibly dead Python function: version_key"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d842038471e788e9", "name": "Possibly dead Python function: require_token", "shortDescription": {"text": "Possibly dead Python function: require_token"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3d07e2d10baa226", "name": "Possibly dead Python function: canonical_key_for_statement_created", "shortDescription": {"text": "Possibly dead Python function: canonical_key_for_statement_created"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-534f0c6d7833e0ef", "name": "Possibly dead Python function: canonical_key_for_statement_superseded", "shortDescription": {"text": "Possibly dead Python function: canonical_key_for_statement_superseded"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c32641e332b2d2b", "name": "Possibly dead Python function: canonical_key_for_engram_appended", "shortDescription": {"text": "Possibly dead Python function: canonical_key_for_engram_appended"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d6b0713effdc245", "name": "Possibly dead Python function: causation_root", "shortDescription": {"text": "Possibly dead Python function: causation_root"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-724bc71d55873d95", "name": "Insecure pattern 'eval_used' in scripts/eval_commitment.py:99", "shortDescription": {"text": "Insecure pattern 'eval_used' in scripts/eval_commitment.py:99"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-89e068c7a1e286e0", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 82 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 16 placeholder/mock markers across 10 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-98b827d27a1879bc", "name": "Commented-code block (5 lines) in tests/python/test_pattern_completion.py:93", "shortDescription": {"text": "Commented-code block (5 lines) in tests/python/test_pattern_completion.py:93"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-37217ffe81793f76", "name": "Legacy-named symbol `S_old` in tests/python/test_p1_non_critical.py:429", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_p1_non_critical.py:429"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b2297e0720272e7", "name": "Commented-code block (5 lines) in tests/python/test_tc_new_outbox_idemp.py:57", "shortDescription": {"text": "Commented-code block (5 lines) in tests/python/test_tc_new_outbox_idemp.py:57"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-12880d97da37709b", "name": "Legacy-named symbol `weights_v1` in tests/python/test_tc_relation_fiske.py:175", "shortDescription": {"text": "Legacy-named symbol `weights_v1` in tests/python/test_tc_relation_fiske.py:175"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53852634a1937c53", "name": "Legacy-named symbol `S_old` in tests/python/test_tc_conflict_key_unique.py:94", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_tc_conflict_key_unique.py:94"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f9aecd669cc9dd5", "name": "Legacy-named symbol `S_old` in tests/python/test_tc_q3a_001.py:56", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_tc_q3a_001.py:56"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20ecba3afe94cb7d", "name": "Commented-code block (7 lines) in tests/python/test_tc_q3b_001.py:31", "shortDescription": {"text": "Commented-code block (7 lines) in tests/python/test_tc_q3b_001.py:31"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a2d96cd9d6fb586e", "name": "Legacy-named symbol `S_old` in tests/python/test_tc_new_conflict_severe.py:59", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_tc_new_conflict_severe.py:59"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da2b8bf7ce167e27", "name": "Commented-code block (9 lines) in tests/python/test_tc_new_conflict_severe.py:234", "shortDescription": {"text": "Commented-code block (9 lines) in tests/python/test_tc_new_conflict_severe.py:234"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1f9506d26d5fe7e9", "name": "Commented-code block (5 lines) in tests/python/test_m0_2_acceptance_smoke.py:62", "shortDescription": {"text": "Commented-code block (5 lines) in tests/python/test_m0_2_acceptance_smoke.py:62"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-61ccf70138359453", "name": "Legacy-named symbol `S_old` in tests/python/test_mark_consolidated.py:9", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_mark_consolidated.py:9"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e8db522d27c0274", "name": "Legacy-named symbol `_seed_consolidated_old` in tests/python/test_tc_a6_001.py:23", "shortDescription": {"text": "Legacy-named symbol `_seed_consolidated_old` in tests/python/test_tc_a6_001.py:23"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bf320eecf6baded", "name": "Commented-code block (7 lines) in tests/python/test_m0_4_acceptance.py:30", "shortDescription": {"text": "Commented-code block (7 lines) in tests/python/test_m0_4_acceptance.py:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f9b40181831f2c5c", "name": "Commented-code block (5 lines) in tests/python/test_basic_retrieve_multi_holder_reject.py:24", "shortDescription": {"text": "Commented-code block (5 lines) in tests/python/test_basic_retrieve_multi_holder_reject.py:24"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f3bc7b16a958b1eb", "name": "Legacy-named symbol `S_old` in tests/python/test_basic_retrieve_smoke.py:8", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_basic_retrieve_smoke.py:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97d4d976e89a9680", "name": "Commented-code block (7 lines) in tests/python/test_basic_retrieve_smoke.py:196", "shortDescription": {"text": "Commented-code block (7 lines) in tests/python/test_basic_retrieve_smoke.py:196"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bcda44f49ddb703e", "name": "Legacy-named symbol `S_old` in tests/python/test_e2e_severe_conflict.py:6", "shortDescription": {"text": "Legacy-named symbol `S_old` in tests/python/test_e2e_severe_conflict.py:6"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf1fb8c67405bd58", "name": "Commented-code block (6 lines) in tests/python/test_e2e_severe_conflict.py:274", "shortDescription": {"text": "Commented-code block (6 lines) in tests/python/test_e2e_severe_conflict.py:274"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3a74877da0b304f5", "name": "Legacy-named symbol `_seed_consolidated_old` in tests/python/test_tc_a6_002.py:22", "shortDescription": {"text": "Legacy-named symbol `_seed_consolidated_old` in tests/python/test_tc_a6_002.py:22"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c9c4669d85ac6a7", "name": "Commented-code block (5 lines) in tests/python/test_extractor_holder_perspective.py:16", "shortDescription": {"text": "Commented-code block (5 lines) in tests/python/test_extractor_holder_perspective.py:16"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8794cd7b6308b008", "name": "Commented-code block (5 lines) in tests/python/test_mark_evidence_erased.py:183", "shortDescription": {"text": "Commented-code block (5 lines) in tests/python/test_mark_evidence_erased.py:183"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-28416f5644f73398", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/configure_build.py:517", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/configure_build.py:517"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aca7056f4119893b", "name": "Commented-code block (5 lines) in scripts/eval_longmemeval.py:126", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/eval_longmemeval.py:126"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-519cb52183e9d282", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/run_dashboard.py:30", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/run_dashboard.py:30"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5533ec4aac784b2", "name": "Commented-code block (6 lines) in scripts/ci_static_scan.py:33", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/ci_static_scan.py:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e75d6346b7617d0a", "name": "Commented-code block (12 lines) in scripts/generate_commitment_corpus.py:9", "shortDescription": {"text": "Commented-code block (12 lines) in scripts/generate_commitment_corpus.py:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-80727be9d012cac7", "name": "Commented-code block (5 lines) in dashboard/web/src/app.d.ts:5", "shortDescription": {"text": "Commented-code block (5 lines) in dashboard/web/src/app.d.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-84452408ff52584e", "name": "Commented-code block (6 lines) in python/starling/runtime.py:30", "shortDescription": {"text": "Commented-code block (6 lines) in python/starling/runtime.py:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b6b11a5fcd694d3d", "name": "Legacy-named symbol `S_old` in python/starling/testing/__init__.py:18", "shortDescription": {"text": "Legacy-named symbol `S_old` in python/starling/testing/__init__.py:18"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c7a2a44a4874099", "name": "Commented-code block (5 lines) in python/starling/bus/outbox_dispatcher_py.py:114", "shortDescription": {"text": "Commented-code block (5 lines) in python/starling/bus/outbox_dispatcher_py.py:114"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/configure_build.py:runtime_link_args_for_linux, scripts/configure_build.py:run\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\npython/starling/runtime.py:append_evidence, python/starling/runtime.py:write, python/starling/runtime.py:append_evidence, python/starling/runtime.py:write\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b100f43769da8a9", "name": "FastAPI POST `recall` without auth dependency \u2014 python/starling/dashboard/routes/commands.py:74", "shortDescription": {"text": "FastAPI POST `recall` without auth dependency \u2014 python/starling/dashboard/routes/commands.py:74"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ff00fa3dabe776be", "name": "FastAPI POST `tick` without auth dependency \u2014 python/starling/dashboard/routes/commands.py:90", "shortDescription": {"text": "FastAPI POST `tick` without auth dependency \u2014 python/starling/dashboard/routes/commands.py:90"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13850980e4aadb99", "name": "FastAPI POST `post_config` without auth dependency \u2014 python/starling/dashboard/routes/config.py:59", "shortDescription": {"text": "FastAPI POST `post_config` without auth dependency \u2014 python/starling/dashboard/routes/config.py:59"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ef23557a1899c1f5", "name": "FastAPI POST `test_config` without auth dependency \u2014 python/starling/dashboard/routes/config.py:79", "shortDescription": {"text": "FastAPI POST `test_config` without auth dependency \u2014 python/starling/dashboard/routes/config.py:79"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c93b82c283e36ca", "name": "Unused endpoint: GET /api/ping", "shortDescription": {"text": "Unused endpoint: GET /api/ping"}, "fullDescription": {"text": "`python/starling/dashboard/app.py` declares `GET /api/ping` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b1d5926fda286fa", "name": "Unused endpoint: GET /{full_path:path}", "shortDescription": {"text": "Unused endpoint: GET /{full_path:path}"}, "fullDescription": {"text": "`python/starling/dashboard/app.py` declares `GET /{full_path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff9f708a878993d5", "name": "Unused endpoint: POST /remember", "shortDescription": {"text": "Unused endpoint: POST /remember"}, "fullDescription": {"text": "`python/starling/dashboard/routes/commands.py` declares `POST /remember` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6578ca0022bf9033", "name": "Unused endpoint: POST /recall", "shortDescription": {"text": "Unused endpoint: POST /recall"}, "fullDescription": {"text": "`python/starling/dashboard/routes/commands.py` declares `POST /recall` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bcf9e5d01aab2da7", "name": "Unused endpoint: POST /tick", "shortDescription": {"text": "Unused endpoint: POST /tick"}, "fullDescription": {"text": "`python/starling/dashboard/routes/commands.py` declares `POST /tick` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3fa9971292434e8", "name": "Unused endpoint: GET /working_set", "shortDescription": {"text": "Unused endpoint: GET /working_set"}, "fullDescription": {"text": "`python/starling/dashboard/routes/commands.py` declares `GET /working_set` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6f48e60c30777ab", "name": "Unused endpoint: GET /config", "shortDescription": {"text": "Unused endpoint: GET /config"}, "fullDescription": {"text": "`python/starling/dashboard/routes/config.py` declares `GET /config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0666d1d987815276", "name": "Unused endpoint: POST /config", "shortDescription": {"text": "Unused endpoint: POST /config"}, "fullDescription": {"text": "`python/starling/dashboard/routes/config.py` declares `POST /config` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf53a4499cd05941", "name": "Unused endpoint: POST /config/test", "shortDescription": {"text": "Unused endpoint: POST /config/test"}, "fullDescription": {"text": "`python/starling/dashboard/routes/config.py` declares `POST /config/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-008be858a84b3d28", "name": "Unused endpoint: GET /eval", "shortDescription": {"text": "Unused endpoint: GET /eval"}, "fullDescription": {"text": "`python/starling/dashboard/routes/evalreport.py` declares `GET /eval` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac2f552bf9d967ce", "name": "Unused endpoint: GET /overview", "shortDescription": {"text": "Unused endpoint: GET /overview"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /overview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0224ef8a38deb859", "name": "Unused endpoint: GET /statements", "shortDescription": {"text": "Unused endpoint: GET /statements"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /statements` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15221ba859890c76", "name": "Unused endpoint: GET /cognizers", "shortDescription": {"text": "Unused endpoint: GET /cognizers"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /cognizers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aff7073eedeaac08", "name": "Unused endpoint: GET /commitments", "shortDescription": {"text": "Unused endpoint: GET /commitments"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /commitments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c8acff0ad1159324", "name": "Unused endpoint: GET /replay", "shortDescription": {"text": "Unused endpoint: GET /replay"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /replay` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a3a71584f89ef43", "name": "Unused endpoint: GET /conflicts", "shortDescription": {"text": "Unused endpoint: GET /conflicts"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /conflicts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e3487dd80cfde299", "name": "Unused endpoint: GET /queues", "shortDescription": {"text": "Unused endpoint: GET /queues"}, "fullDescription": {"text": "`python/starling/dashboard/routes/inspect.py` declares `GET /queues` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18560"}, "properties": {"repository": "ruijieguo/starling", "repoUrl": "https://github.com/ruijieguo/starling", "branch": "main"}, "results": [{"ruleId": "scanner-bdf8460b0ea1bab6", "level": "note", "message": {"text": "Possibly dead Python function: version_key"}, "properties": {"repobilityId": "f3278be16825d248", "scanner": "scanner-primary", "fingerprint": "bdf8460b0ea1bab6", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/configure_build.py:38"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d842038471e788e9", "level": "note", "message": {"text": "Possibly dead Python function: require_token"}, "properties": {"repobilityId": "4b23e525218d395c", "scanner": "scanner-primary", "fingerprint": "d842038471e788e9", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/dashboard/auth.py:15"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3d07e2d10baa226", "level": "note", "message": {"text": "Possibly dead Python function: canonical_key_for_statement_created"}, "properties": {"repobilityId": "0b258a9e97f49d7a", "scanner": "scanner-primary", "fingerprint": "b3d07e2d10baa226", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/bus/idempotency.py:4"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-534f0c6d7833e0ef", "level": "note", "message": {"text": "Possibly dead Python function: canonical_key_for_statement_superseded"}, "properties": {"repobilityId": "a97d96517e448dc1", "scanner": "scanner-primary", "fingerprint": "534f0c6d7833e0ef", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/bus/idempotency.py:8"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c32641e332b2d2b", "level": "note", "message": {"text": "Possibly dead Python function: canonical_key_for_engram_appended"}, "properties": {"repobilityId": "eb96f3272e8fcbcb", "scanner": "scanner-primary", "fingerprint": "9c32641e332b2d2b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/bus/idempotency.py:12"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d6b0713effdc245", "level": "note", "message": {"text": "Possibly dead Python function: causation_root"}, "properties": {"repobilityId": "f566b09698da65e3", "scanner": "scanner-primary", "fingerprint": "2d6b0713effdc245", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/bus/idempotency.py:16"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-724bc71d55873d95", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in scripts/eval_commitment.py:99"}, "properties": {"repobilityId": "09fb0bc3f96700e8", "scanner": "scanner-primary", "fingerprint": "724bc71d55873d95", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/eval_commitment.py"}, "region": {"startLine": 99}}}]}, {"ruleId": "scanner-89e068c7a1e286e0", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "3a67b858b3be6ced", "scanner": "scanner-primary", "fingerprint": "89e068c7a1e286e0", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "f817508fede8a3fb", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "3d61fd91710c0c02", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "44fc27ea301d3db5", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "24462b89b6c77974", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "9c491e53254db82a", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "b38a9c9235e58748", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "91a96570c1cdcabd", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-98b827d27a1879bc", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/python/test_pattern_completion.py:93"}, "properties": {"repobilityId": "d5ced9888d5d2f51", "scanner": "scanner-primary", "fingerprint": "98b827d27a1879bc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-37217ffe81793f76", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_p1_non_critical.py:429"}, "properties": {"repobilityId": "202be9ba0d203bdd", "scanner": "scanner-primary", "fingerprint": "37217ffe81793f76", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-8b2297e0720272e7", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/python/test_tc_new_outbox_idemp.py:57"}, "properties": {"repobilityId": "d32ca31a263f0b7e", "scanner": "scanner-primary", "fingerprint": "8b2297e0720272e7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-12880d97da37709b", "level": "note", "message": {"text": "Legacy-named symbol `weights_v1` in tests/python/test_tc_relation_fiske.py:175"}, "properties": {"repobilityId": "e6f80b638cb01d34", "scanner": "scanner-primary", "fingerprint": "12880d97da37709b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-53852634a1937c53", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_tc_conflict_key_unique.py:94"}, "properties": {"repobilityId": "b699618f7cc597db", "scanner": "scanner-primary", "fingerprint": "53852634a1937c53", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3f9aecd669cc9dd5", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_tc_q3a_001.py:56"}, "properties": {"repobilityId": "93b1125968bd2ee2", "scanner": "scanner-primary", "fingerprint": "3f9aecd669cc9dd5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-20ecba3afe94cb7d", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/python/test_tc_q3b_001.py:31"}, "properties": {"repobilityId": "06c22e946bb81056", "scanner": "scanner-primary", "fingerprint": "20ecba3afe94cb7d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a2d96cd9d6fb586e", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_tc_new_conflict_severe.py:59"}, "properties": {"repobilityId": "bea1e824a38ac38c", "scanner": "scanner-primary", "fingerprint": "a2d96cd9d6fb586e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-da2b8bf7ce167e27", "level": "none", "message": {"text": "Commented-code block (9 lines) in tests/python/test_tc_new_conflict_severe.py:234"}, "properties": {"repobilityId": "d4e52fc659e6eae7", "scanner": "scanner-primary", "fingerprint": "da2b8bf7ce167e27", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1f9506d26d5fe7e9", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/python/test_m0_2_acceptance_smoke.py:62"}, "properties": {"repobilityId": "a1f4c94b52d3b067", "scanner": "scanner-primary", "fingerprint": "1f9506d26d5fe7e9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-61ccf70138359453", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_mark_consolidated.py:9"}, "properties": {"repobilityId": "69556813b9f11137", "scanner": "scanner-primary", "fingerprint": "61ccf70138359453", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6e8db522d27c0274", "level": "note", "message": {"text": "Legacy-named symbol `_seed_consolidated_old` in tests/python/test_tc_a6_001.py:23"}, "properties": {"repobilityId": "d53ed49c48a6e9f4", "scanner": "scanner-primary", "fingerprint": "6e8db522d27c0274", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-6bf320eecf6baded", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/python/test_m0_4_acceptance.py:30"}, "properties": {"repobilityId": "e3ef332d632be533", "scanner": "scanner-primary", "fingerprint": "6bf320eecf6baded", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f9b40181831f2c5c", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/python/test_basic_retrieve_multi_holder_reject.py:24"}, "properties": {"repobilityId": "482b502020b41170", "scanner": "scanner-primary", "fingerprint": "f9b40181831f2c5c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f3bc7b16a958b1eb", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_basic_retrieve_smoke.py:8"}, "properties": {"repobilityId": "2fcd40e5e6af0a85", "scanner": "scanner-primary", "fingerprint": "f3bc7b16a958b1eb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-97d4d976e89a9680", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/python/test_basic_retrieve_smoke.py:196"}, "properties": {"repobilityId": "a366975259420faf", "scanner": "scanner-primary", "fingerprint": "97d4d976e89a9680", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bcda44f49ddb703e", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in tests/python/test_e2e_severe_conflict.py:6"}, "properties": {"repobilityId": "0f291552102b26d6", "scanner": "scanner-primary", "fingerprint": "bcda44f49ddb703e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-cf1fb8c67405bd58", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/python/test_e2e_severe_conflict.py:274"}, "properties": {"repobilityId": "0541c15714300b22", "scanner": "scanner-primary", "fingerprint": "cf1fb8c67405bd58", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3a74877da0b304f5", "level": "note", "message": {"text": "Legacy-named symbol `_seed_consolidated_old` in tests/python/test_tc_a6_002.py:22"}, "properties": {"repobilityId": "2429762bcdb2a2c5", "scanner": "scanner-primary", "fingerprint": "3a74877da0b304f5", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7c9c4669d85ac6a7", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/python/test_extractor_holder_perspective.py:16"}, "properties": {"repobilityId": "cbf73d063ea14b12", "scanner": "scanner-primary", "fingerprint": "7c9c4669d85ac6a7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8794cd7b6308b008", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/python/test_mark_evidence_erased.py:183"}, "properties": {"repobilityId": "7e01818d2c81318d", "scanner": "scanner-primary", "fingerprint": "8794cd7b6308b008", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-28416f5644f73398", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/configure_build.py:517"}, "properties": {"repobilityId": "cfbc438720357bc5", "scanner": "scanner-primary", "fingerprint": "28416f5644f73398", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-aca7056f4119893b", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/eval_longmemeval.py:126"}, "properties": {"repobilityId": "fd539a1b17333f35", "scanner": "scanner-primary", "fingerprint": "aca7056f4119893b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-519cb52183e9d282", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/run_dashboard.py:30"}, "properties": {"repobilityId": "e48bed160b39aa17", "scanner": "scanner-primary", "fingerprint": "519cb52183e9d282", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d5533ec4aac784b2", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/ci_static_scan.py:33"}, "properties": {"repobilityId": "cf21d193baa69b35", "scanner": "scanner-primary", "fingerprint": "d5533ec4aac784b2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e75d6346b7617d0a", "level": "none", "message": {"text": "Commented-code block (12 lines) in scripts/generate_commitment_corpus.py:9"}, "properties": {"repobilityId": "fd88f5ff99531f17", "scanner": "scanner-primary", "fingerprint": "e75d6346b7617d0a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-80727be9d012cac7", "level": "none", "message": {"text": "Commented-code block (5 lines) in dashboard/web/src/app.d.ts:5"}, "properties": {"repobilityId": "d82a50d855ded2cf", "scanner": "scanner-primary", "fingerprint": "80727be9d012cac7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-84452408ff52584e", "level": "none", "message": {"text": "Commented-code block (6 lines) in python/starling/runtime.py:30"}, "properties": {"repobilityId": "5f01dba1389ca4e7", "scanner": "scanner-primary", "fingerprint": "84452408ff52584e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b6b11a5fcd694d3d", "level": "note", "message": {"text": "Legacy-named symbol `S_old` in python/starling/testing/__init__.py:18"}, "properties": {"repobilityId": "2543618063631897", "scanner": "scanner-primary", "fingerprint": "b6b11a5fcd694d3d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4c7a2a44a4874099", "level": "none", "message": {"text": "Commented-code block (5 lines) in python/starling/bus/outbox_dispatcher_py.py:114"}, "properties": {"repobilityId": "dcd0fa0d5074df6a", "scanner": "scanner-primary", "fingerprint": "4c7a2a44a4874099", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "c22f59668f169255", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "05b9e264e9c37101", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "fd974892503764e4", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "911d8eaae5d3575d", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "490cde4ebaaf9307", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "a97e9b11d8bd6ca7", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "b8f8fd2efc33d13c", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "0f306f7c08e210b5", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-9b100f43769da8a9", "level": "error", "message": {"text": "FastAPI POST `recall` without auth dependency \u2014 python/starling/dashboard/routes/commands.py:74"}, "properties": {"repobilityId": "71a049ee787d93da", "scanner": "scanner-primary", "fingerprint": "9b100f43769da8a9", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/dashboard/routes/commands.py"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-ff00fa3dabe776be", "level": "error", "message": {"text": "FastAPI POST `tick` without auth dependency \u2014 python/starling/dashboard/routes/commands.py:90"}, "properties": {"repobilityId": "49820933e4b1094c", "scanner": "scanner-primary", "fingerprint": "ff00fa3dabe776be", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/dashboard/routes/commands.py"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-13850980e4aadb99", "level": "error", "message": {"text": "FastAPI POST `post_config` without auth dependency \u2014 python/starling/dashboard/routes/config.py:59"}, "properties": {"repobilityId": "1e6e39a0cf05f299", "scanner": "scanner-primary", "fingerprint": "13850980e4aadb99", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/dashboard/routes/config.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-ef23557a1899c1f5", "level": "error", "message": {"text": "FastAPI POST `test_config` without auth dependency \u2014 python/starling/dashboard/routes/config.py:79"}, "properties": {"repobilityId": "8a630cafda159662", "scanner": "scanner-primary", "fingerprint": "ef23557a1899c1f5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "python/starling/dashboard/routes/config.py"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-3c93b82c283e36ca", "level": "note", "message": {"text": "Unused endpoint: GET /api/ping"}, "properties": {"repobilityId": "1fded04618d1bb67", "scanner": "scanner-primary", "fingerprint": "3c93b82c283e36ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b1d5926fda286fa", "level": "note", "message": {"text": "Unused endpoint: GET /{full_path:path}"}, "properties": {"repobilityId": "f8b4712887b9ef9f", "scanner": "scanner-primary", "fingerprint": "1b1d5926fda286fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff9f708a878993d5", "level": "note", "message": {"text": "Unused endpoint: POST /remember"}, "properties": {"repobilityId": "70f3e98112a478fc", "scanner": "scanner-primary", "fingerprint": "ff9f708a878993d5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6578ca0022bf9033", "level": "note", "message": {"text": "Unused endpoint: POST /recall"}, "properties": {"repobilityId": "ea25d45e68cb6b3f", "scanner": "scanner-primary", "fingerprint": "6578ca0022bf9033", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bcf9e5d01aab2da7", "level": "note", "message": {"text": "Unused endpoint: POST /tick"}, "properties": {"repobilityId": "94fe8a087d7724a7", "scanner": "scanner-primary", "fingerprint": "bcf9e5d01aab2da7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f3fa9971292434e8", "level": "note", "message": {"text": "Unused endpoint: GET /working_set"}, "properties": {"repobilityId": "e2f3d20b6cf47be5", "scanner": "scanner-primary", "fingerprint": "f3fa9971292434e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a6f48e60c30777ab", "level": "note", "message": {"text": "Unused endpoint: GET /config"}, "properties": {"repobilityId": "52b367ea8cf0d10b", "scanner": "scanner-primary", "fingerprint": "a6f48e60c30777ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0666d1d987815276", "level": "note", "message": {"text": "Unused endpoint: POST /config"}, "properties": {"repobilityId": "9deba145d9d2a1b0", "scanner": "scanner-primary", "fingerprint": "0666d1d987815276", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cf53a4499cd05941", "level": "note", "message": {"text": "Unused endpoint: POST /config/test"}, "properties": {"repobilityId": "7c75160e5b0977e9", "scanner": "scanner-primary", "fingerprint": "cf53a4499cd05941", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-008be858a84b3d28", "level": "note", "message": {"text": "Unused endpoint: GET /eval"}, "properties": {"repobilityId": "bfce45f620e784dd", "scanner": "scanner-primary", "fingerprint": "008be858a84b3d28", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac2f552bf9d967ce", "level": "note", "message": {"text": "Unused endpoint: GET /overview"}, "properties": {"repobilityId": "d3d236a9d91f2251", "scanner": "scanner-primary", "fingerprint": "ac2f552bf9d967ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0224ef8a38deb859", "level": "note", "message": {"text": "Unused endpoint: GET /statements"}, "properties": {"repobilityId": "8caca544f8987667", "scanner": "scanner-primary", "fingerprint": "0224ef8a38deb859", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-15221ba859890c76", "level": "note", "message": {"text": "Unused endpoint: GET /cognizers"}, "properties": {"repobilityId": "678eacec924249fd", "scanner": "scanner-primary", "fingerprint": "15221ba859890c76", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aff7073eedeaac08", "level": "note", "message": {"text": "Unused endpoint: GET /commitments"}, "properties": {"repobilityId": "b9fbfcdeb87f535e", "scanner": "scanner-primary", "fingerprint": "aff7073eedeaac08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c8acff0ad1159324", "level": "note", "message": {"text": "Unused endpoint: GET /replay"}, "properties": {"repobilityId": "b3b6d4974ed0ab21", "scanner": "scanner-primary", "fingerprint": "c8acff0ad1159324", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9a3a71584f89ef43", "level": "note", "message": {"text": "Unused endpoint: GET /conflicts"}, "properties": {"repobilityId": "32d39589d8ac9188", "scanner": "scanner-primary", "fingerprint": "9a3a71584f89ef43", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e3487dd80cfde299", "level": "note", "message": {"text": "Unused endpoint: GET /queues"}, "properties": {"repobilityId": "7856e7248e8281e5", "scanner": "scanner-primary", "fingerprint": "e3487dd80cfde299", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}