{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-e0dcad07868d885d", "name": "Stray `console.log` in TS/JS \u2014 tests/harness.js:95", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/harness.js:95"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28a37d6592e33952", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/main.js:14", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/main.js:14"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-198c3d5c1b85b2bc", "name": "Insecure pattern 'local_storage_auth_token' in js/auth/auth.js:110", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in js/auth/auth.js:110"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea326fa97f0a23e8", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/core/storage.js:71", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/core/storage.js:71"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ca02c6f2daa62e2", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/calls.js:217", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/calls.js:217"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6dde96b84ab6d4a", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/profile.js:13", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/profile.js:13"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e25f80818b5c8720", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/inbox.js:84", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/inbox.js:84"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b74f567b1cd0cf5e", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/analytics.js:52", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/analytics.js:52"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ce7322fe3c7c8e55", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/pipeline.js:78", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/pipeline.js:78"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e0d291814cba9675", "name": "Insecure pattern 'insert_adjacent_html' in js/features/pipeline.js:77", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in js/features/pipeline.js:77"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29b4401c766cf8de", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/scraper.js:22", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/scraper.js:22"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67bc759c87482725", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/outreach.js:147", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/outreach.js:147"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5aed76f923979b96", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/leads.js:144", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/leads.js:144"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36b4c6e7be7bd9b9", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/admin.js:90", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/admin.js:90"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a00ad305739254f5", "name": "Insecure pattern 'direct_innerhtml_assignment' in js/features/import.js:69", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/import.js:69"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "2 tests / 20 src (ratio 0.10)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-72fe644f28660372", "name": "Commented-code block (7 lines) in js/auth/auth.js:97", "shortDescription": {"text": "Commented-code block (7 lines) in js/auth/auth.js:97"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2babdd676c66be0d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 js/core/api.js:12", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 js/core/api.js:12"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-490113f2647f7cd9", "name": "Commented-code block (5 lines) in js/features/import.js:23", "shortDescription": {"text": "Commented-code block (5 lines) in js/features/import.js:23"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/24006"}, "properties": {"repository": "AIV-Dream-Avant-Garde/AIV-Lead-Engine-CRM", "repoUrl": "https://github.com/AIV-Dream-Avant-Garde/AIV-Lead-Engine-CRM", "branch": "main"}, "results": [{"ruleId": "scanner-e0dcad07868d885d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/harness.js:95"}, "properties": {"repobilityId": "292662324de5aa92", "scanner": "scanner-primary", "fingerprint": "e0dcad07868d885d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-28a37d6592e33952", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/main.js:14"}, "properties": {"repobilityId": "3b23e0cd41b5e603", "scanner": "scanner-primary", "fingerprint": "28a37d6592e33952", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/main.js"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-198c3d5c1b85b2bc", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in js/auth/auth.js:110"}, "properties": {"repobilityId": "f5df0e7bbcb9a383", "scanner": "scanner-primary", "fingerprint": "198c3d5c1b85b2bc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/auth/auth.js"}, "region": {"startLine": 110}}}]}, {"ruleId": "scanner-ea326fa97f0a23e8", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/core/storage.js:71"}, "properties": {"repobilityId": "bb389311428e0c94", "scanner": "scanner-primary", "fingerprint": "ea326fa97f0a23e8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/core/storage.js"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-0ca02c6f2daa62e2", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/calls.js:217"}, "properties": {"repobilityId": "27cd7d2a39dbdc23", "scanner": "scanner-primary", "fingerprint": "0ca02c6f2daa62e2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/calls.js"}, "region": {"startLine": 217}}}]}, {"ruleId": "scanner-e6dde96b84ab6d4a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/profile.js:13"}, "properties": {"repobilityId": "ab4fe8dc84d9e3b3", "scanner": "scanner-primary", "fingerprint": "e6dde96b84ab6d4a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/profile.js"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-e25f80818b5c8720", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/inbox.js:84"}, "properties": {"repobilityId": "8911e26c88bf5d82", "scanner": "scanner-primary", "fingerprint": "e25f80818b5c8720", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/inbox.js"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-b74f567b1cd0cf5e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/analytics.js:52"}, "properties": {"repobilityId": "d252e5397934a26f", "scanner": "scanner-primary", "fingerprint": "b74f567b1cd0cf5e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/analytics.js"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-ce7322fe3c7c8e55", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/pipeline.js:78"}, "properties": {"repobilityId": "0a2994873aa5917d", "scanner": "scanner-primary", "fingerprint": "ce7322fe3c7c8e55", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/pipeline.js"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-e0d291814cba9675", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in js/features/pipeline.js:77"}, "properties": {"repobilityId": "1624b9ab83485df9", "scanner": "scanner-primary", "fingerprint": "e0d291814cba9675", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/pipeline.js"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-29b4401c766cf8de", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/scraper.js:22"}, "properties": {"repobilityId": "3e61e85c939a292e", "scanner": "scanner-primary", "fingerprint": "29b4401c766cf8de", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/scraper.js"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-67bc759c87482725", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/outreach.js:147"}, "properties": {"repobilityId": "592a92851e7f68d9", "scanner": "scanner-primary", "fingerprint": "67bc759c87482725", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/outreach.js"}, "region": {"startLine": 147}}}]}, {"ruleId": "scanner-5aed76f923979b96", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/leads.js:144"}, "properties": {"repobilityId": "e4b55fc0c4377d88", "scanner": "scanner-primary", "fingerprint": "5aed76f923979b96", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/leads.js"}, "region": {"startLine": 144}}}]}, {"ruleId": "scanner-36b4c6e7be7bd9b9", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/admin.js:90"}, "properties": {"repobilityId": "f54234656fb6dbfc", "scanner": "scanner-primary", "fingerprint": "36b4c6e7be7bd9b9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/admin.js"}, "region": {"startLine": 90}}}]}, {"ruleId": "scanner-a00ad305739254f5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in js/features/import.js:69"}, "properties": {"repobilityId": "065384ae83e2a0f7", "scanner": "scanner-primary", "fingerprint": "a00ad305739254f5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "js/features/import.js"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "f593be342429eb31", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "8ca903427c42290b", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "c4de8549450209d9", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "107169e441d6d533", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72fe644f28660372", "level": "none", "message": {"text": "Commented-code block (7 lines) in js/auth/auth.js:97"}, "properties": {"repobilityId": "9beb21d6c39ad5bd", "scanner": "scanner-primary", "fingerprint": "72fe644f28660372", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2babdd676c66be0d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 js/core/api.js:12"}, "properties": {"repobilityId": "c4480c1f84b862cc", "scanner": "scanner-primary", "fingerprint": "2babdd676c66be0d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-490113f2647f7cd9", "level": "none", "message": {"text": "Commented-code block (5 lines) in js/features/import.js:23"}, "properties": {"repobilityId": "708547f9149c8301", "scanner": "scanner-primary", "fingerprint": "490113f2647f7cd9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}]}]}