{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-e9fc22b9ae7b1ffa", "name": "TODO/FIXME marker in shipping code \u2014 styled-system/preset/src/globalCss.ts:31", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 styled-system/preset/src/globalCss.ts:31"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-a4d4652bdd152c5b", "name": "TODO/FIXME marker in shipping code \u2014 apps/playground/worker/viewkv.tsx:46", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 apps/playground/worker/viewkv.tsx:46"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-def4f74c3a710bd0", "name": "TODO/FIXME marker in shipping code \u2014 apps/playground/worker/api.share.ts:24", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 apps/playground/worker/api.share.ts:24"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-e957fa601c6adb24", "name": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/worker/api.share.ts:47", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/worker/api.share.ts:47"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0106444ac12a0247", "name": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/state/context.tsx:21", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/state/context.tsx:21"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-0c7c8b8cc7501c32", "name": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/monaco/MonacoEditor.tsx:46", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/monaco/MonacoEditor.tsx:46"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-b0a5ebe57ef402e1", "name": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/routes/share.$shareId/view/route.tsx:29", "shortDescription": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/routes/share.$shareId/view/route.tsx:29"}, "fullDescription": {"text": "Remove debug output or route intentional diagnostics through the project's structured logger. Browser console output can expose state and create noise; server and CLI output are outside this rule's scope.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-d56eeea49cf5556a", "name": "TODO/FIXME marker in shipping code \u2014 packages/vscode/vscode.proposed.chatParticipantAdditions.d.ts:790", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/vscode/vscode.proposed.chatParticipantAdditions.d.ts:790"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-6a622cdd59c40783", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/LikeC4Styles.tsx:107", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/LikeC4Styles.tsx:107"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-d69780646a17724d", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/shadowroot/ShadowRoot.tsx:173", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/shadowroot/ShadowRoot.tsx:173"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-97fbd32550fda8df", "name": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/utils/xyflow.ts:174", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/utils/xyflow.ts:174"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-3ba2179dcad90950", "name": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/components/SearchControl.css.ts:8", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/components/SearchControl.css.ts:8"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-779b5b84b6b31d53", "name": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/navigationpanel/editorpanel/ChangeAutoLayoutButton.tsx:78", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/navigationpanel/editorpanel/ChangeAutoLayoutButton.tsx:78"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-a87730d34eb4e6b7", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/context/TagStylesContext.tsx:77", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/context/TagStylesContext.tsx:77"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-3f36fa18b4d188df", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/context/IconRenderer.tsx:194", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/context/IconRenderer.tsx:194"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-c662dfbc86dee471", "name": "React Flow <Controls> without dark theming \u2014 packages/diagram/src/likec4diagram/DiagramXYFlow.tsx:313", "shortDescription": {"text": "React Flow <Controls> without dark theming \u2014 packages/diagram/src/likec4diagram/DiagramXYFlow.tsx:313"}, "fullDescription": {"text": "`<Controls>` ships with white buttons. Override `.react-flow__controls` and `.react-flow__controls-button` in your stylesheet or pass a styled wrapper.\n\nWhy: P1 in CHECKLIST.md \u2014 vendor defaults bleed light through.\nRule id: fq.controls.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-5cf9e6d47e7f7073", "name": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/likec4diagram/state/machine.setup.ts:363", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/likec4diagram/state/machine.setup.ts:363"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-9a567b566b3e876d", "name": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/likec4diagram/custom/nodes/toolbar/Toolbar.tsx:50", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/likec4diagram/custom/nodes/toolbar/Toolbar.tsx:50"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-04f8ee7a05c08c62", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/base-primitives/Markdown.tsx:57", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/base-primitives/Markdown.tsx:57"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-f5c29582f6c715ff", "name": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/overlays/overlaysActor.ts:40", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/overlays/overlaysActor.ts:40"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-e57e6c4c4771f810", "name": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/element-view/__test__/legacy.spec.ts:64", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/element-view/__test__/legacy.spec.ts:64"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-e9ffb71a11131ce9", "name": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/predicates/utils.ts:301", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/predicates/utils.ts:301"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-9b7cd98311681a54", "name": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/stages/stage-include.spec.ts:155", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/stages/stage-include.spec.ts:155"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-c0eea685a3fd9b5c", "name": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/stages/stage-final.ts:195", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/stages/stage-final.ts:195"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-64c8413803c898c4", "name": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 packages/core/src/compute-view/utils/view-ha", "shortDescription": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 packages/core/src/compute-view/utils/view-hash.ts:39"}, "fullDescription": {"text": "React Flow edge labels render with a white rectangle behind the text by default, which scatters bright boxes across a dark canvas. Either drop the label, or override `.react-flow__edge-textbg` and `.react-flow__edge-text` in your stylesheet.\n\nWhy: P-H in CHECKLIST.md \u2014 vendor edge labels bleed white through a dark canvas.\nRule id: fq.edge-label.no-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-56562e081eac9d49", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/filesystem/LikeC4ManualLayouts.ts:99", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/filesystem/LikeC4ManualLayouts.ts:99"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-1245bb490925f403", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/filesystem/LikeC4ManualLayouts.spec.ts:453", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/filesystem/LikeC4ManualLayouts.spec.ts:453"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-bfd01d3b843f821a", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/__tests__/model.spec.ts:234", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/__tests__/model.spec.ts:234"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-f176f0eaecfb6323", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/model-change/ModelChanges.ts:62", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/model-change/ModelChanges.ts:62"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-1439ba2bb1def4c2", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/model/model-locator.ts:136", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/model/model-locator.ts:136"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-30df46db968607e5", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/lsp/DocumentSymbolProvider.ts:205", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/lsp/DocumentSymbolProvider.ts:205"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-e83563868b80c84d", "name": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/lsp/CompletionProvider.spec.ts:992", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/lsp/CompletionProvider.spec.ts:992"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ab0ba7d5dda85359", "name": "TODO/FIXME marker in shipping code \u2014 packages/likec4/src/vite/vite-preview.ts:32", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/likec4/src/vite/vite-preview.ts:32"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-ea122cbade1b683a", "name": "TODO/FIXME marker in shipping code \u2014 packages/layouts/src/graphviz/QueueGraphvizLayoter.ts:155", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/layouts/src/graphviz/QueueGraphvizLayoter.ts:155"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 0.7}}, {"id": "scanner-bff8ed141e04c9ef", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsDot.tsx:31", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsDot.tsx:31"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-d4f24839798ad7c0", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsD2.tsx:71", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsD2.tsx:71"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-3acabd3edf70b67e", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsMmd.tsx:56", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsMmd.tsx:56"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-32a4fe99c1b91e04", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsPuml.tsx:69", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsPuml.tsx:69"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 0.8}}, {"id": "scanner-982c5296f8d89460", "name": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/LikeC4Styles.tsx:107", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/LikeC4Styles.tsx:107"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-c629f75001891a3d", "name": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/base-primitives/Markdown.tsx:57", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/base-primitives/Markdown.tsx:57"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-60e2dd9ac161b3af", "name": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/context/TagStylesContext.tsx:77", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/context/TagStylesContext.tsx:77"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-78db9c70ef3313aa", "name": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/shadowroot/ShadowRoot.tsx:173", "shortDescription": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/shadowroot/ShadowRoot.tsx:173"}, "fullDescription": {"text": "Detection of dangerouslySetInnerHTML from non-constant definition. This can inadvertently expose users to cross-site scripting (XSS) attacks if this comes from user-provided input. If you have to use dangerouslySetInnerHTML, consider using a sanitization library such as DOMPurify to sanitize your HTML.\n\nRule: typescript.react.security.audit.react-dangerouslysetinnerhtml.react-dangerouslysetinnerhtml\nSeverity: WARNING\nOWASP: A07:2017 - Cross-Site Scripting (XSS), A03:2021 - Injection, A05:2025 - Injection\nCWE: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\nCategory: security\nContext: production"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.7}}, {"id": "scanner-993552b71134bcb6", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.14\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9dadc5f9682a312", "name": "CVE-2026-12590: body-parser 2.2.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "body-parser: body-parser: Denial of Service via invalid limit option\n\nImpact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or NaN, bytes.parse returns null and the request body size check is silently skipped. Applications that rely on limit as their primary safeguard against oversized request bodies will accept arbitrarily large payloads, leading to excessive memory and CPU usage and denial of service. Patches: This issue is fixed in body-pars\n\nPackage: body-parser\nInstalled: 2.2.2\nFixed in: 1.20.6, 2.3.0\nSeverity: LOW\nFix: Upgrade body-parser to 1.20.6, 2.3.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c244ca577ede5b06", "name": "CVE-2026-13149: brace-expansion 2.0.3 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 2.0.3 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 2.0.3\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f4940e308ee9766", "name": "CVE-2026-13149: brace-expansion 4.0.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 4.0.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 4.0.1\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0571f0916082f0b4", "name": "CVE-2026-33750: brace-expansion 4.0.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-33750: brace-expansion 4.0.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used.\n\nPackage: brace-expansion\nInstalled: 4.0.1\nFixed in: 5.0.5, 3.0.2, 2.0.3, 1.1.13\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.5, 3.0.2, 2.0.3, 1.1.13"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-37b28548b0918bab", "name": "CVE-2026-13149: brace-expansion 5.0.5 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13149: brace-expansion 5.0.5 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity\n\nbrace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.\n\nPackage: brace-expansion\nInstalled: 5.0.5\nFixed in: 5.0.7, 1.1.16, 2.1.2\nSeverity: HIGH\nFix: Upgrade brace-expansion to 5.0.7, 1.1.16, 2.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-92f5f86743908e9b", "name": "CVE-2026-45149: brace-expansion 5.0.5 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45149: brace-expansion 5.0.5 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges\n\nThe brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vul\n\nPackage: brace-expansion\nInstalled: 5.0.5\nFixed in: 5.0.6\nSeverity: MEDIUM\nFix: Upgrade brace-expansion to 5.0.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-21802d4cdef662d3", "name": "CVE-2026-24001: diff 7.0.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-24001: diff 7.0.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "jsdiff: denial of service vulnerability in parsePatch and applyPatch\n\njsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\\r`, `\\u2028`, or `\\u2029` can cause the `parsePatch` method to enter an infinite loop. It then consumes memory without limit until the process crashes due to running out of memory. Applications are therefore likely to be vulnerable to a denial-of-service attack if they call `parsePatch` with a user-provid\n\nPackage: diff\nInstalled: 7.0.0\nFixed in: 8.0.3, 5.2.2, 4.0.4, 3.5.1\nSeverity: LOW\nFix: Upgrade diff to 8.0.3, 5.2.2, 4.0.4, 3.5.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3fb09555ec9db6b", "name": "CVE-2025-14505: elliptic 6.6.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-14505: elliptic 6.6.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "elliptic: Key handling flaws in Elliptic\n\nThe ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed based on step 3.2 of  RFC 6979 https://datatracker.ietf.org/doc/html/rfc6979 ) has leading zeros and is susceptible to cryptanalysis, which can lead to secret key exposure. This happens, because the byte-length of 'k' is incorrectly computed, resulting in its getting truncated during the computation. Legitimate transactions or communications will be broken as a result.\u00a0Furtherm\n\nPackage: elliptic\nInstalled: 6.6.1\nFixed in: \u2014\nSeverity: LOW\nFix: No fix version published yet"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32938573f597b150", "name": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "esbuild allows arbitrary file read when running the development server on Windows\n\n### Summary\n\nThe development server contains a path traversal vulnerability on Windows when serving files from `servedir`.\n\nDue to the use of `path.Clean()` (which only normalizes forward-slash `/` separators) instead of a Windows-aware path normalization function, it is possible to craft requests using backslashes (`\\`) that bypass the intended directory containment logic. An attacker can escape the configured `servedir` root and access arbitrary files on the filesystem.\nThis issue affects Wind\n\nPackage: esbuild\nInstalled: 0.27.3\nFixed in: 0.28.1\nSeverity: LOW\nFix: Upgrade esbuild to 0.28.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e925efd8793ae9b", "name": "CVE-2026-13676: fast-uri 3.1.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization\n\nfast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) befo\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 4.0.1, 3.1.3, 2.4.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 4.0.1, 3.1.3, 2.4.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2281acd7795cdefe", "name": "CVE-2026-16221: fast-uri 3.1.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x  ...\n\nImpact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use f\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 2.4.3, 3.1.4, 4.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 2.4.3, 3.1.4, 4.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ee58b7134906e5d0", "name": "CVE-2026-6321: fast-uri 3.1.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies\n\nfast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Version\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.1\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fa67cc47d2cf8220", "name": "CVE-2026-6322: fast-uri 3.1.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "fast-uri: fast-uri: URI authority bypass due to improper delimiter handling\n\nfast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a differ\n\nPackage: fast-uri\nInstalled: 3.1.0\nFixed in: 3.1.2\nSeverity: HIGH\nFix: Upgrade fast-uri to 3.1.2"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c39e60a99cd19f3b", "name": "CVE-2026-42338: ip-address 10.1.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input\n\nip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods,\n\nPackage: ip-address\nInstalled: 10.1.0\nFixed in: 10.1.1\nSeverity: MEDIUM\nFix: Upgrade ip-address to 10.1.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-693d36861b537d20", "name": "CVE-2026-4800: lodash-es 4.17.21 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: lodash: Arbitrary code execution via untrusted input in template imports\n\nImpact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith t\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: HIGH\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-54d8efaee3f14b51", "name": "CVE-2025-13465: lodash-es 4.17.21 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: prototype pollution in _.unset and _.omit functions\n\nLodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset\u00a0and _.omit\u00a0functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.17.23\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.17.23"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58afeacd92324a10", "name": "CVE-2026-2950: lodash-es 4.17.21 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass\n\nImpact:\n\nLodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check by passing array-wrapped path segments. This allows deletion of properties from built-in prototypes such as Object.prototype, Number.prototype, and String.prototype.\n\nThe issue permits deletion of prot\n\nPackage: lodash-es\nInstalled: 4.17.21\nFixed in: 4.18.0\nSeverity: MEDIUM\nFix: Upgrade lodash-es to 4.18.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-284af2733559a755", "name": "CVE-2026-48712: protobufjs 7.5.6 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48712: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via uncontrolled recursion with crafted protobuf payload\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversion path. A crafted protobuf binary payload containing deeply nested Any values could cause the JavaScript call stack to be exhausted during conversion to JSON. This vulnerability is fixed in 7.6.1 and\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.6.1, 8.4.1\nSeverity: HIGH\nFix: Upgrade protobufjs to 7.6.1, 8.4.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-68ad5daf168590ef", "name": "CVE-2026-45740: protobufjs 7.5.6 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45740: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted JSON descriptors\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recurse without a depth limit while expanding nested JSON descriptors through Root.fromJSON() and Namespace.addJSON(). A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading. This vulnerability is fixed in 7.5.8 and 8.2.0.\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.5.8, 8.2.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.5.8, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d8fbd64b9ed72ccd", "name": "CVE-2026-54269: protobufjs 7.5.6 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-54269: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs-cli: protobufjs: Denial of Service due to name collision with runtime helpers\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted certain schema-derived names that could collide with properties used by protobufjs runtime helpers. The known affected names are fields named hasOwnProperty, field or oneof names such as $type when loaded through protobufjs JSON/reflection descriptors, and service methods whose generated helper name is rpcCall. When affected message or service types were used, protobufjs could r\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.6.3, 8.6.0\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.3, 8.6.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0eb61ff523e5d94b", "name": "CVE-2026-59877: protobufjs 7.5.6 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-59877: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "protobufjs: protobufjs: Denial of Service via crafted .proto schema\n\nprotobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing through schema tokens until reaching an = token without checking for end of input, so a crafted .proto schema that opens an option declaration and ends prematurely can cause parse, Root.load, or Root.loadSync to loop indefinitely. This issue is fixed in versions 7.6.5 and 8.6.6.\n\nPackage: protobufjs\nInstalled: 7.5.6\nFixed in: 7.6.5, 8.6.6\nSeverity: MEDIUM\nFix: Upgrade protobufjs to 7.6.5, 8.6.6"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-404d8b2336db7441", "name": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\n### Impact\n\nA number of vulnerabilities, two rated as \"High\" severity using CVSSv4, have been discovered and fixed in the upstream libvips dependency.\n\nThose processing untrusted input with versions of sharp prior to 0.35.0 are affected.\n\n### Patches\n\n#### Using prebuilt binaries provided by sharp?\n\nMost people rely on the prebuilt binaries provided by sharp.\n\nPlease upgrade sharp to the latest version, currently 0.35.3, which provides libvips 8.18.3.\n\n#### Using a globally-installed libvips?\n\nP\n\nPackage: sharp\nInstalled: 0.34.5\nFixed in: 0.35.0\nSeverity: HIGH\nFix: Upgrade sharp to 0.35.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6d8acbce5234a3ff", "name": "CVE-2026-12151: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12151: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames\n\nImpact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: HIGH\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-24dd739a588c2add", "name": "CVE-2026-1526: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-1526: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression\n\nThe undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed data size. A malicious WebSocket server can send a small compressed frame (a \"decompression bomb\") that expands to an extremely large size in memory, causing the Node.js process to e\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.24.0, 7.24.0\nSeverity: HIGH\nFix: Upgrade undici to 6.24.0, 7.24.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b4b965b741ef572d", "name": "CVE-2026-1528: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-1528: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Denial of Service via crafted WebSocket frame with large length\n\nImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.\n\nPatches\n\nPatched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.24.0, 7.24.0\nSeverity: HIGH\nFix: Upgrade undici to 6.24.0, 7.24.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8c86b43fb2647d14", "name": "CVE-2026-2229: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2229: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter\n\nImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the\u00a0server_max_window_bits\u00a0parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range\u00a0server_max_window_bits\u00a0value (outside zlib's valid range of 8-15). When the server subsequently sends a compressed frame, the client attempts to cre\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.24.0, 7.24.0\nSeverity: HIGH\nFix: Upgrade undici to 6.24.0, 7.24.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-703f5d0d0e208f40", "name": "CVE-2026-1525: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-1525: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers\n\nUndici allows duplicate HTTP\u00a0Content-Length\u00a0headers when they are provided in an array with case-variant names (e.g.,\u00a0Content-Length\u00a0and\u00a0content-length). This produces malformed HTTP/1.1 requests with multiple conflicting\u00a0Content-Length\u00a0values on the wire.\n\nWho is impacted:\n\n  *  Applications using\u00a0undici.request(),\u00a0undici.Client, or similar low-level APIs with headers passed as flat arrays\n  *  Applications that accept user-controlled header names without case-normalization\n\n\nPotential conseque\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.24.0, 7.24.0\nSeverity: MEDIUM\nFix: Upgrade undici to 6.24.0, 7.24.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f3f12011af70e20a", "name": "CVE-2026-1527: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-1527: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: HTTP header injection and request smuggling vulnerability\n\nImpactWhen an application passes user-controlled input to the\u00a0upgrade\u00a0option of\u00a0client.request(), an attacker can inject CRLF sequences (\\r\\n) to:\n\n  *  Inject arbitrary HTTP headers\n  *  Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch)\nThe vulnerability exists because undici writes the\u00a0upgrade\u00a0value directly to the socket without validating for invalid header characters:\n\n// lib/dispatcher/client-h1.js:1121\nif (upgrade) {\n  heade\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.24.0, 7.24.0\nSeverity: MEDIUM\nFix: Upgrade undici to 6.24.0, 7.24.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f542ddebaaedae47", "name": "CVE-2026-2581: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-2581: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: Denial of Service due to uncontrolled resource consumption\n\nThis is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).\n\nIn vulnerable Undici versions, when\u00a0interceptors.deduplicate()\u00a0is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted upstream endpoint can exploit this with large/chunked responses and concurrent identical requests, causing high memory usage and potential OOM process termination.\n\nImpacted users a\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 7.24.0\nSeverity: MEDIUM\nFix: Upgrade undici to 7.24.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8901c221dad0f368", "name": "CVE-2026-9678: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-9678: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: Information disclosure due to improper cache-control header parsing\n\nImpact:\nUndici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=\" authorization\" or no-cache=\"\\tauthorization\". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored.\n\nIn shared-cache mode, this allows a response containing one user's authenticated data to be serve\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96d7a0ff40939a5b", "name": "CVE-2026-9679: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-9679: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding\n\nImpact:\nundici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 \u00a75.4 does not specify any decoding and browsers do not decode either.\n\nApplications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inj\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4d7b050ba13e6a6", "name": "CVE-2026-11525: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-11525: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n\nImpact:\nWhen undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict).\n\nAffected applications are those that consume Set-Cookie header\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87cdb31389dc830a", "name": "CVE-2026-6733: undici 7.18.2 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6733: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.\n\nImpact:\nUndici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.\n\nThis requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-ali\n\nPackage: undici\nInstalled: 7.18.2\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6f7b9acd0646f4f", "name": "CVE-2026-12151: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-12151: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames\n\nImpact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client\n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: HIGH\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ad8fc3ecf1da3a0", "name": "CVE-2026-6734: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6734: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing\n\nImpact:\nWhen using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination.\n\nThis causes cross-origin request routing: credentials and request data intended for origin B are sent to origin A, responses from the wrong origin are trusted, and HTTPS requests may be silently downgraded to HT\n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 7.28.0, 8.2.0\nSeverity: HIGH\nFix: Upgrade undici to 7.28.0, 8.2.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e815153881e360b4", "name": "CVE-2026-9697: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-9697: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy\n\nImpact:\nundici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.\n\nApplications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed \n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 7.28.0, 8.5.0\nSeverity: HIGH\nFix: Upgrade undici to 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c6da4ddddc77ab9", "name": "CVE-2026-9678: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-9678: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: Information disclosure due to improper cache-control header parsing\n\nImpact:\nUndici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=\" authorization\" or no-cache=\"\\tauthorization\". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored.\n\nIn shared-cache mode, this allows a response containing one user's authenticated data to be serve\n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c40d1582b5784bb2", "name": "CVE-2026-9679: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-9679: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding\n\nImpact:\nundici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 \u00a75.4 does not specify any decoding and browsers do not decode either.\n\nApplications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inj\n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: MEDIUM\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fdf139b242dbef93", "name": "CVE-2026-11525: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-11525: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n\nImpact:\nWhen undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict).\n\nAffected applications are those that consume Set-Cookie header\n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33b8054569796111", "name": "CVE-2026-6733: undici 7.24.8 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-6733: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery.\n\nImpact:\nUndici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.\n\nThis requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-ali\n\nPackage: undici\nInstalled: 7.24.8\nFixed in: 6.27.0, 7.28.0, 8.5.0\nSeverity: LOW\nFix: Upgrade undici to 6.27.0, 7.28.0, 8.5.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d57769a75313f0c2", "name": "CVE-2026-41907: uuid 9.0.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality\n\nuuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.\n\nPackage: uuid\nInstalled: 9.0.1\nFixed in: 11.1.1, 12.0.1, 13.0.1\nSeverity: MEDIUM\nFix: Upgrade uuid to 11.1.1, 12.0.1, 13.0.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dd8ec5a200fa9359", "name": "CVE-2026-48779: ws 8.18.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48779: ws 8.18.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.18.0\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d0df7f161352f4a8", "name": "CVE-2026-45736: ws 8.18.0 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-45736: ws 8.18.0 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray`\n\nws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.\n\nPackage: ws\nInstalled: 8.18.0\nFixed in: 8.20.1\nSeverity: MEDIUM\nFix: Upgrade ws to 8.20.1"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-df43818ec803dac6", "name": "CVE-2026-48779: ws 8.20.1 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "CVE-2026-48779: ws 8.20.1 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments\n\nws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-si\n\nPackage: ws\nInstalled: 8.20.1\nFixed in: 5.2.5, 6.2.4, 7.5.11, 8.21.0\nSeverity: HIGH\nFix: Upgrade ws to 5.2.5, 6.2.4, 7.5.11, 8.21.0"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a3527e70129fb18", "name": "DS-0002: Image user should not be 'root' \u2014 Dockerfile", "shortDescription": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "fullDescription": {"text": "Image user should not be 'root'\n\nSpecify at least 1 USER command in Dockerfile with non-root user as argument\n\nRule: DS-0002\nSeverity: HIGH\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-72ff79e0f8219b60", "name": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile", "shortDescription": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile"}, "fullDescription": {"text": "'RUN cd ...' to change directory\n\nRUN should not be used to change directory: 'apt-get update &&     apt-get install -y --no-install-recommends         ca-certificates         build-essential         jq         libexpat1-dev         libgd-dev         zlib1g-dev         curl         cmake         pkg-config         libtool &&     mkdir -p $GRAPHVIZ_BUILD_DIR &&     cd $GRAPHVIZ_BUILD_DIR &&     GRAPHVIZ_VERSION=${GRAPHVIZ_VERSION:-$(curl -s https://gitlab.com/api/v4/projects/4207231/releases/ | jq -r '.[] | .name' | sort -V -r | \n\nRule: DS-0013\nSeverity: MEDIUM\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c4041c454cda88e", "name": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile", "shortDescription": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "fullDescription": {"text": "No HEALTHCHECK defined\n\nAdd HEALTHCHECK instruction in your Dockerfile\n\nRule: DS-0026\nSeverity: LOW\nTarget: Dockerfile"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2679282aa1c484b5", "name": "Agent authority lacks a verifier contract: AGENTS.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: AGENTS.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4464cc6cd54be57d", "name": "Agent authority lacks a verifier contract: .claude/agents/release.agent.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/agents/release.agent.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b98d57abf36ee64c", "name": "Agent authority lacks a verifier contract: skills/likec4-dsl/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/likec4-dsl/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan skills/likec4-dsl --format sarif --outp"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8b20daabca537667", "name": "Docker base image is tag-pinned but not digest-pinned: node:22.22.3-bookworm", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22.22.3-bookworm"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa5ad1dd4605d1da", "name": "Docker base image is tag-pinned but not digest-pinned: node:22.22.3-bookworm-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22.22.3-bookworm-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-01ecdd95cb21cf16", "name": "Insecure pattern 'local_storage_auth_token' in apps/playground/src/components/appshell/UserButton.tsx:47", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in apps/playground/src/components/appshell/UserButton.tsx:47"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f48dfc26c822f27", "name": "Insecure pattern 'cors_wildcard' in packages/mcp/src/server/StreamableLikeC4MCPServer.ts:25", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in packages/mcp/src/server/StreamableLikeC4MCPServer.ts:25"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e90da1b9133b8514", "name": "Insecure pattern 'node_child_process' in packages/diagram/vite.config.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/diagram/vite.config.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.9}}, {"id": "scanner-6c2e838dd958185b", "name": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/LikeC4Styles.tsx:107", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/LikeC4Styles.tsx:107"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-645b6d02bf3925fa", "name": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/shadowroot/ShadowRoot.tsx:173", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/shadowroot/ShadowRoot.tsx:173"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-3702ed2ee878a1dd", "name": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/context/TagStylesContext.tsx:77", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/context/TagStylesContext.tsx:77"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-a6cde56f2871f14b", "name": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/context/IconRenderer.tsx:194", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/context/IconRenderer.tsx:194"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-123b5d53cc496bb1", "name": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/base-primitives/Markdown.tsx:9", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/base-primitives/Markdown.tsx:9"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-95ae98b0af7adf01", "name": "Insecure pattern 'new_function_used' in packages/icons/scripts/prerender-svg.mjs:45", "shortDescription": {"text": "Insecure pattern 'new_function_used' in packages/icons/scripts/prerender-svg.mjs:45"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ab35855379418698", "name": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/expressions.spec.ts:17", "shortDescription": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/expressions.spec.ts:17"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e22a8d0a72e77db", "name": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/properties.spec.ts:17", "shortDescription": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/properties.spec.ts:17"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7995483e20d4cc35", "name": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/base.spec.ts:40", "shortDescription": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/base.spec.ts:40"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e99b9487c001d155", "name": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/expressions.ts:160", "shortDescription": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/expressions.ts:160"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-273b534c7f7a2a07", "name": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/views.ts:77", "shortDescription": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/views.ts:77"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64a2855ea30c5317", "name": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsDot.tsx:31", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsDot.tsx:31"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-0d8025d651d551be", "name": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsD2.tsx:71", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsD2.tsx:71"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-fb5bb1ea6075ff65", "name": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsMmd.tsx:56", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsMmd.tsx:56"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-4a5e570947125622", "name": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsPuml.tsx:69", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsPuml.tsx:69"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.65}}, {"id": "scanner-65aa740cba4a4a73", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aedc8731e312291e", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-086ec83e9465da3a", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-abe3b73e6139548b", "name": "pull_request_target workflow appears to check out untrusted PR code", "shortDescription": {"text": "pull_request_target workflow appears to check out untrusted PR code"}, "fullDescription": {"text": "pull_request_target runs with base-repo privileges. Checking out PR head code in that context can expose repository tokens or secrets to attacker-controlled code."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9645d38058e18095", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6adb60f4d8515fbc", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/github-script@v8 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-85c05d0cae247dcd", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e2d0519635166268", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "pnpm/action-setup@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7dc7c1e428a24a89", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-941b767627e5c8c4", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "peter-evans/repository-dispatch@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bde84117402b3e2c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v7 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-adf12377b1a303ec", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "cloudflare/wrangler-action@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13e5ad85fc4fc86c", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "peter-evans/create-pull-request@v8 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fdb8a76317f1eee1", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cfcd474feae0153b", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d7e834080dbebed", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "changesets/action@v1 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-299e5e0d9ac9f81f", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c2c7eb004a085af", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v7 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b40816ce6a870dc6", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v7 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9466de6abbe2c0b8", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "docker/setup-docker-action@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-562504aada59f017", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb639d9a10a47b23", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58d62f5c6b8bc69b", "name": "Very large file: packages/icons/tech/tastejs.tsx (1631 lines)", "shortDescription": {"text": "Very large file: packages/icons/tech/tastejs.tsx (1631 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8911b023c2695a9", "name": "Very large file: packages/icons/tech/index.ts (2000 lines)", "shortDescription": {"text": "Very large file: packages/icons/tech/index.ts (2000 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2444183221362c6", "name": "Very large file: packages/icons/tech/sugarss.tsx (834 lines)", "shortDescription": {"text": "Very large file: packages/icons/tech/sugarss.tsx (834 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e7fa601c70961b3", "name": "Very large file: packages/icons/tech/linux.tsx (3092 lines)", "shortDescription": {"text": "Very large file: packages/icons/tech/linux.tsx (3092 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-23958dd388793cee", "name": "Very large file: packages/icons/tech/memgraph.tsx (2313 lines)", "shortDescription": {"text": "Very large file: packages/icons/tech/memgraph.tsx (2313 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ebfb1a6ea63cc7e7", "name": "Very large file: packages/icons/bootstrap/index.ts (2051 lines)", "shortDescription": {"text": "Very large file: packages/icons/bootstrap/index.ts (2051 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c49fb370249d58a1", "name": "Very large file: packages/language-server/src/workspace/ProjectsManager.spec.ts (1346 lines)", "shortDescription": {"text": "Very large file: packages/language-server/src/workspace/ProjectsManager.spec.ts (1346 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49e3bbf97ee82bf3", "name": "Very large file: packages/language-server/src/formatting/LikeC4Formatter.spec.ts (2128 lines)", "shortDescription": {"text": "Very large file: packages/language-server/src/formatting/LikeC4Formatter.spec.ts (2128 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77a3dd2aa8905980", "name": "Very large file: packages/generators/src/drawio/parse-drawio.ts (1996 lines)", "shortDescription": {"text": "Very large file: packages/generators/src/drawio/parse-drawio.ts (1996 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db8171af90fe543f", "name": "Very large file: packages/generators/src/drawio/generate-drawio.ts (1431 lines)", "shortDescription": {"text": "Very large file: packages/generators/src/drawio/generate-drawio.ts (1431 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "162 test file(s) for 6492 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5b99d1a3a09b1419", "name": "32 TODO/FIXME markers", "shortDescription": {"text": "32 TODO/FIXME markers"}, "fullDescription": {"text": "High count of TODO/FIXME/HACK markers \u2014 track them as issues so they're not forgotten."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-577e6d5469194fe6", "name": "Node manifest has dependencies but no lockfile: styled-system/preset/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: styled-system/preset/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f9003bc06de6043", "name": "Node manifest has dependencies but no lockfile: styled-system/styles/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: styled-system/styles/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a59386c68de50fc", "name": "Node manifest has dependencies but no lockfile: apps/playground/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/playground/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f84d18439696f71", "name": "Node manifest has dependencies but no lockfile: apps/docs/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/docs/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63f2d56cec85b7f3", "name": "Node manifest has dependencies but no lockfile: packages/create-likec4/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/create-likec4/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b24578f9e802c3a7", "name": "Node manifest has dependencies but no lockfile: packages/create-likec4/template/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/create-likec4/template/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ca655118d4b75e9", "name": "Node manifest has dependencies but no lockfile: packages/vscode-preview/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/vscode-preview/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fc79ab9c1d1589c", "name": "Node manifest has dependencies but no lockfile: packages/config/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/config/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7a39c3ee75d357e", "name": "Node manifest has dependencies but no lockfile: packages/language-services/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/language-services/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93cf61dbf59813a8", "name": "Node manifest has dependencies but no lockfile: packages/vscode/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/vscode/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be458b5a9a2261bf", "name": "Node manifest has dependencies but no lockfile: packages/mcp/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/mcp/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-feb7d4d7a4aff9ad", "name": "Node manifest has dependencies but no lockfile: packages/diagram/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/diagram/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e7508869b10a649", "name": "Node manifest has dependencies but no lockfile: packages/vite-plugin/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/vite-plugin/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-22dc28eb18ff2862", "name": "Node manifest has dependencies but no lockfile: packages/react/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/react/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-785efb308883920e", "name": "Node manifest has dependencies but no lockfile: packages/log/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/log/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-329bfc097219bd77", "name": "Node manifest has dependencies but no lockfile: packages/icons/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/icons/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ada30b496643aab", "name": "Node manifest has dependencies but no lockfile: packages/core/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-055e6d3fe9b6e226", "name": "Node manifest has dependencies but no lockfile: packages/language-server/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/language-server/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91cdc2f03ab4a218", "name": "Node manifest has dependencies but no lockfile: packages/lsp/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/lsp/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b66ad9f79ad402c", "name": "Node manifest has dependencies but no lockfile: packages/likec4/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/likec4/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11f7e1a2099517a3", "name": "Node manifest has dependencies but no lockfile: packages/layouts/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/layouts/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bc387f8a44cfef2", "name": "Node manifest has dependencies but no lockfile: packages/generators/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/generators/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47d7261e52b2f0fe", "name": "Node manifest has dependencies but no lockfile: packages/likec4-spa/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/likec4-spa/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7146d8a45f56b47", "name": "Node manifest has dependencies but no lockfile: packages/leanix-bridge/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/leanix-bridge/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-378f40fda6d85a8c", "name": "Node manifest has dependencies but no lockfile: devops/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: devops/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50bd2f3a273b7c84", "name": "Node manifest has dependencies but no lockfile: e2e/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: e2e/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 118 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 28 placeholder/mock markers across 15 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4e41f5b8affc8cb", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 apps/playground/worker/index.ts:77", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 apps/playground/worker/index.ts:77"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-2fcdba371c8199b9", "name": "Commented-code block (6 lines) in apps/playground/worker/types.ts:56", "shortDescription": {"text": "Commented-code block (6 lines) in apps/playground/worker/types.ts:56"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-8a47a5a31215f31b", "name": "Fire-and-forget `fetch()` has no rejection handler \u2014 apps/docs/src/lib/githubdata.ts:187", "shortDescription": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 apps/docs/src/lib/githubdata.ts:187"}, "fullDescription": {"text": "This fetch result is neither awaited, returned, assigned, nor followed by `.catch(...)`. A network failure can therefore become an unhandled promise rejection. Await/return the promise or attach an explicit rejection handler."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-5b4c5f67ac560c33", "name": "Commented-code block (11 lines) in packages/vscode/src/useMessenger.ts:178", "shortDescription": {"text": "Commented-code block (11 lines) in packages/vscode/src/useMessenger.ts:178"}, "fullDescription": {"text": "10 of 11 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-c2de0493242122a4", "name": "Commented-code block (9 lines) in packages/diagram/src/search/components/styles.css.ts:50", "shortDescription": {"text": "Commented-code block (9 lines) in packages/diagram/src/search/components/styles.css.ts:50"}, "fullDescription": {"text": "5 of 9 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-09ddbbd0dd06e763", "name": "Commented-code block (5 lines) in packages/diagram/src/likec4diagram/state/utils.ts:93", "shortDescription": {"text": "Commented-code block (5 lines) in packages/diagram/src/likec4diagram/state/utils.ts:93"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-e58d7286af57299c", "name": "Legacy-named symbol `SvgEslintOld` in packages/icons/tech/eslint-old.tsx:4", "shortDescription": {"text": "Legacy-named symbol `SvgEslintOld` in packages/icons/tech/eslint-old.tsx:4"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-712fb867b978f344", "name": "Legacy-named symbol `EslintOld` in packages/icons/tech/index.ts:583", "shortDescription": {"text": "Legacy-named symbol `EslintOld` in packages/icons/tech/index.ts:583"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1145d0ea19190e29", "name": "Legacy-named symbol `ContainerServicesDeprecated` in packages/icons/azure/index.ts:182", "shortDescription": {"text": "Legacy-named symbol `ContainerServicesDeprecated` in packages/icons/azure/index.ts:182"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-872cb00feaf95115", "name": "Legacy-named symbol `SvgContainerServicesDeprecated` in packages/icons/azure/container-services-deprecated.tsx:4", "shortDescription": {"text": "Legacy-named symbol `SvgContainerServicesDeprecated` in packages/icons/azure/container-services-deprecated.tsx:4"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e2521a686b53adf", "name": "Commented-code block (5 lines) in packages/core/src/model/connection/ops.ts:258", "shortDescription": {"text": "Commented-code block (5 lines) in packages/core/src/model/connection/ops.ts:258"}, "fullDescription": {"text": "5 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-fb1e0cf5db7a6e27", "name": "Commented-code block (11 lines) in packages/core/src/compute-view/element-view/clean-connections.ts:27", "shortDescription": {"text": "Commented-code block (11 lines) in packages/core/src/compute-view/element-view/clean-connections.ts:27"}, "fullDescription": {"text": "11 of 11 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-76d1b7f9e00a3fc4", "name": "Legacy-named symbol `mute_old` in packages/core/src/compute-view/element-view/__test__/fixture.ts:355", "shortDescription": {"text": "Legacy-named symbol `mute_old` in packages/core/src/compute-view/element-view/__test__/fixture.ts:355"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-798fa3c1d7fd61e5", "name": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-direct.ts:27", "shortDescription": {"text": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-direct.ts:27"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-0105e62fe0846ac8", "name": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-incoming.ts:80", "shortDescription": {"text": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-incoming.ts:80"}, "fullDescription": {"text": "5 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-41269faeb91f80ea", "name": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-outgoing.ts:74", "shortDescription": {"text": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-outgoing.ts:74"}, "fullDescription": {"text": "5 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-7413523b53463808", "name": "Commented-code block (5 lines) in packages/core/src/compute-view/deployment-view/stages/stage-final.ts:38", "shortDescription": {"text": "Commented-code block (5 lines) in packages/core/src/compute-view/deployment-view/stages/stage-final.ts:38"}, "fullDescription": {"text": "4 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-a96fae56b1ffb324", "name": "Commented-code block (9 lines) in packages/core/src/compute-view/relationships-view/layout.ts:61", "shortDescription": {"text": "Commented-code block (9 lines) in packages/core/src/compute-view/relationships-view/layout.ts:61"}, "fullDescription": {"text": "8 of 9 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-5ca88393cb772ac8", "name": "Commented-code block (11 lines) in packages/language-server/src/validation/imports.ts:32", "shortDescription": {"text": "Commented-code block (11 lines) in packages/language-server/src/validation/imports.ts:32"}, "fullDescription": {"text": "10 of 11 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-17cfcca09f2bc6b0", "name": "Commented-code block (6 lines) in packages/likec4/src/cli/serve/serve.ts:125", "shortDescription": {"text": "Commented-code block (6 lines) in packages/likec4/src/cli/serve/serve.ts:125"}, "fullDescription": {"text": "6 of 6 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-97390224a4fede93", "name": "Commented-code block (8 lines) in packages/layouts/src/graphviz/dot-labels.ts:211", "shortDescription": {"text": "Commented-code block (8 lines) in packages/layouts/src/graphviz/dot-labels.ts:211"}, "fullDescription": {"text": "4 of 8 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-c1eb4eb50ff83b3d", "name": "Commented-code block (5 lines) in packages/layouts/src/graphviz/QueueGraphvizLayoter.ts:155", "shortDescription": {"text": "Commented-code block (5 lines) in packages/layouts/src/graphviz/QueueGraphvizLayoter.ts:155"}, "fullDescription": {"text": "3 of 5 consecutive comment lines look like executable statements. Confirm the block is obsolete, then delete it or recover it from git history when needed."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 0.72}}, {"id": "scanner-5653dc0d42b22458", "name": "Legacy-named symbol `cloud_legacy` in e2e/src/likec4-model.test-d.ts:72", "shortDescription": {"text": "Legacy-named symbol `cloud_legacy` in e2e/src/likec4-model.test-d.ts:72"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-34bf1b8c94367afb", "name": "Legacy-named symbol `cloud_legacy` in e2e/src/likec4-views.test-d.ts:79", "shortDescription": {"text": "Legacy-named symbol `cloud_legacy` in e2e/src/likec4-views.test-d.ts:79"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67984f56ee9f3426", "name": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.14` (resolved in `pnpm-lock.yaml`) is affected by GHSA-frvp-7c67-39w9.\n\nNode.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58d0f5c5b5cb2ac3", "name": "Vulnerable dependency esbuild 0.27.3: GHSA-g7r4-m6w7-qqqr", "shortDescription": {"text": "Vulnerable dependency esbuild 0.27.3: GHSA-g7r4-m6w7-qqqr"}, "fullDescription": {"text": "OSV.dev reports `esbuild` at version `0.27.3` (resolved in `pnpm-lock.yaml`) is affected by GHSA-g7r4-m6w7-qqqr.\n\nesbuild allows arbitrary file read when running the development server on Windows\n\nAdvisory: https://osv.dev/vulnerability/GHSA-g7r4-m6w7-qqqr\nFix: upgrade `esbuild` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0caa6a61eb89b7cb", "name": "Vulnerable dependency sharp 0.34.5: GHSA-f88m-g3jw-g9cj", "shortDescription": {"text": "Vulnerable dependency sharp 0.34.5: GHSA-f88m-g3jw-g9cj"}, "fullDescription": {"text": "OSV.dev reports `sharp` at version `0.34.5` (resolved in `pnpm-lock.yaml`) is affected by GHSA-f88m-g3jw-g9cj.\n\nsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591\n\nAdvisory: https://osv.dev/vulnerability/GHSA-f88m-g3jw-g9cj\nFix: upgrade `sharp` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a3fe169b62730d62", "name": "Vulnerable dependency ws 8.18.0: GHSA-58qx-3vcg-4xpx", "shortDescription": {"text": "Vulnerable dependency ws 8.18.0: GHSA-58qx-3vcg-4xpx"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.18.0` (resolved in `pnpm-lock.yaml`) is affected by GHSA-58qx-3vcg-4xpx (aka CVE-2026-45736).\n\nws: Uninitialized memory disclosure\n\nAliases: CVE-2026-45736\nAdvisory: https://osv.dev/vulnerability/GHSA-58qx-3vcg-4xpx\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3fe816a6ef728b4", "name": "Vulnerable dependency ws 8.18.0: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "Vulnerable dependency ws 8.18.0: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.18.0` (resolved in `pnpm-lock.yaml`) is affected by GHSA-96hv-2xvq-fx4p (aka CVE-2026-48779).\n\nws: Memory exhaustion DoS from tiny fragments and data chunks\n\nAliases: CVE-2026-48779\nAdvisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-50a0ccef57d8b8f3", "name": "Vulnerable dependency ws 8.20.1: GHSA-96hv-2xvq-fx4p", "shortDescription": {"text": "Vulnerable dependency ws 8.20.1: GHSA-96hv-2xvq-fx4p"}, "fullDescription": {"text": "OSV.dev reports `ws` at version `8.20.1` (resolved in `pnpm-lock.yaml`) is affected by GHSA-96hv-2xvq-fx4p (aka CVE-2026-48779).\n\nws: Memory exhaustion DoS from tiny fragments and data chunks\n\nAliases: CVE-2026-48779\nAdvisory: https://osv.dev/vulnerability/GHSA-96hv-2xvq-fx4p\nFix: upgrade `ws` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d8bab24956e6a57", "name": "Dependency @codingame/monaco-vscode-editor-api is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-editor-api is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-editor-api` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-editor-api` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7d403217964b90cf", "name": "Dependency @codingame/monaco-vscode-editor-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-editor-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-editor-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-editor-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-d2030fe1a2fbbf18", "name": "Dependency @codingame/monaco-vscode-files-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-files-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-files-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-files-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-80d43a1ab9e7f438", "name": "Dependency @codingame/monaco-vscode-keybindings-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-keybindings-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-keybindings-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-keybindings-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-47453df35acdc587", "name": "Dependency @codingame/monaco-vscode-lifecycle-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-lifecycle-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-lifecycle-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-lifecycle-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-10b0f5021a110f4e", "name": "Dependency @codingame/monaco-vscode-textmate-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-textmate-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-textmate-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-textmate-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-88798c5cf9480b43", "name": "Dependency @codingame/monaco-vscode-theme-defaults-default-extension is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-theme-defaults-default-extension is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-theme-defaults-default-extension` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-theme-defaults-default-extension` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-7aef9cd0c304a04b", "name": "Dependency @codingame/monaco-vscode-theme-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-theme-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-theme-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-theme-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ff1edecd51a35ddc", "name": "Dependency @codingame/monaco-vscode-views-service-override is two or more major versions behind", "shortDescription": {"text": "Dependency @codingame/monaco-vscode-views-service-override is two or more major versions behind"}, "fullDescription": {"text": "`@codingame/monaco-vscode-views-service-override` is pinned at `16.1.1` in `apps/playground/package.json` while the latest release on the npm registry is `36.0.0` \u2014 20 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@codingame/monaco-vscode-views-service-override` to `36.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-67a663527529d914", "name": "Dependency @typefox/monaco-editor-react is a major version behind", "shortDescription": {"text": "Dependency @typefox/monaco-editor-react is a major version behind"}, "fullDescription": {"text": "`@typefox/monaco-editor-react` is pinned at `6.7.0` in `apps/playground/package.json` while the latest release on the npm registry is `7.7.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@typefox/monaco-editor-react` to `7.7.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-4c52a8b5c25787c4", "name": "Dependency @types/node is two or more major versions behind", "shortDescription": {"text": "Dependency @types/node is two or more major versions behind"}, "fullDescription": {"text": "`@types/node` is pinned at `22.19.17` in `e2e/package.json` while the latest release on the npm registry is `26.1.1` \u2014 4 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@types/node` to `26.1.1`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-667185838da0280d", "name": "Dependency monaco-languageclient is a major version behind", "shortDescription": {"text": "Dependency monaco-languageclient is a major version behind"}, "fullDescription": {"text": "`monaco-languageclient` is pinned at `9.6.0` in `apps/playground/package.json` while the latest release on the npm registry is `10.7.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `monaco-languageclient` to `10.7.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-78474aa6edcf52ec", "name": "Dependency std-env is a major version behind", "shortDescription": {"text": "Dependency std-env is a major version behind"}, "fullDescription": {"text": "`std-env` is pinned at `3.9.0` in `e2e/package.json` while the latest release on the npm registry is `4.2.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `std-env` to `4.2.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-7b31aae5d4ddd33b", "name": "Dependency typescript is two or more major versions behind", "shortDescription": {"text": "Dependency typescript is two or more major versions behind"}, "fullDescription": {"text": "`typescript` is pinned at `5.9.3` in `e2e/package.json` while the latest release on the npm registry is `7.0.2` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `typescript` to `7.0.2`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-4396f2c909b6e017", "name": "Dependency which is two or more major versions behind", "shortDescription": {"text": "Dependency which is two or more major versions behind"}, "fullDescription": {"text": "`which` is pinned at `5.0.0` in `packages/language-server/package.json` while the latest release on the npm registry is `7.0.0` \u2014 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `which` to `7.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-ad136b8f8eba3186", "name": "Dependency yargs is a major version behind", "shortDescription": {"text": "Dependency yargs is a major version behind"}, "fullDescription": {"text": "`yargs` is pinned at `17.7.2` in `packages/likec4/package.json` while the latest release on the npm registry is `18.0.0` \u2014 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `yargs` to `18.0.0`."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 0.9}}, {"id": "scanner-b5d1fd957e3a5ed2", "name": "2 backend endpoints not called by scanned frontend", "shortDescription": {"text": "2 backend endpoints not called by scanned frontend"}, "fullDescription": {"text": "No scanned frontend call matched these backend routes. Sample: ALL /mcp, USE /__likec4_ai. This is fine when endpoints serve external clients (mobile apps, SDKs, third-party integrations, server-side webhooks). Otherwise document consumers or remove dead routes."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/30743"}, "properties": {"repository": "likec4/likec4", "repoUrl": "https://github.com/likec4/likec4", "branch": "main"}, "results": [{"ruleId": "scanner-e9fc22b9ae7b1ffa", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 styled-system/preset/src/globalCss.ts:31"}, "properties": {"repobilityId": "f32ec69e56680e69", "scanner": "scanner-primary", "fingerprint": "e9fc22b9ae7b1ffa", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "styled-system/preset/src/globalCss.ts"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-a4d4652bdd152c5b", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 apps/playground/worker/viewkv.tsx:46"}, "properties": {"repobilityId": "1c4c95c6a13e4166", "scanner": "scanner-primary", "fingerprint": "a4d4652bdd152c5b", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/worker/viewkv.tsx"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-def4f74c3a710bd0", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 apps/playground/worker/api.share.ts:24"}, "properties": {"repobilityId": "41a282dafaf711fb", "scanner": "scanner-primary", "fingerprint": "def4f74c3a710bd0", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/worker/api.share.ts"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-e957fa601c6adb24", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/worker/api.share.ts:47"}, "properties": {"repobilityId": "339e0869c2a60fe5", "scanner": "scanner-primary", "fingerprint": "e957fa601c6adb24", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/worker/api.share.ts"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-0106444ac12a0247", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/state/context.tsx:21"}, "properties": {"repobilityId": "8b75180b1d1841d8", "scanner": "scanner-primary", "fingerprint": "0106444ac12a0247", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/src/state/context.tsx"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-0c7c8b8cc7501c32", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/monaco/MonacoEditor.tsx:46"}, "properties": {"repobilityId": "e275498730be2be7", "scanner": "scanner-primary", "fingerprint": "0c7c8b8cc7501c32", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/src/monaco/MonacoEditor.tsx"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-b0a5ebe57ef402e1", "level": "note", "message": {"text": "Debug `console.log` remains in browser-facing code \u2014 apps/playground/src/routes/share.$shareId/view/route.tsx:29"}, "properties": {"repobilityId": "c9cc6bad9235c18b", "scanner": "scanner-primary", "fingerprint": "b0a5ebe57ef402e1", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.console-leak"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/src/routes/share.$shareId/view/route.tsx"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-d56eeea49cf5556a", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/vscode/vscode.proposed.chatParticipantAdditions.d.ts:790"}, "properties": {"repobilityId": "5fec59e0de25bbf0", "scanner": "scanner-primary", "fingerprint": "d56eeea49cf5556a", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vscode/vscode.proposed.chatParticipantAdditions.d.ts"}, "region": {"startLine": 790}}}]}, {"ruleId": "scanner-6a622cdd59c40783", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/LikeC4Styles.tsx:107"}, "properties": {"repobilityId": "18300b50e0a41b34", "scanner": "scanner-primary", "fingerprint": "6a622cdd59c40783", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/LikeC4Styles.tsx"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-d69780646a17724d", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/shadowroot/ShadowRoot.tsx:173"}, "properties": {"repobilityId": "ab68126bf10c37ae", "scanner": "scanner-primary", "fingerprint": "d69780646a17724d", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/shadowroot/ShadowRoot.tsx"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-97fbd32550fda8df", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/utils/xyflow.ts:174"}, "properties": {"repobilityId": "8d2e364af87da065", "scanner": "scanner-primary", "fingerprint": "97fbd32550fda8df", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/utils/xyflow.ts"}, "region": {"startLine": 174}}}]}, {"ruleId": "scanner-3ba2179dcad90950", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/components/SearchControl.css.ts:8"}, "properties": {"repobilityId": "e680c84fe4237233", "scanner": "scanner-primary", "fingerprint": "3ba2179dcad90950", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/components/SearchControl.css.ts"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-779b5b84b6b31d53", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/navigationpanel/editorpanel/ChangeAutoLayoutButton.tsx:78"}, "properties": {"repobilityId": "318af446dcd41ba8", "scanner": "scanner-primary", "fingerprint": "779b5b84b6b31d53", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/navigationpanel/editorpanel/ChangeAutoLayoutButton.tsx"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-a87730d34eb4e6b7", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/context/TagStylesContext.tsx:77"}, "properties": {"repobilityId": "e5e5191a2b4387a1", "scanner": "scanner-primary", "fingerprint": "a87730d34eb4e6b7", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/context/TagStylesContext.tsx"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-3f36fa18b4d188df", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/context/IconRenderer.tsx:194"}, "properties": {"repobilityId": "285a41aaf3ec0df8", "scanner": "scanner-primary", "fingerprint": "3f36fa18b4d188df", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/context/IconRenderer.tsx"}, "region": {"startLine": 194}}}]}, {"ruleId": "scanner-c662dfbc86dee471", "level": "note", "message": {"text": "React Flow <Controls> without dark theming \u2014 packages/diagram/src/likec4diagram/DiagramXYFlow.tsx:313"}, "properties": {"repobilityId": "af5fd09f52a97a63", "scanner": "scanner-primary", "fingerprint": "c662dfbc86dee471", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.controls.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/likec4diagram/DiagramXYFlow.tsx"}, "region": {"startLine": 313}}}]}, {"ruleId": "scanner-5cf9e6d47e7f7073", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/likec4diagram/state/machine.setup.ts:363"}, "properties": {"repobilityId": "a1d09f1708a9b814", "scanner": "scanner-primary", "fingerprint": "5cf9e6d47e7f7073", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/likec4diagram/state/machine.setup.ts"}, "region": {"startLine": 363}}}]}, {"ruleId": "scanner-9a567b566b3e876d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/likec4diagram/custom/nodes/toolbar/Toolbar.tsx:50"}, "properties": {"repobilityId": "6bcd62eeeed34fd0", "scanner": "scanner-primary", "fingerprint": "9a567b566b3e876d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/likec4diagram/custom/nodes/toolbar/Toolbar.tsx"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-04f8ee7a05c08c62", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/diagram/src/base-primitives/Markdown.tsx:57"}, "properties": {"repobilityId": "f13fb5fb0a8312ad", "scanner": "scanner-primary", "fingerprint": "04f8ee7a05c08c62", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/base-primitives/Markdown.tsx"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-f5c29582f6c715ff", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/diagram/src/overlays/overlaysActor.ts:40"}, "properties": {"repobilityId": "c0e58f6a0c0d9743", "scanner": "scanner-primary", "fingerprint": "f5c29582f6c715ff", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/overlays/overlaysActor.ts"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-e57e6c4c4771f810", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/element-view/__test__/legacy.spec.ts:64"}, "properties": {"repobilityId": "ef96bc368f53d9d6", "scanner": "scanner-primary", "fingerprint": "e57e6c4c4771f810", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/element-view/__test__/legacy.spec.ts"}, "region": {"startLine": 64}}}]}, {"ruleId": "scanner-e9ffb71a11131ce9", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/predicates/utils.ts:301"}, "properties": {"repobilityId": "ad0323a95ee9b762", "scanner": "scanner-primary", "fingerprint": "e9ffb71a11131ce9", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/predicates/utils.ts"}, "region": {"startLine": 301}}}]}, {"ruleId": "scanner-9b7cd98311681a54", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/stages/stage-include.spec.ts:155"}, "properties": {"repobilityId": "c6c166efc3f70928", "scanner": "scanner-primary", "fingerprint": "9b7cd98311681a54", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/stages/stage-include.spec.ts"}, "region": {"startLine": 155}}}]}, {"ruleId": "scanner-c0eea685a3fd9b5c", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/core/src/compute-view/deployment-view/stages/stage-final.ts:195"}, "properties": {"repobilityId": "fbf1dd3f088e000f", "scanner": "scanner-primary", "fingerprint": "c0eea685a3fd9b5c", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/stages/stage-final.ts"}, "region": {"startLine": 195}}}]}, {"ruleId": "scanner-64c8413803c898c4", "level": "note", "message": {"text": "React Flow edge with `label=` but no project-wide edge-label CSS override \u2014 packages/core/src/compute-view/utils/view-hash.ts:39"}, "properties": {"repobilityId": "dc0acb4b7734dbe2", "scanner": "scanner-primary", "fingerprint": "64c8413803c898c4", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.edge-label.no-bg"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/utils/view-hash.ts"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-56562e081eac9d49", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/filesystem/LikeC4ManualLayouts.ts:99"}, "properties": {"repobilityId": "1979cce3bb7a03e8", "scanner": "scanner-primary", "fingerprint": "56562e081eac9d49", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/filesystem/LikeC4ManualLayouts.ts"}, "region": {"startLine": 99}}}]}, {"ruleId": "scanner-1245bb490925f403", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/filesystem/LikeC4ManualLayouts.spec.ts:453"}, "properties": {"repobilityId": "58eb184d979c9c76", "scanner": "scanner-primary", "fingerprint": "1245bb490925f403", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/filesystem/LikeC4ManualLayouts.spec.ts"}, "region": {"startLine": 453}}}]}, {"ruleId": "scanner-bfd01d3b843f821a", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/__tests__/model.spec.ts:234"}, "properties": {"repobilityId": "7734137bea77fadc", "scanner": "scanner-primary", "fingerprint": "bfd01d3b843f821a", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/__tests__/model.spec.ts"}, "region": {"startLine": 234}}}]}, {"ruleId": "scanner-f176f0eaecfb6323", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/model-change/ModelChanges.ts:62"}, "properties": {"repobilityId": "c874f303391e50a3", "scanner": "scanner-primary", "fingerprint": "f176f0eaecfb6323", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/model-change/ModelChanges.ts"}, "region": {"startLine": 62}}}]}, {"ruleId": "scanner-1439ba2bb1def4c2", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/model/model-locator.ts:136"}, "properties": {"repobilityId": "68ac2ab779719ff9", "scanner": "scanner-primary", "fingerprint": "1439ba2bb1def4c2", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/model/model-locator.ts"}, "region": {"startLine": 136}}}]}, {"ruleId": "scanner-30df46db968607e5", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/lsp/DocumentSymbolProvider.ts:205"}, "properties": {"repobilityId": "cfa0a1feaa273e74", "scanner": "scanner-primary", "fingerprint": "30df46db968607e5", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/lsp/DocumentSymbolProvider.ts"}, "region": {"startLine": 205}}}]}, {"ruleId": "scanner-e83563868b80c84d", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/language-server/src/lsp/CompletionProvider.spec.ts:992"}, "properties": {"repobilityId": "132f027055cb814d", "scanner": "scanner-primary", "fingerprint": "e83563868b80c84d", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/lsp/CompletionProvider.spec.ts"}, "region": {"startLine": 992}}}]}, {"ruleId": "scanner-ab0ba7d5dda85359", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/likec4/src/vite/vite-preview.ts:32"}, "properties": {"repobilityId": "289a2f5109dd8330", "scanner": "scanner-primary", "fingerprint": "ab0ba7d5dda85359", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4/src/vite/vite-preview.ts"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-ea122cbade1b683a", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/layouts/src/graphviz/QueueGraphvizLayoter.ts:155"}, "properties": {"repobilityId": "79881364e956108a", "scanner": "scanner-primary", "fingerprint": "ea122cbade1b683a", "layer": "frontend", "severity": "info", "confidence": 0.7, "tags": ["frontend-quality", "fq.todo-marker"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/layouts/src/graphviz/QueueGraphvizLayoter.ts"}, "region": {"startLine": 155}}}]}, {"ruleId": "scanner-bff8ed141e04c9ef", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsDot.tsx:31"}, "properties": {"repobilityId": "492e642d19c03e80", "scanner": "scanner-primary", "fingerprint": "bff8ed141e04c9ef", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsDot.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-d4f24839798ad7c0", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsD2.tsx:71"}, "properties": {"repobilityId": "7ba8a2e06f188e06", "scanner": "scanner-primary", "fingerprint": "d4f24839798ad7c0", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsD2.tsx"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-3acabd3edf70b67e", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsMmd.tsx:56"}, "properties": {"repobilityId": "0df20685451fda73", "scanner": "scanner-primary", "fingerprint": "3acabd3edf70b67e", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsMmd.tsx"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-32a4fe99c1b91e04", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 packages/likec4-spa/src/pages/ViewAsPuml.tsx:69"}, "properties": {"repobilityId": "3f5acf85ff869be6", "scanner": "scanner-primary", "fingerprint": "32a4fe99c1b91e04", "layer": "frontend", "severity": "medium", "confidence": 0.8, "tags": ["frontend-quality", "fq.dangerous-html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsPuml.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-982c5296f8d89460", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/LikeC4Styles.tsx:107"}, "properties": {"repobilityId": "5f2b10eb90371b4a", "scanner": "scanner-primary", "fingerprint": "982c5296f8d89460", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/LikeC4Styles.tsx"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-c629f75001891a3d", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/base-primitives/Markdown.tsx:57"}, "properties": {"repobilityId": "4cef5648c79f1482", "scanner": "scanner-primary", "fingerprint": "c629f75001891a3d", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/base-primitives/Markdown.tsx"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-60e2dd9ac161b3af", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/context/TagStylesContext.tsx:77"}, "properties": {"repobilityId": "79e650b9a3c44772", "scanner": "scanner-primary", "fingerprint": "60e2dd9ac161b3af", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/context/TagStylesContext.tsx"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-78db9c70ef3313aa", "level": "warning", "message": {"text": "react dangerouslysetinnerhtml \u2014 packages/diagram/src/shadowroot/ShadowRoot.tsx:173"}, "properties": {"repobilityId": "3ac66afe68633031", "scanner": "scanner-primary", "fingerprint": "78db9c70ef3313aa", "layer": "security", "severity": "medium", "confidence": 0.7, "tags": ["semgrep", "security", "react"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/shadowroot/ShadowRoot.tsx"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-993552b71134bcb6", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.14 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "7a7c2342b3c17e8c", "scanner": "scanner-primary", "fingerprint": "993552b71134bcb6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-c9dadc5f9682a312", "level": "note", "message": {"text": "CVE-2026-12590: body-parser 2.2.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "c52a5d8da171f050", "scanner": "scanner-primary", "fingerprint": "c9dadc5f9682a312", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12590"]}}, {"ruleId": "scanner-c244ca577ede5b06", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 2.0.3 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "eedf4eae95361bb4", "scanner": "scanner-primary", "fingerprint": "c244ca577ede5b06", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-2f4940e308ee9766", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 4.0.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "eedf4eae95361bb4", "scanner": "scanner-primary", "fingerprint": "2f4940e308ee9766", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-0571f0916082f0b4", "level": "warning", "message": {"text": "CVE-2026-33750: brace-expansion 4.0.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "0e051d7cc2692dd1", "scanner": "scanner-primary", "fingerprint": "0571f0916082f0b4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-33750"]}}, {"ruleId": "scanner-37b28548b0918bab", "level": "error", "message": {"text": "CVE-2026-13149: brace-expansion 5.0.5 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "eedf4eae95361bb4", "scanner": "scanner-primary", "fingerprint": "37b28548b0918bab", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13149"]}}, {"ruleId": "scanner-92f5f86743908e9b", "level": "warning", "message": {"text": "CVE-2026-45149: brace-expansion 5.0.5 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "458f022300c5c9bd", "scanner": "scanner-primary", "fingerprint": "92f5f86743908e9b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45149"]}}, {"ruleId": "scanner-21802d4cdef662d3", "level": "note", "message": {"text": "CVE-2026-24001: diff 7.0.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "9b00d51cd6038a1d", "scanner": "scanner-primary", "fingerprint": "21802d4cdef662d3", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-24001"]}}, {"ruleId": "scanner-c3fb09555ec9db6b", "level": "note", "message": {"text": "CVE-2025-14505: elliptic 6.6.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "7ef81e2243f29d7d", "scanner": "scanner-primary", "fingerprint": "c3fb09555ec9db6b", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-14505"]}}, {"ruleId": "scanner-32938573f597b150", "level": "note", "message": {"text": "GHSA-g7r4-m6w7-qqqr: esbuild 0.27.3 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "e19cc30c5c9b0a60", "scanner": "scanner-primary", "fingerprint": "32938573f597b150", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-g7r4-m6w7-qqqr"]}}, {"ruleId": "scanner-9e925efd8793ae9b", "level": "error", "message": {"text": "CVE-2026-13676: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "22f3458cd6c077d8", "scanner": "scanner-primary", "fingerprint": "9e925efd8793ae9b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-13676"]}}, {"ruleId": "scanner-2281acd7795cdefe", "level": "error", "message": {"text": "CVE-2026-16221: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "d0a482fb1283ccc4", "scanner": "scanner-primary", "fingerprint": "2281acd7795cdefe", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-16221"]}}, {"ruleId": "scanner-ee58b7134906e5d0", "level": "error", "message": {"text": "CVE-2026-6321: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "235bcfe30a3ee7f4", "scanner": "scanner-primary", "fingerprint": "ee58b7134906e5d0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6321"]}}, {"ruleId": "scanner-fa67cc47d2cf8220", "level": "error", "message": {"text": "CVE-2026-6322: fast-uri 3.1.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "45d19c683e75019e", "scanner": "scanner-primary", "fingerprint": "fa67cc47d2cf8220", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6322"]}}, {"ruleId": "scanner-c39e60a99cd19f3b", "level": "warning", "message": {"text": "CVE-2026-42338: ip-address 10.1.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "51ecbe5de5837549", "scanner": "scanner-primary", "fingerprint": "c39e60a99cd19f3b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-42338"]}}, {"ruleId": "scanner-693d36861b537d20", "level": "error", "message": {"text": "CVE-2026-4800: lodash-es 4.17.21 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "9d209189a798223a", "scanner": "scanner-primary", "fingerprint": "693d36861b537d20", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-4800"]}}, {"ruleId": "scanner-54d8efaee3f14b51", "level": "warning", "message": {"text": "CVE-2025-13465: lodash-es 4.17.21 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "9081d1a405a97937", "scanner": "scanner-primary", "fingerprint": "54d8efaee3f14b51", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2025-13465"]}}, {"ruleId": "scanner-58afeacd92324a10", "level": "warning", "message": {"text": "CVE-2026-2950: lodash-es 4.17.21 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "88659273123e03cd", "scanner": "scanner-primary", "fingerprint": "58afeacd92324a10", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2950"]}}, {"ruleId": "scanner-284af2733559a755", "level": "error", "message": {"text": "CVE-2026-48712: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "5294751aa71cebd5", "scanner": "scanner-primary", "fingerprint": "284af2733559a755", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48712"]}}, {"ruleId": "scanner-68ad5daf168590ef", "level": "warning", "message": {"text": "CVE-2026-45740: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "dd1d2f6635ab2ab3", "scanner": "scanner-primary", "fingerprint": "68ad5daf168590ef", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45740"]}}, {"ruleId": "scanner-d8fbd64b9ed72ccd", "level": "warning", "message": {"text": "CVE-2026-54269: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "bc7be1a11f0831e7", "scanner": "scanner-primary", "fingerprint": "d8fbd64b9ed72ccd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-54269"]}}, {"ruleId": "scanner-0eb61ff523e5d94b", "level": "warning", "message": {"text": "CVE-2026-59877: protobufjs 7.5.6 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "e476f049a4a11e8e", "scanner": "scanner-primary", "fingerprint": "0eb61ff523e5d94b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-59877"]}}, {"ruleId": "scanner-404d8b2336db7441", "level": "error", "message": {"text": "GHSA-f88m-g3jw-g9cj: sharp 0.34.5 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "c4ad3b02581e456f", "scanner": "scanner-primary", "fingerprint": "404d8b2336db7441", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-f88m-g3jw-g9cj"]}}, {"ruleId": "scanner-6d8acbce5234a3ff", "level": "error", "message": {"text": "CVE-2026-12151: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "43b892875fa9caa6", "scanner": "scanner-primary", "fingerprint": "6d8acbce5234a3ff", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12151"]}}, {"ruleId": "scanner-24dd739a588c2add", "level": "error", "message": {"text": "CVE-2026-1526: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "96f4a9e8d717bb52", "scanner": "scanner-primary", "fingerprint": "24dd739a588c2add", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1526"]}}, {"ruleId": "scanner-b4b965b741ef572d", "level": "error", "message": {"text": "CVE-2026-1528: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "89ab921934d5e2d4", "scanner": "scanner-primary", "fingerprint": "b4b965b741ef572d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1528"]}}, {"ruleId": "scanner-8c86b43fb2647d14", "level": "error", "message": {"text": "CVE-2026-2229: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "eee37224a5f32db8", "scanner": "scanner-primary", "fingerprint": "8c86b43fb2647d14", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2229"]}}, {"ruleId": "scanner-703f5d0d0e208f40", "level": "warning", "message": {"text": "CVE-2026-1525: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "d12a160c186d7146", "scanner": "scanner-primary", "fingerprint": "703f5d0d0e208f40", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1525"]}}, {"ruleId": "scanner-f3f12011af70e20a", "level": "warning", "message": {"text": "CVE-2026-1527: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "b132a3b7cf2b43dc", "scanner": "scanner-primary", "fingerprint": "f3f12011af70e20a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-1527"]}}, {"ruleId": "scanner-f542ddebaaedae47", "level": "warning", "message": {"text": "CVE-2026-2581: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "0d43c7ea15fb8b19", "scanner": "scanner-primary", "fingerprint": "f542ddebaaedae47", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-2581"]}}, {"ruleId": "scanner-8901c221dad0f368", "level": "warning", "message": {"text": "CVE-2026-9678: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "8b7bc5ed1f65bf6e", "scanner": "scanner-primary", "fingerprint": "8901c221dad0f368", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9678"]}}, {"ruleId": "scanner-96d7a0ff40939a5b", "level": "warning", "message": {"text": "CVE-2026-9679: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "7181992331f10edf", "scanner": "scanner-primary", "fingerprint": "96d7a0ff40939a5b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9679"]}}, {"ruleId": "scanner-f4d7b050ba13e6a6", "level": "note", "message": {"text": "CVE-2026-11525: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "68c1d778b48fb6bc", "scanner": "scanner-primary", "fingerprint": "f4d7b050ba13e6a6", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-11525"]}}, {"ruleId": "scanner-87cdb31389dc830a", "level": "note", "message": {"text": "CVE-2026-6733: undici 7.18.2 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "f5a068a85a035106", "scanner": "scanner-primary", "fingerprint": "87cdb31389dc830a", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6733"]}}, {"ruleId": "scanner-e6f7b9acd0646f4f", "level": "error", "message": {"text": "CVE-2026-12151: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "43b892875fa9caa6", "scanner": "scanner-primary", "fingerprint": "e6f7b9acd0646f4f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-12151"]}}, {"ruleId": "scanner-8ad8fc3ecf1da3a0", "level": "error", "message": {"text": "CVE-2026-6734: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "114c7f56ef224afc", "scanner": "scanner-primary", "fingerprint": "8ad8fc3ecf1da3a0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6734"]}}, {"ruleId": "scanner-e815153881e360b4", "level": "error", "message": {"text": "CVE-2026-9697: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "1bc1c9bbf7812467", "scanner": "scanner-primary", "fingerprint": "e815153881e360b4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9697"]}}, {"ruleId": "scanner-9c6da4ddddc77ab9", "level": "warning", "message": {"text": "CVE-2026-9678: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "8b7bc5ed1f65bf6e", "scanner": "scanner-primary", "fingerprint": "9c6da4ddddc77ab9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9678"]}}, {"ruleId": "scanner-c40d1582b5784bb2", "level": "warning", "message": {"text": "CVE-2026-9679: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "7181992331f10edf", "scanner": "scanner-primary", "fingerprint": "c40d1582b5784bb2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-9679"]}}, {"ruleId": "scanner-fdf139b242dbef93", "level": "note", "message": {"text": "CVE-2026-11525: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "68c1d778b48fb6bc", "scanner": "scanner-primary", "fingerprint": "fdf139b242dbef93", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-11525"]}}, {"ruleId": "scanner-33b8054569796111", "level": "note", "message": {"text": "CVE-2026-6733: undici 7.24.8 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "f5a068a85a035106", "scanner": "scanner-primary", "fingerprint": "33b8054569796111", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-6733"]}}, {"ruleId": "scanner-d57769a75313f0c2", "level": "warning", "message": {"text": "CVE-2026-41907: uuid 9.0.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "ce64d4a91b418955", "scanner": "scanner-primary", "fingerprint": "d57769a75313f0c2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-41907"]}}, {"ruleId": "scanner-dd8ec5a200fa9359", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.18.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "3e3e7c29f5745cfa", "scanner": "scanner-primary", "fingerprint": "dd8ec5a200fa9359", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-d0df7f161352f4a8", "level": "warning", "message": {"text": "CVE-2026-45736: ws 8.18.0 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "641d2b16c8bb5383", "scanner": "scanner-primary", "fingerprint": "d0df7f161352f4a8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-45736"]}}, {"ruleId": "scanner-df43818ec803dac6", "level": "error", "message": {"text": "CVE-2026-48779: ws 8.20.1 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "3e3e7c29f5745cfa", "scanner": "scanner-primary", "fingerprint": "df43818ec803dac6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "vuln", "CVE-2026-48779"]}}, {"ruleId": "scanner-3a3527e70129fb18", "level": "error", "message": {"text": "DS-0002: Image user should not be 'root' \u2014 Dockerfile"}, "properties": {"repobilityId": "691787f6b20605df", "scanner": "scanner-primary", "fingerprint": "3a3527e70129fb18", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-72ff79e0f8219b60", "level": "warning", "message": {"text": "DS-0013: 'RUN cd ...' to change directory \u2014 Dockerfile"}, "properties": {"repobilityId": "975852f52ce6eb22", "scanner": "scanner-primary", "fingerprint": "72ff79e0f8219b60", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-3c4041c454cda88e", "level": "note", "message": {"text": "DS-0026: No HEALTHCHECK defined \u2014 Dockerfile"}, "properties": {"repobilityId": "da995bb2cfa21f65", "scanner": "scanner-primary", "fingerprint": "3c4041c454cda88e", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["trivy", "misconfig"]}}, {"ruleId": "scanner-2679282aa1c484b5", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: AGENTS.md"}, "properties": {"repobilityId": "27d579812e6be614", "scanner": "scanner-primary", "fingerprint": "2679282aa1c484b5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "AGENTS.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4464cc6cd54be57d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/agents/release.agent.md"}, "properties": {"repobilityId": "a6b3116502b086e6", "scanner": "scanner-primary", "fingerprint": "4464cc6cd54be57d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/release.agent.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b98d57abf36ee64c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/likec4-dsl/SKILL.md"}, "properties": {"repobilityId": "5daa3f39adcd714b", "scanner": "scanner-primary", "fingerprint": "b98d57abf36ee64c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/likec4-dsl/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-8b20daabca537667", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22.22.3-bookworm"}, "properties": {"repobilityId": "6ea59884d2344f76", "scanner": "scanner-primary", "fingerprint": "8b20daabca537667", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-fa5ad1dd4605d1da", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22.22.3-bookworm-slim"}, "properties": {"repobilityId": "5c20d7f3d3010d07", "scanner": "scanner-primary", "fingerprint": "fa5ad1dd4605d1da", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-01ecdd95cb21cf16", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in apps/playground/src/components/appshell/UserButton.tsx:47"}, "properties": {"repobilityId": "e15a702deb06ca6f", "scanner": "scanner-primary", "fingerprint": "01ecdd95cb21cf16", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/src/components/appshell/UserButton.tsx"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-8f48dfc26c822f27", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in packages/mcp/src/server/StreamableLikeC4MCPServer.ts:25"}, "properties": {"repobilityId": "49e3eeafaf74a5f5", "scanner": "scanner-primary", "fingerprint": "8f48dfc26c822f27", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/mcp/src/server/StreamableLikeC4MCPServer.ts"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-e90da1b9133b8514", "level": "error", "message": {"text": "Insecure pattern 'node_child_process' in packages/diagram/vite.config.ts:3"}, "properties": {"repobilityId": "c0f7b6f2ab36d5a4", "scanner": "scanner-primary", "fingerprint": "e90da1b9133b8514", "layer": "security", "severity": "high", "confidence": 0.9, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/vite.config.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-6c2e838dd958185b", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/LikeC4Styles.tsx:107"}, "properties": {"repobilityId": "c997c0b796e953f7", "scanner": "scanner-primary", "fingerprint": "6c2e838dd958185b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/LikeC4Styles.tsx"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-645b6d02bf3925fa", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/shadowroot/ShadowRoot.tsx:173"}, "properties": {"repobilityId": "70d20c4aaf1cbde7", "scanner": "scanner-primary", "fingerprint": "645b6d02bf3925fa", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/shadowroot/ShadowRoot.tsx"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-3702ed2ee878a1dd", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/context/TagStylesContext.tsx:77"}, "properties": {"repobilityId": "f150aec91244efc1", "scanner": "scanner-primary", "fingerprint": "3702ed2ee878a1dd", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/context/TagStylesContext.tsx"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-a6cde56f2871f14b", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/context/IconRenderer.tsx:194"}, "properties": {"repobilityId": "76815f0cbb76b767", "scanner": "scanner-primary", "fingerprint": "a6cde56f2871f14b", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/context/IconRenderer.tsx"}, "region": {"startLine": 194}}}]}, {"ruleId": "scanner-123b5d53cc496bb1", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/diagram/src/base-primitives/Markdown.tsx:9"}, "properties": {"repobilityId": "3e8788912754597c", "scanner": "scanner-primary", "fingerprint": "123b5d53cc496bb1", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/base-primitives/Markdown.tsx"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-95ae98b0af7adf01", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in packages/icons/scripts/prerender-svg.mjs:45"}, "properties": {"repobilityId": "862e2e51ae95d29a", "scanner": "scanner-primary", "fingerprint": "95ae98b0af7adf01", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/icons/scripts/prerender-svg.mjs"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-ab35855379418698", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/expressions.spec.ts:17"}, "properties": {"repobilityId": "37998a97f9118b2a", "scanner": "scanner-primary", "fingerprint": "ab35855379418698", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/generators/src/likec4/operators/expressions.spec.ts"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-1e22a8d0a72e77db", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/properties.spec.ts:17"}, "properties": {"repobilityId": "453c5f77c8465e30", "scanner": "scanner-primary", "fingerprint": "1e22a8d0a72e77db", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/generators/src/likec4/operators/properties.spec.ts"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-7995483e20d4cc35", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/base.spec.ts:40"}, "properties": {"repobilityId": "23c5ee22f9ead5c0", "scanner": "scanner-primary", "fingerprint": "7995483e20d4cc35", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/generators/src/likec4/operators/base.spec.ts"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-e99b9487c001d155", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/expressions.ts:160"}, "properties": {"repobilityId": "d0e9a19104df8a2f", "scanner": "scanner-primary", "fingerprint": "e99b9487c001d155", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/generators/src/likec4/operators/expressions.ts"}, "region": {"startLine": 160}}}]}, {"ruleId": "scanner-273b534c7f7a2a07", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in packages/generators/src/likec4/operators/views.ts:77"}, "properties": {"repobilityId": "28ad329a862b31f8", "scanner": "scanner-primary", "fingerprint": "273b534c7f7a2a07", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/generators/src/likec4/operators/views.ts"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-64a2855ea30c5317", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsDot.tsx:31"}, "properties": {"repobilityId": "341df2b47ee3f5d1", "scanner": "scanner-primary", "fingerprint": "64a2855ea30c5317", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsDot.tsx"}, "region": {"startLine": 31}}}]}, {"ruleId": "scanner-0d8025d651d551be", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsD2.tsx:71"}, "properties": {"repobilityId": "4c745bf8edd66a71", "scanner": "scanner-primary", "fingerprint": "0d8025d651d551be", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsD2.tsx"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-fb5bb1ea6075ff65", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsMmd.tsx:56"}, "properties": {"repobilityId": "0dd2530688ef6b14", "scanner": "scanner-primary", "fingerprint": "fb5bb1ea6075ff65", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsMmd.tsx"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-4a5e570947125622", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in packages/likec4-spa/src/pages/ViewAsPuml.tsx:69"}, "properties": {"repobilityId": "3e52713e10790231", "scanner": "scanner-primary", "fingerprint": "4a5e570947125622", "layer": "security", "severity": "medium", "confidence": 0.65, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/src/pages/ViewAsPuml.tsx"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f72e4b498f09201b", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-aedc8731e312291e", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "5643caafe282aebc", "scanner": "scanner-primary", "fingerprint": "aedc8731e312291e", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test-export-action.yml"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-086ec83e9465da3a", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "4dbf04f825a105b2", "scanner": "scanner-primary", "fingerprint": "086ec83e9465da3a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test-export-action.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-abe3b73e6139548b", "level": "error", "message": {"text": "pull_request_target workflow appears to check out untrusted PR code"}, "properties": {"repobilityId": "8ac2c2a8bd1d317e", "scanner": "scanner-primary", "fingerprint": "abe3b73e6139548b", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pull-request-target"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/prepare-release.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9645d38058e18095", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "a42f17c8cd085147", "scanner": "scanner-primary", "fingerprint": "9645d38058e18095", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/prepare-release.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6adb60f4d8515fbc", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0a50d9878cbb377c", "scanner": "scanner-primary", "fingerprint": "6adb60f4d8515fbc", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/issue-comment.yaml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-85c05d0cae247dcd", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "3a6205418a393353", "scanner": "scanner-primary", "fingerprint": "85c05d0cae247dcd", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/issue-comment.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e2d0519635166268", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "2b8a345212e55d78", "scanner": "scanner-primary", "fingerprint": "e2d0519635166268", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yaml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-7dc7c1e428a24a89", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "55c4144d6305e149", "scanner": "scanner-primary", "fingerprint": "7dc7c1e428a24a89", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-941b767627e5c8c4", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "952e2348762fc206", "scanner": "scanner-primary", "fingerprint": "941b767627e5c8c4", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/trigger-deploy-template.yaml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-bde84117402b3e2c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ebebce09330c1a8b", "scanner": "scanner-primary", "fingerprint": "bde84117402b3e2c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docs.yaml"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-adf12377b1a303ec", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "26c35837b62c0c41", "scanner": "scanner-primary", "fingerprint": "adf12377b1a303ec", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/playground.yaml"}, "region": {"startLine": 68}}}]}, {"ruleId": "scanner-13e5ad85fc4fc86c", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f9f5af94294e88b6", "scanner": "scanner-primary", "fingerprint": "13e5ad85fc4fc86c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/e2e-update-screenshots.yaml"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-fdb8a76317f1eee1", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "f3592dab2284d669", "scanner": "scanner-primary", "fingerprint": "fdb8a76317f1eee1", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/e2e-update-screenshots.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cfcd474feae0153b", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "06244eea15d60f27", "scanner": "scanner-primary", "fingerprint": "cfcd474feae0153b", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/cleanup-cache.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-1d7e834080dbebed", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "3fb26437e5bad61d", "scanner": "scanner-primary", "fingerprint": "1d7e834080dbebed", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main.yml"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-299e5e0d9ac9f81f", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "cb6b9b70fd6463a9", "scanner": "scanner-primary", "fingerprint": "299e5e0d9ac9f81f", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/main.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c2c7eb004a085af", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1743578d1fefbc91", "scanner": "scanner-primary", "fingerprint": "7c2c7eb004a085af", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/checks.yaml"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-b40816ce6a870dc6", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "cb60ed28e551d404", "scanner": "scanner-primary", "fingerprint": "b40816ce6a870dc6", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/vscode.yaml"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-9466de6abbe2c0b8", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e1ce6276e2a35630", "scanner": "scanner-primary", "fingerprint": "9466de6abbe2c0b8", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker.yaml"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-562504aada59f017", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "78d0d6e8b725fe0e", "scanner": "scanner-primary", "fingerprint": "562504aada59f017", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/docker.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cb639d9a10a47b23", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "b86179956da3a4a8", "scanner": "scanner-primary", "fingerprint": "cb639d9a10a47b23", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58d62f5c6b8bc69b", "level": "note", "message": {"text": "Very large file: packages/icons/tech/tastejs.tsx (1631 lines)"}, "properties": {"repobilityId": "0626f386ab3c157f", "scanner": "scanner-primary", "fingerprint": "58d62f5c6b8bc69b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f8911b023c2695a9", "level": "note", "message": {"text": "Very large file: packages/icons/tech/index.ts (2000 lines)"}, "properties": {"repobilityId": "3ba48a820a902d1a", "scanner": "scanner-primary", "fingerprint": "f8911b023c2695a9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a2444183221362c6", "level": "note", "message": {"text": "Very large file: packages/icons/tech/sugarss.tsx (834 lines)"}, "properties": {"repobilityId": "81d17fb6a5834838", "scanner": "scanner-primary", "fingerprint": "a2444183221362c6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6e7fa601c70961b3", "level": "note", "message": {"text": "Very large file: packages/icons/tech/linux.tsx (3092 lines)"}, "properties": {"repobilityId": "6d6088e724ab750c", "scanner": "scanner-primary", "fingerprint": "6e7fa601c70961b3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-23958dd388793cee", "level": "note", "message": {"text": "Very large file: packages/icons/tech/memgraph.tsx (2313 lines)"}, "properties": {"repobilityId": "a8d7e24ff57abbbd", "scanner": "scanner-primary", "fingerprint": "23958dd388793cee", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ebfb1a6ea63cc7e7", "level": "note", "message": {"text": "Very large file: packages/icons/bootstrap/index.ts (2051 lines)"}, "properties": {"repobilityId": "1c0713801ae9dfc2", "scanner": "scanner-primary", "fingerprint": "ebfb1a6ea63cc7e7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c49fb370249d58a1", "level": "note", "message": {"text": "Very large file: packages/language-server/src/workspace/ProjectsManager.spec.ts (1346 lines)"}, "properties": {"repobilityId": "a4a006a09eb67835", "scanner": "scanner-primary", "fingerprint": "c49fb370249d58a1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-49e3bbf97ee82bf3", "level": "note", "message": {"text": "Very large file: packages/language-server/src/formatting/LikeC4Formatter.spec.ts (2128 lines)"}, "properties": {"repobilityId": "4df31dea20875a86", "scanner": "scanner-primary", "fingerprint": "49e3bbf97ee82bf3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-77a3dd2aa8905980", "level": "note", "message": {"text": "Very large file: packages/generators/src/drawio/parse-drawio.ts (1996 lines)"}, "properties": {"repobilityId": "1707b214967d6436", "scanner": "scanner-primary", "fingerprint": "77a3dd2aa8905980", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-db8171af90fe543f", "level": "note", "message": {"text": "Very large file: packages/generators/src/drawio/generate-drawio.ts (1431 lines)"}, "properties": {"repobilityId": "b738869f26c86174", "scanner": "scanner-primary", "fingerprint": "db8171af90fe543f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-5b99d1a3a09b1419", "level": "note", "message": {"text": "32 TODO/FIXME markers"}, "properties": {"repobilityId": "4b38c118003e07d2", "scanner": "scanner-primary", "fingerprint": "5b99d1a3a09b1419", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["maintenance"]}}, {"ruleId": "scanner-577e6d5469194fe6", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: styled-system/preset/package.json"}, "properties": {"repobilityId": "7482a7b515b089a6", "scanner": "scanner-primary", "fingerprint": "577e6d5469194fe6", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "styled-system/preset/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3f9003bc06de6043", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: styled-system/styles/package.json"}, "properties": {"repobilityId": "c302a56da90bc439", "scanner": "scanner-primary", "fingerprint": "3f9003bc06de6043", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "styled-system/styles/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5a59386c68de50fc", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/playground/package.json"}, "properties": {"repobilityId": "09f01c09e4129cac", "scanner": "scanner-primary", "fingerprint": "5a59386c68de50fc", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f84d18439696f71", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/docs/package.json"}, "properties": {"repobilityId": "aef63841a7a897be", "scanner": "scanner-primary", "fingerprint": "1f84d18439696f71", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/docs/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-63f2d56cec85b7f3", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/create-likec4/package.json"}, "properties": {"repobilityId": "15fd0da7ccae40a9", "scanner": "scanner-primary", "fingerprint": "63f2d56cec85b7f3", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/create-likec4/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b24578f9e802c3a7", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/create-likec4/template/package.json"}, "properties": {"repobilityId": "63f45a82948dd176", "scanner": "scanner-primary", "fingerprint": "b24578f9e802c3a7", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/create-likec4/template/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ca655118d4b75e9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/vscode-preview/package.json"}, "properties": {"repobilityId": "fd1919ba64fc1fc9", "scanner": "scanner-primary", "fingerprint": "4ca655118d4b75e9", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vscode-preview/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2fc79ab9c1d1589c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/config/package.json"}, "properties": {"repobilityId": "03931bf3537e3eaf", "scanner": "scanner-primary", "fingerprint": "2fc79ab9c1d1589c", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/config/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b7a39c3ee75d357e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/language-services/package.json"}, "properties": {"repobilityId": "8dc245ce95d705d0", "scanner": "scanner-primary", "fingerprint": "b7a39c3ee75d357e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-services/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-93cf61dbf59813a8", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/vscode/package.json"}, "properties": {"repobilityId": "8f4199693123a2e8", "scanner": "scanner-primary", "fingerprint": "93cf61dbf59813a8", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vscode/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be458b5a9a2261bf", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/mcp/package.json"}, "properties": {"repobilityId": "7b57a55f1ea73746", "scanner": "scanner-primary", "fingerprint": "be458b5a9a2261bf", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/mcp/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-feb7d4d7a4aff9ad", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/diagram/package.json"}, "properties": {"repobilityId": "42cfcc3223dcc2db", "scanner": "scanner-primary", "fingerprint": "feb7d4d7a4aff9ad", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e7508869b10a649", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/vite-plugin/package.json"}, "properties": {"repobilityId": "0eca5908b31e7c09", "scanner": "scanner-primary", "fingerprint": "6e7508869b10a649", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vite-plugin/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-22dc28eb18ff2862", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/react/package.json"}, "properties": {"repobilityId": "280ebcdfd6337c69", "scanner": "scanner-primary", "fingerprint": "22dc28eb18ff2862", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/react/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-785efb308883920e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/log/package.json"}, "properties": {"repobilityId": "0115916a8e0df68d", "scanner": "scanner-primary", "fingerprint": "785efb308883920e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/log/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-329bfc097219bd77", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/icons/package.json"}, "properties": {"repobilityId": "282ce8c0fc711465", "scanner": "scanner-primary", "fingerprint": "329bfc097219bd77", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/icons/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ada30b496643aab", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "properties": {"repobilityId": "8640e46be7e3f9b2", "scanner": "scanner-primary", "fingerprint": "1ada30b496643aab", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-055e6d3fe9b6e226", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/language-server/package.json"}, "properties": {"repobilityId": "b7b2ba201f77fe56", "scanner": "scanner-primary", "fingerprint": "055e6d3fe9b6e226", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-91cdc2f03ab4a218", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/lsp/package.json"}, "properties": {"repobilityId": "1dbebe5b73e539fe", "scanner": "scanner-primary", "fingerprint": "91cdc2f03ab4a218", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/lsp/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b66ad9f79ad402c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/likec4/package.json"}, "properties": {"repobilityId": "a557b0ec47e1036f", "scanner": "scanner-primary", "fingerprint": "1b66ad9f79ad402c", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11f7e1a2099517a3", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/layouts/package.json"}, "properties": {"repobilityId": "26d6665482f27992", "scanner": "scanner-primary", "fingerprint": "11f7e1a2099517a3", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/layouts/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8bc387f8a44cfef2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/generators/package.json"}, "properties": {"repobilityId": "d1dfa0e6eb18be01", "scanner": "scanner-primary", "fingerprint": "8bc387f8a44cfef2", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/generators/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47d7261e52b2f0fe", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/likec4-spa/package.json"}, "properties": {"repobilityId": "288761273c67fd89", "scanner": "scanner-primary", "fingerprint": "47d7261e52b2f0fe", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4-spa/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f7146d8a45f56b47", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/leanix-bridge/package.json"}, "properties": {"repobilityId": "f6431f0175d9f459", "scanner": "scanner-primary", "fingerprint": "f7146d8a45f56b47", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/leanix-bridge/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-378f40fda6d85a8c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: devops/package.json"}, "properties": {"repobilityId": "7001d4c4b2792458", "scanner": "scanner-primary", "fingerprint": "378f40fda6d85a8c", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "devops/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50bd2f3a273b7c84", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: e2e/package.json"}, "properties": {"repobilityId": "4c9201e2b263799e", "scanner": "scanner-primary", "fingerprint": "50bd2f3a273b7c84", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "12118c036d54b77d", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "7afd8eb10284a660", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "b6c66035584f6fed", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "e6d4a6dfef3ca569", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-f4e41f5b8affc8cb", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 apps/playground/worker/index.ts:77"}, "properties": {"repobilityId": "4084acaea12cb454", "scanner": "scanner-primary", "fingerprint": "f4e41f5b8affc8cb", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/worker/index.ts"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-2fcdba371c8199b9", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/playground/worker/types.ts:56"}, "properties": {"repobilityId": "32df5f7d5d4bee9f", "scanner": "scanner-primary", "fingerprint": "2fcdba371c8199b9", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/worker/types.ts"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-8a47a5a31215f31b", "level": "warning", "message": {"text": "Fire-and-forget `fetch()` has no rejection handler \u2014 apps/docs/src/lib/githubdata.ts:187"}, "properties": {"repobilityId": "ae1ae9a051e9b38a", "scanner": "scanner-primary", "fingerprint": "8a47a5a31215f31b", "layer": "quality", "severity": "medium", "confidence": 0.9, "tags": ["integrity", "fragile-runtime", "robustness", "unhandled-promise"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/docs/src/lib/githubdata.ts"}, "region": {"startLine": 187}}}]}, {"ruleId": "scanner-5b4c5f67ac560c33", "level": "none", "message": {"text": "Commented-code block (11 lines) in packages/vscode/src/useMessenger.ts:178"}, "properties": {"repobilityId": "694deccd99f61465", "scanner": "scanner-primary", "fingerprint": "5b4c5f67ac560c33", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/vscode/src/useMessenger.ts"}, "region": {"startLine": 178}}}]}, {"ruleId": "scanner-c2de0493242122a4", "level": "none", "message": {"text": "Commented-code block (9 lines) in packages/diagram/src/search/components/styles.css.ts:50"}, "properties": {"repobilityId": "c23c068f70506a23", "scanner": "scanner-primary", "fingerprint": "c2de0493242122a4", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/search/components/styles.css.ts"}, "region": {"startLine": 50}}}]}, {"ruleId": "scanner-09ddbbd0dd06e763", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/diagram/src/likec4diagram/state/utils.ts:93"}, "properties": {"repobilityId": "e6abb9f63ace6649", "scanner": "scanner-primary", "fingerprint": "09ddbbd0dd06e763", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/diagram/src/likec4diagram/state/utils.ts"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-e58d7286af57299c", "level": "note", "message": {"text": "Legacy-named symbol `SvgEslintOld` in packages/icons/tech/eslint-old.tsx:4"}, "properties": {"repobilityId": "a298b4c3121dcf15", "scanner": "scanner-primary", "fingerprint": "e58d7286af57299c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-712fb867b978f344", "level": "note", "message": {"text": "Legacy-named symbol `EslintOld` in packages/icons/tech/index.ts:583"}, "properties": {"repobilityId": "78a4813ee17834e4", "scanner": "scanner-primary", "fingerprint": "712fb867b978f344", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1145d0ea19190e29", "level": "note", "message": {"text": "Legacy-named symbol `ContainerServicesDeprecated` in packages/icons/azure/index.ts:182"}, "properties": {"repobilityId": "97be1e14da3e187f", "scanner": "scanner-primary", "fingerprint": "1145d0ea19190e29", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-872cb00feaf95115", "level": "note", "message": {"text": "Legacy-named symbol `SvgContainerServicesDeprecated` in packages/icons/azure/container-services-deprecated.tsx:4"}, "properties": {"repobilityId": "e4dbbc3c0e101807", "scanner": "scanner-primary", "fingerprint": "872cb00feaf95115", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1e2521a686b53adf", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/core/src/model/connection/ops.ts:258"}, "properties": {"repobilityId": "83ab4e7495c80e4f", "scanner": "scanner-primary", "fingerprint": "1e2521a686b53adf", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/model/connection/ops.ts"}, "region": {"startLine": 258}}}]}, {"ruleId": "scanner-fb1e0cf5db7a6e27", "level": "none", "message": {"text": "Commented-code block (11 lines) in packages/core/src/compute-view/element-view/clean-connections.ts:27"}, "properties": {"repobilityId": "ab83cef935a3138e", "scanner": "scanner-primary", "fingerprint": "fb1e0cf5db7a6e27", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/element-view/clean-connections.ts"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-76d1b7f9e00a3fc4", "level": "note", "message": {"text": "Legacy-named symbol `mute_old` in packages/core/src/compute-view/element-view/__test__/fixture.ts:355"}, "properties": {"repobilityId": "0d475909c36251d1", "scanner": "scanner-primary", "fingerprint": "76d1b7f9e00a3fc4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-798fa3c1d7fd61e5", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-direct.ts:27"}, "properties": {"repobilityId": "2f26c61e0e1e758e", "scanner": "scanner-primary", "fingerprint": "798fa3c1d7fd61e5", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/predicates/relation-direct.ts"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-0105e62fe0846ac8", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-incoming.ts:80"}, "properties": {"repobilityId": "7ad872e26872d6e3", "scanner": "scanner-primary", "fingerprint": "0105e62fe0846ac8", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/predicates/relation-incoming.ts"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-41269faeb91f80ea", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/core/src/compute-view/deployment-view/predicates/relation-outgoing.ts:74"}, "properties": {"repobilityId": "32fee73a940b64fa", "scanner": "scanner-primary", "fingerprint": "41269faeb91f80ea", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/predicates/relation-outgoing.ts"}, "region": {"startLine": 74}}}]}, {"ruleId": "scanner-7413523b53463808", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/core/src/compute-view/deployment-view/stages/stage-final.ts:38"}, "properties": {"repobilityId": "db952a2ae180be1b", "scanner": "scanner-primary", "fingerprint": "7413523b53463808", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/deployment-view/stages/stage-final.ts"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-a96fae56b1ffb324", "level": "none", "message": {"text": "Commented-code block (9 lines) in packages/core/src/compute-view/relationships-view/layout.ts:61"}, "properties": {"repobilityId": "7a6d07d5745eeb8c", "scanner": "scanner-primary", "fingerprint": "a96fae56b1ffb324", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/compute-view/relationships-view/layout.ts"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-5ca88393cb772ac8", "level": "none", "message": {"text": "Commented-code block (11 lines) in packages/language-server/src/validation/imports.ts:32"}, "properties": {"repobilityId": "fdf91f7562a379de", "scanner": "scanner-primary", "fingerprint": "5ca88393cb772ac8", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/src/validation/imports.ts"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-17cfcca09f2bc6b0", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/likec4/src/cli/serve/serve.ts:125"}, "properties": {"repobilityId": "5490088a4268c644", "scanner": "scanner-primary", "fingerprint": "17cfcca09f2bc6b0", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4/src/cli/serve/serve.ts"}, "region": {"startLine": 125}}}]}, {"ruleId": "scanner-97390224a4fede93", "level": "none", "message": {"text": "Commented-code block (8 lines) in packages/layouts/src/graphviz/dot-labels.ts:211"}, "properties": {"repobilityId": "1799eba4d191ef92", "scanner": "scanner-primary", "fingerprint": "97390224a4fede93", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/layouts/src/graphviz/dot-labels.ts"}, "region": {"startLine": 211}}}]}, {"ruleId": "scanner-c1eb4eb50ff83b3d", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/layouts/src/graphviz/QueueGraphvizLayoter.ts:155"}, "properties": {"repobilityId": "8c2ffe1802dc5ad4", "scanner": "scanner-primary", "fingerprint": "c1eb4eb50ff83b3d", "layer": "quality", "severity": "info", "confidence": 0.72, "tags": ["integrity", "commented-code", "dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/layouts/src/graphviz/QueueGraphvizLayoter.ts"}, "region": {"startLine": 155}}}]}, {"ruleId": "scanner-5653dc0d42b22458", "level": "note", "message": {"text": "Legacy-named symbol `cloud_legacy` in e2e/src/likec4-model.test-d.ts:72"}, "properties": {"repobilityId": "ec11970cb9fb6d62", "scanner": "scanner-primary", "fingerprint": "5653dc0d42b22458", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-34bf1b8c94367afb", "level": "note", "message": {"text": "Legacy-named symbol `cloud_legacy` in e2e/src/likec4-views.test-d.ts:79"}, "properties": {"repobilityId": "771d66d83154016d", "scanner": "scanner-primary", "fingerprint": "34bf1b8c94367afb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-67984f56ee9f3426", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.14: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "e20a828d2748b708", "scanner": "scanner-primary", "fingerprint": "67984f56ee9f3426", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58d0f5c5b5cb2ac3", "level": "note", "message": {"text": "Vulnerable dependency esbuild 0.27.3: GHSA-g7r4-m6w7-qqqr"}, "properties": {"repobilityId": "8ca6a3c17eea45ad", "scanner": "scanner-primary", "fingerprint": "58d0f5c5b5cb2ac3", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-g7r4-m6w7-qqqr"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0caa6a61eb89b7cb", "level": "error", "message": {"text": "Vulnerable dependency sharp 0.34.5: GHSA-f88m-g3jw-g9cj"}, "properties": {"repobilityId": "c3222d5482f512fc", "scanner": "scanner-primary", "fingerprint": "0caa6a61eb89b7cb", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-f88m-g3jw-g9cj"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a3fe169b62730d62", "level": "warning", "message": {"text": "Vulnerable dependency ws 8.18.0: GHSA-58qx-3vcg-4xpx"}, "properties": {"repobilityId": "4b711e251c99749c", "scanner": "scanner-primary", "fingerprint": "a3fe169b62730d62", "layer": "dependencies", "severity": "medium", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-58qx-3vcg-4xpx"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3fe816a6ef728b4", "level": "error", "message": {"text": "Vulnerable dependency ws 8.18.0: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": "ac83265fafaa07b6", "scanner": "scanner-primary", "fingerprint": "b3fe816a6ef728b4", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-96hv-2xvq-fx4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-50a0ccef57d8b8f3", "level": "error", "message": {"text": "Vulnerable dependency ws 8.20.1: GHSA-96hv-2xvq-fx4p"}, "properties": {"repobilityId": "a1dc5bed811d8076", "scanner": "scanner-primary", "fingerprint": "50a0ccef57d8b8f3", "layer": "dependencies", "severity": "high", "confidence": 1.0, "tags": ["dependency", "sca", "osv", "GHSA-96hv-2xvq-fx4p"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7d8bab24956e6a57", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-editor-api is two or more major versions behind"}, "properties": {"repobilityId": "ff4eb7a094822a5f", "scanner": "scanner-primary", "fingerprint": "7d8bab24956e6a57", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7d403217964b90cf", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-editor-service-override is two or more major versions behind"}, "properties": {"repobilityId": "f6a91ba143b21008", "scanner": "scanner-primary", "fingerprint": "7d403217964b90cf", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2030fe1a2fbbf18", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-files-service-override is two or more major versions behind"}, "properties": {"repobilityId": "8a6cf17748b8b8c0", "scanner": "scanner-primary", "fingerprint": "d2030fe1a2fbbf18", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-80d43a1ab9e7f438", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-keybindings-service-override is two or more major versions behind"}, "properties": {"repobilityId": "ffad729f1ae5191c", "scanner": "scanner-primary", "fingerprint": "80d43a1ab9e7f438", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-47453df35acdc587", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-lifecycle-service-override is two or more major versions behind"}, "properties": {"repobilityId": "85393088fcd59489", "scanner": "scanner-primary", "fingerprint": "47453df35acdc587", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10b0f5021a110f4e", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-textmate-service-override is two or more major versions behind"}, "properties": {"repobilityId": "ac6321012ae5692d", "scanner": "scanner-primary", "fingerprint": "10b0f5021a110f4e", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-88798c5cf9480b43", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-theme-defaults-default-extension is two or more major versions behind"}, "properties": {"repobilityId": "1f5f8940ffa326d5", "scanner": "scanner-primary", "fingerprint": "88798c5cf9480b43", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7aef9cd0c304a04b", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-theme-service-override is two or more major versions behind"}, "properties": {"repobilityId": "c747ec8f2abf1baf", "scanner": "scanner-primary", "fingerprint": "7aef9cd0c304a04b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ff1edecd51a35ddc", "level": "warning", "message": {"text": "Dependency @codingame/monaco-vscode-views-service-override is two or more major versions behind"}, "properties": {"repobilityId": "91e6dd39dc0be942", "scanner": "scanner-primary", "fingerprint": "ff1edecd51a35ddc", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-67a663527529d914", "level": "note", "message": {"text": "Dependency @typefox/monaco-editor-react is a major version behind"}, "properties": {"repobilityId": "ea7a22f35cbdb4ad", "scanner": "scanner-primary", "fingerprint": "67a663527529d914", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4c52a8b5c25787c4", "level": "warning", "message": {"text": "Dependency @types/node is two or more major versions behind"}, "properties": {"repobilityId": "b4f624e83c60771c", "scanner": "scanner-primary", "fingerprint": "4c52a8b5c25787c4", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-667185838da0280d", "level": "note", "message": {"text": "Dependency monaco-languageclient is a major version behind"}, "properties": {"repobilityId": "ab68257da99b23c2", "scanner": "scanner-primary", "fingerprint": "667185838da0280d", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/playground/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-78474aa6edcf52ec", "level": "note", "message": {"text": "Dependency std-env is a major version behind"}, "properties": {"repobilityId": "b440ad00d2aaec90", "scanner": "scanner-primary", "fingerprint": "78474aa6edcf52ec", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b31aae5d4ddd33b", "level": "warning", "message": {"text": "Dependency typescript is two or more major versions behind"}, "properties": {"repobilityId": "534bbb7963e3e18b", "scanner": "scanner-primary", "fingerprint": "7b31aae5d4ddd33b", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4396f2c909b6e017", "level": "warning", "message": {"text": "Dependency which is two or more major versions behind"}, "properties": {"repobilityId": "5725e36727b8a866", "scanner": "scanner-primary", "fingerprint": "4396f2c909b6e017", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/language-server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad136b8f8eba3186", "level": "note", "message": {"text": "Dependency yargs is a major version behind"}, "properties": {"repobilityId": "7e73ec067707f272", "scanner": "scanner-primary", "fingerprint": "ad136b8f8eba3186", "layer": "dependencies", "severity": "low", "confidence": 0.9, "tags": ["dependency", "freshness", "outdated"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/likec4/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b5d1fd957e3a5ed2", "level": "note", "message": {"text": "2 backend endpoints not called by scanned frontend"}, "properties": {"repobilityId": "3c8e96670c5e1f9f", "scanner": "scanner-primary", "fingerprint": "b5d1fd957e3a5ed2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}