{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: sailingnaturali/signalk-dsc", "shortDescription": {"text": "Foundry mined assumption checks: sailingnaturali/signalk-dsc"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#1\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_weak_supervision\nChain evidence:\nIssue/PR evidence chain: sailingnaturali/signalk-dsc#1\nRepo: sailingnaturali/signalk-dsc\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 4\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 0\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-7d159ed5cb14a095\",\n    \"kind\": \"issue_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/sailingnaturali/signalk-dsc/issues/1\",\n    \"text\": \"GitHub feedback: agent_ins"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_bad_chain", "name": "Foundry mined bad chains: sailingnaturali/signalk-dsc", "shortDescription": {"text": "Foundry mined bad chains: sailingnaturali/signalk-dsc"}, "fullDescription": {"text": "Comment chain pattern product: bad_chains\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#3\nOutcome: self_attested_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_high_confidence\nChain evidence:\nIssue/PR evidence chain: sailingnaturali/signalk-dsc#3\nRepo: sailingnaturali/signalk-dsc\nThread label: thread_has_human_issue_and_fix_context\nOutcome: self_attested_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 1\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'docs_or_claims': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1b0c68bab7de8983\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/sailingnaturali/signalk-dsc/pull/3\",\n    \"text\": \"GitHub feedback:"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "high", "confidence": 0.84, "cwe": "", "owasp": ""}}, {"id": "foundry_fake_real_gap", "name": "Foundry mined mock as real or placeholder: sailingnaturali/signalk-dsc", "shortDescription": {"text": "Foundry mined mock as real or placeholder: sailingnaturali/signalk-dsc"}, "fullDescription": {"text": "Graph query export: Mock, sample, placeholder, or self-attested behavior treated as real\nQuery id: mock_as_real_or_placeholder\nQuery type: motif_query\nIntent: Hard negatives for fake completeness and missing real data paths.\nMotif: mock_as_real_or_placeholder\nTraining usage: hard_negative\nGraph gold label: supported_by_high_confidence_link\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#3\nEvidence:\nGraph motif: Mock, sample, placeholder, or self-attested behavior treated as real\nMotif id: mock_as_real_or_placeholder\nPolarity: bad\nTraining usage: hard_negative\nSeverity: critical\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#3\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: sailingnaturali/signalk-dsc#3\nRepo: sailingnaturali/signalk-dsc\nIssue/PR number: 3\nGraph consistency label: supported_by_high_confidence_link\nNodes: 12\nEdges: 16\nNode types: {'link_quality': 3, 'commit': "}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "critical", "confidence": 0.82, "cwe": "", "owasp": ""}}, {"id": "scanner-05be69f68a643bf3", "name": "Stray `console.log` in TS/JS \u2014 scripts/send-test-dsc.js:125", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/send-test-dsc.js:125"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b9c6cce1f8f0e39c", "name": "Stray `console.log` in TS/JS \u2014 scripts/clear-dsc-alarm.js:99", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/clear-dsc-alarm.js:99"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7ffa33751be3d771", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2f0c9710165a287b", "name": "Commented-code block (5 lines) in index.js:381", "shortDescription": {"text": "Commented-code block (5 lines) in index.js:381"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1ba9a760ee207d41", "name": "`fetch()` without try/.catch or AbortSignal \u2014 index.js:176", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 index.js:176"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e03df2b4aa41471", "name": "Commented-code block (6 lines) in lib/dsc.js:132", "shortDescription": {"text": "Commented-code block (6 lines) in lib/dsc.js:132"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18765"}, "properties": {"repository": "sailingnaturali/signalk-dsc", "repoUrl": "https://github.com/sailingnaturali/signalk-dsc", "branch": "main"}, "results": [{"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: sailingnaturali/signalk-dsc"}, "properties": {"repobilityId": 312047, "scanner": "foundry_dataset", "fingerprint": "30cf408a1ca244915a40afc288f00afe0ee6a4843eca8e22ad450f006175e936", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "sailingnaturali/signalk-dsc#1", "human_labels": ["agent_instruction_gap"], "issue_number": "1", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "claimed_resolved_unverified", "source_backed": true, "max_confidence": 0.65, "repo_full_name": "sailingnaturali/signalk-dsc", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-ddd0888247e5b94d", "helicopter_views": {}, "artifact_families": {"docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 0, "source_graph_label": "source_artifact_without_verification_graph", "changed_file_labels": {}, "linked_commit_count": 4, "helicopter_view_count": 0, "source_artifact_count": 1, "classification_reasons": ["source_graph_has_real_artifacts", "link_quality_weak_supervision"], "linked_ci_commit_count": 0, "verification_artifact_count": 0, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: assumption_checks\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#1\nOutcome: claimed_resolved_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_weak_supervision\nChain evidence:\nIssue/PR evidence chain: sailingnaturali/signalk-dsc#1\nRepo: sailingnaturali/signalk-dsc\nThread label: thread_has_human_issue_and_fix_context\nOutcome: claimed_resolved_unverified\nComment count: 1\nLinked commit count: 4\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 0\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-7d159ed5cb14a095\",\n    \"kind\": \"issue_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/sailingnaturali/signalk-dsc/issues/1\",\n    \"text\": \"GitHub feedback: agent_instruction_gap\\nPolarity: bad\\nKind: issue_body\\nRepo: sailingnaturali/signalk-dsc\\nAuthor: clarkbw (User)\\nURL: https://github.com/sailingnaturali/signalk-dsc/issues/1\\nTitle: Upstream: contribute PGN 129808 mapping to n2k-signalk\\nBody:\\nn2k-signalk has no mapping for PGN 129808 (DSC Call Information) at all \u2014 verified zero hits in the repo. Any N2K VHF's DSC traffic (incl. a distress alert) produces no SignalK delta; this plugin works around it by listening to the server's `N2KAnalyzerOut` analyzer event directly.\\n\\nThe mapping work is already done here:\\n- `lib/pgn129808.js` \u2014 normalizes both canboat variants (`dscDistressCallInformation` / `dscCallInformation`), handles resolved lookup names *and* raw ITU symbol numbers, MMSI zero-padding, time-of-position\\n- `test/pgn129808.test.js` \u2014 covers distress, urgency, routine, and missing-field shapes\\n\\nThe PR would translate that into n2k-signalk's conversion table (probably emitting under the sender's vessel context, mirroring what their AIS conversions do). Heads up that the PGN definition itself has known quirks upstream: canboat/canboat#508.\\n\\n\ud83e\udd16 Generated with [Claude Code](https://claude.com/claude-code)\\n\"\n  }\n]\nChanged files:\n[]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-9e44c8a0f4732558\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: sailingnaturali/signalk-dsc\nGraph label: source_artifact_without_verification_graph\nNodes: 5\nEdges: 6\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"repo\": 1, \"source_artifact\": 1, \"source_bundle\": 1}\nEdge types: {\"artifact_needs_claim_verification\": 1, \"repo_has_cooccurrence_profile\": 1, \"repo_has_github_evidence_summary\": 1, \"repo_has_source_artifact\": 1, \"repo_has_source_bundle\": 1, \"source_bundle_uses_cooccurrence_profile\": 1}\nArtifact families: {\"docs\": 1}\nHelicopter views: {}\nBundle labels: {\"source_backed_graph_pattern_bundle\": 1}\nCo-occurrence labels: {\"mixed_good_bad_repo_profile\": 1}", "source": "foundry_mined_dataset", "repo_url": "https://github.com/sailingnaturali/signalk-dsc", "source_id": "comment-chain-pattern-assumption_checks-f2cb6e54b4e6c8e1", "synthetic": false, "gold_label": "", "graph_label": "source_artifact_without_verification_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "sailingnaturali/signalk-dsc", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_bad_chain", "level": "error", "message": {"text": "Foundry mined bad chains: sailingnaturali/signalk-dsc"}, "properties": {"repobilityId": 322550, "scanner": "foundry_dataset", "fingerprint": "496785bab34fa9ec046e58ffb5a229359b83b1750474fee18e1ea133aa04557e", "category": "practices", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "bad_chains", "synthetic": false, "thread_key": "sailingnaturali/signalk-dsc#3", "human_labels": ["agent_instruction_gap", "docs_or_claims"], "issue_number": "3", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "self_attested_unverified", "source_backed": true, "max_confidence": 0.825, "repo_full_name": "sailingnaturali/signalk-dsc", "training_usage": "gold_candidate", "confidence_tier": "high_confidence", "source_chain_id": "evidence-chain-issue_chain-92d10409059ed89f", "helicopter_views": {}, "artifact_families": {"docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 1, "source_graph_label": "source_artifact_without_verification_graph", "changed_file_labels": {"docs_or_claims": 1}, "linked_commit_count": 2, "helicopter_view_count": 0, "source_artifact_count": 1, "classification_reasons": ["source_graph_has_real_artifacts", "link_quality_high_confidence"], "linked_ci_commit_count": 0, "verification_artifact_count": 0, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: bad_chains\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#3\nOutcome: self_attested_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_high_confidence\nChain evidence:\nIssue/PR evidence chain: sailingnaturali/signalk-dsc#3\nRepo: sailingnaturali/signalk-dsc\nThread label: thread_has_human_issue_and_fix_context\nOutcome: self_attested_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 1\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'docs_or_claims': 1}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1b0c68bab7de8983\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/sailingnaturali/signalk-dsc/pull/3\",\n    \"text\": \"GitHub feedback: agent_instruction_gap\\nPolarity: bad\\nKind: pull_request_body\\nRepo: sailingnaturali/signalk-dsc\\nAuthor: clarkbw (User)\\nURL: https://github.com/sailingnaturali/signalk-dsc/pull/3\\nTitle: Cite the regulation the DSC radio log mirrors\\nBody:\\nBryan asked whether regs actually require logging distress calls \u2014 turns out yes, and it's basically the reason this plugin keeps a radio log, so worth saying out loud in the README.\\n\\nAdds a short paragraph to **Why** grounding the log feature in the rule it mirrors:\\n\\n- **47 CFR \u00a780.409** (FCC station logs) \u2014 the quotable one: distress/automatic-alarm/urgency/safety signals *\\\"made or intercepted\\\"* must be entered with time and the position of the station in distress. The *intercepted* bit is exactly what this plugin captures.\\n- **SOLAS Ch. IV** + **ITU Radio Regulations** \u2014 the international backbone.\\n- **TP 1539** \u2014 the Canadian equivalent (we're in BC waters).\\n\\nKept the honest caveat: the log *mandate* binds compulsorily-equipped / GMDSS / SOLAS-class vessels, not voluntary recreational stations. So the framing is \\\"this gives you the same SOLAS-grade record automatically,\\\" not \\\"the law makes you do this.\\\" Didn't want a sharp-eyed re\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-da329ea1f0f06c89\",\n    \"filename\": \"README.md\",\n    \"label\": \"docs_or_claims\",\n    \"status\": \"modified\",\n    \"additions\": 11,\n    \"deletions\": 0,\n    \"changes\": 11,\n    \"blob_url\": \"https://github.com/sailingnaturali/signalk-dsc/blob/120f91664400c5f27e8c87b7e2dfeeca9009fc3c/README.md\"\n  }\n]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-948aec8552c06065\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: sailingnaturali/signalk-dsc\nGraph label: source_artifact_without_verification_graph\nNodes: 5\nEdges: 6\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"repo\": 1, \"source_artifact\": 1, \"source_bundle\": 1}\nEdge types: {\"artifact_needs_claim_verification\": 1,\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/sailingnaturali/signalk-dsc", "source_id": "comment-chain-pattern-bad_chains-a42868e60e5709a1", "synthetic": false, "gold_label": "", "graph_label": "source_artifact_without_verification_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/bad_chains/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "sailingnaturali/signalk-dsc", "source_dataset": "comment_chain_patterns/bad_chains", "training_usage": "gold_candidate"}}}, {"ruleId": "foundry_bad_chain", "level": "error", "message": {"text": "Foundry mined bad chains: sailingnaturali/signalk-dsc"}, "properties": {"repobilityId": 322549, "scanner": "foundry_dataset", "fingerprint": "c69372157ffa199ac1068f65963c7090c54375a11e616449564def18bc71f257", "category": "practices", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "bad_chains", "synthetic": false, "thread_key": "sailingnaturali/signalk-dsc#2", "human_labels": ["agent_instruction_gap"], "issue_number": "2", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "self_attested_unverified", "source_backed": true, "max_confidence": 0.65, "repo_full_name": "sailingnaturali/signalk-dsc", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-8699f038f4714669", "helicopter_views": {}, "artifact_families": {"docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 0, "source_graph_label": "source_artifact_without_verification_graph", "changed_file_labels": {}, "linked_commit_count": 2, "helicopter_view_count": 0, "source_artifact_count": 1, "classification_reasons": ["source_graph_has_real_artifacts", "link_quality_weak_supervision"], "linked_ci_commit_count": 0, "verification_artifact_count": 0, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: bad_chains\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#2\nOutcome: self_attested_unverified\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_weak_supervision\nChain evidence:\nIssue/PR evidence chain: sailingnaturali/signalk-dsc#2\nRepo: sailingnaturali/signalk-dsc\nThread label: thread_has_human_issue_and_fix_context\nOutcome: self_attested_unverified\nComment count: 1\nLinked commit count: 2\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 0\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-3f47760df885e9b8\",\n    \"kind\": \"issue_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/sailingnaturali/signalk-dsc/issues/2\",\n    \"text\": \"GitHub feedback: agent_instruction_gap\\nPolarity: bad\\nKind: issue_body\\nRepo: sailingnaturali/signalk-dsc\\nAuthor: clarkbw (User)\\nURL: https://github.com/sailingnaturali/signalk-dsc/issues/2\\nTitle: Upstream: DSC hook fixes + DSE support for nmea0183-signalk (closes their #217)\\nBody:\\nThe stock `DSC.ts` hook in [SignalK/nmea0183-signalk](https://github.com/SignalK/nmea0183-signalk) has three gaps this plugin had to paper over with its own sentence parsers:\\n\\n1. **Sparse distress alerts are dropped** \u2014 some radios omit the category field on a distress alert (implied by format 112). The `empty > 3` bail-out throws these away; it's the exact failing sentence in [SignalK/nmea0183-signalk#217](https://github.com/SignalK/nmea0183-signalk/issues/217), open since 2022. Our parser treats an empty category with format 12 as distress (`lib/dsc.js`, tested against the literal sentence from that issue).\\n2. **No `DSE` hook** \u2014 the expansion sentence that refines a DSC position from \u00b11 NM to ten-thousandths of a minute is silently discarded. Ours pairs it with the preceding call by MMSI (`lib/dse.js`).\\n3. **Relay/ack/cancellation fields ignored** \u2014 the hook doc itself marks distress cancellation 'unsup\"\n  }\n]\nChanged files:\n[]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-cfbdab4925f1381a\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: sailingnaturali/signalk-dsc\nGraph label: source_artifact_without_verification_graph\nNodes: 5\nEdges: 6\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"repo\": 1, \"source_artifact\": 1, \"source_bundle\": 1}\nEdge types: {\"artifact_needs_claim_verification\": 1, \"repo_has_cooccurrence_profile\": 1, \"repo_has_github_evidence_summary\": 1, \"repo_has_source_artifact\": 1, \"repo_has_source_bundle\": 1, \"source_bundle_uses_cooccurrence_profile\": 1}\nArtifact families: {\"docs\": 1}\nHelicopter views: {}\nBundle labels: {\"source_backed_graph_pattern_bundle\": 1}\nCo-occurrence labels: {\"mixed_good_bad_repo_profile\": 1}", "source": "foundry_mined_dataset", "repo_url": "https://github.com/sailingnaturali/signalk-dsc", "source_id": "comment-chain-pattern-bad_chains-8f67496c9a359eb2", "synthetic": false, "gold_label": "", "graph_label": "source_artifact_without_verification_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/bad_chains/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "sailingnaturali/signalk-dsc", "source_dataset": "comment_chain_patterns/bad_chains", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_fake_real_gap", "level": "error", "message": {"text": "Foundry mined mock as real or placeholder: sailingnaturali/signalk-dsc"}, "properties": {"repobilityId": 327098, "scanner": "foundry_dataset", "fingerprint": "5d4e87b90cd970c596124ca0f6530add4bdd86d2bc81b4cb9f5ac5b0e678cd65", "category": "practices", "severity": "critical", "confidence": 0.82, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Mock, sample, placeholder, or self-attested behavior treated as real", "intent": "Hard negatives for fake completeness and missing real data paths.", "labels": {"docs_or_chore": 1, "docs_or_claims": 1, "generated_provenance": 1, "agent_instruction_gap": 1, "self_attested_unverified": 3, "issue_or_pull_request_thread": 1, "thread_has_human_issue_and_fix_context": 2, "self_attested_or_generated_fix_unverified": 1}, "source": "graph_query_export", "motif_id": "mock_as_real_or_placeholder", "outcomes": {"self_attested_unverified": 6}, "polarity": "bad", "query_id": "mock_as_real_or_placeholder", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 16, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 1, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "comment_chain_touches_file": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 12, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "pr_file": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "sailingnaturali/signalk-dsc#3", "issue_number": "3", "quality_tiers": {"high_confidence": 3}, "repo_full_name": "sailingnaturali/signalk-dsc", "training_usage": "hard_negative", "source_motif_id": "graph-pattern-motif-thread-2086f2ada144b07a", "graph_gold_label": "supported_by_high_confidence_link", "changed_file_labels": {"docs_or_claims": 4}}, "text": "Graph query export: Mock, sample, placeholder, or self-attested behavior treated as real\nQuery id: mock_as_real_or_placeholder\nQuery type: motif_query\nIntent: Hard negatives for fake completeness and missing real data paths.\nMotif: mock_as_real_or_placeholder\nTraining usage: hard_negative\nGraph gold label: supported_by_high_confidence_link\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#3\nEvidence:\nGraph motif: Mock, sample, placeholder, or self-attested behavior treated as real\nMotif id: mock_as_real_or_placeholder\nPolarity: bad\nTraining usage: hard_negative\nSeverity: critical\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#3\nGraph gold label: supported_by_high_confidence_link\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: sailingnaturali/signalk-dsc#3\nRepo: sailingnaturali/signalk-dsc\nIssue/PR number: 3\nGraph consistency label: supported_by_high_confidence_link\nNodes: 12\nEdges: 16\nNode types: {'link_quality': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'pr_file': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_touches_file': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'comment_chain_touches_file': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'issue_chain_touches_file': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'self_attested_unverified': 3, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'agent_instruction_gap': 1, 'docs_or_claims': 1, 'self_attested_or_generated_fix_unverified': 1, 'docs_or_chore': 1, 'generated_provenance': 1}\nOutcomes: {'self_attested_unverified': 6}\nQuality tiers: {'high_confidence': 3}\nCI labels: {}\nCurriculum targets:\n- Train real-data plumbing and mock-removal tasks from source to UI.\n- Use as hard negatives for dashboards or apps claiming real runs without provenance.\nAssumption checks:\n- Is user-visible behavior backed by real storage/API/CI artifacts?\n- Are placeholders, sample data, or generated claims still in a production path?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/sailingnaturali/signalk-dsc", "source_id": "graph-query-motif_query-00e20bcefdc1f582", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/mock_as_real_or_placeholder/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "sailingnaturali/signalk-dsc", "source_dataset": "graph_queries/mock_as_real_or_placeholder", "training_usage": "hard_negative"}}}, {"ruleId": "foundry_fake_real_gap", "level": "error", "message": {"text": "Foundry mined mock as real or placeholder: sailingnaturali/signalk-dsc"}, "properties": {"repobilityId": 327097, "scanner": "foundry_dataset", "fingerprint": "2d77d1f8e39014b00732892d3f4344ecd4922687abf6bf437132977aac09fd03", "category": "practices", "severity": "critical", "confidence": 0.82, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Mock, sample, placeholder, or self-attested behavior treated as real", "intent": "Hard negatives for fake completeness and missing real data paths.", "labels": {"generated_provenance": 2, "agent_instruction_gap": 1, "self_attested_unverified": 3, "issue_or_pull_request_thread": 1, "thread_has_human_issue_and_fix_context": 2, "self_attested_or_generated_fix_unverified": 1}, "source": "graph_query_export", "motif_id": "mock_as_real_or_placeholder", "outcomes": {"self_attested_unverified": 6}, "polarity": "bad", "query_id": "mock_as_real_or_placeholder", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 13, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "thread_has_comment_chain": 1, "comment_chain_links_commit": 2, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 11, "node_types": {"repo": 1, "commit": 2, "thread": 1, "comment": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "sailingnaturali/signalk-dsc#2", "issue_number": "2", "quality_tiers": {"weak_supervision": 3}, "repo_full_name": "sailingnaturali/signalk-dsc", "training_usage": "hard_negative", "source_motif_id": "graph-pattern-motif-thread-630c8f2f948a49bb", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {}}, "text": "Graph query export: Mock, sample, placeholder, or self-attested behavior treated as real\nQuery id: mock_as_real_or_placeholder\nQuery type: motif_query\nIntent: Hard negatives for fake completeness and missing real data paths.\nMotif: mock_as_real_or_placeholder\nTraining usage: hard_negative\nGraph gold label: weak_supervision_needs_review\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#2\nEvidence:\nGraph motif: Mock, sample, placeholder, or self-attested behavior treated as real\nMotif id: mock_as_real_or_placeholder\nPolarity: bad\nTraining usage: hard_negative\nSeverity: critical\nRepo: sailingnaturali/signalk-dsc\nThread: sailingnaturali/signalk-dsc#2\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: sailingnaturali/signalk-dsc#2\nRepo: sailingnaturali/signalk-dsc\nIssue/PR number: 2\nGraph consistency label: weak_supervision_needs_review\nNodes: 11\nEdges: 13\nNode types: {'link_quality': 3, 'commit': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'comment_chain_links_commit': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'self_attested_unverified': 3, 'generated_provenance': 2, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'agent_instruction_gap': 1, 'self_attested_or_generated_fix_unverified': 1}\nOutcomes: {'self_attested_unverified': 6}\nQuality tiers: {'weak_supervision': 3}\nCI labels: {}\nCurriculum targets:\n- Train real-data plumbing and mock-removal tasks from source to UI.\n- Use as hard negatives for dashboards or apps claiming real runs without provenance.\nAssumption checks:\n- Is user-visible behavior backed by real storage/API/CI artifacts?\n- Are placeholders, sample data, or generated claims still in a production path?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/sailingnaturali/signalk-dsc", "source_id": "graph-query-motif_query-f82e734da4c512e6", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/mock_as_real_or_placeholder/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "sailingnaturali/signalk-dsc", "source_dataset": "graph_queries/mock_as_real_or_placeholder", "training_usage": "hard_negative"}}}, {"ruleId": "scanner-05be69f68a643bf3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/send-test-dsc.js:125"}, "properties": {"repobilityId": "1827c36322f93268", "scanner": "scanner-primary", "fingerprint": "05be69f68a643bf3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b9c6cce1f8f0e39c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/clear-dsc-alarm.js:99"}, "properties": {"repobilityId": "e2e3628ad865e725", "scanner": "scanner-primary", "fingerprint": "b9c6cce1f8f0e39c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-7ffa33751be3d771", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "491a3ad29cbaf189", "scanner": "scanner-primary", "fingerprint": "7ffa33751be3d771", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "dd883d7e9390c46b", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "48c6e726f15cdd7f", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-2f0c9710165a287b", "level": "none", "message": {"text": "Commented-code block (5 lines) in index.js:381"}, "properties": {"repobilityId": "4bb0caf25c819a06", "scanner": "scanner-primary", "fingerprint": "2f0c9710165a287b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1ba9a760ee207d41", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 index.js:176"}, "properties": {"repobilityId": "159c345a962ba431", "scanner": "scanner-primary", "fingerprint": "1ba9a760ee207d41", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-6e03df2b4aa41471", "level": "none", "message": {"text": "Commented-code block (6 lines) in lib/dsc.js:132"}, "properties": {"repobilityId": "fbe6d3a0b499869f", "scanner": "scanner-primary", "fingerprint": "6e03df2b4aa41471", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}]}]}