{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-15bebf0cba690bff", "name": "Stray `console.log` in TS/JS \u2014 tests/performance.spec.js:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/performance.spec.js:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96a8d9f857f83af6", "name": "Stray `console.log` in TS/JS \u2014 tests/test-dompurify.spec.js:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/test-dompurify.spec.js:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-573a774f92891257", "name": "Stray `console.log` in TS/JS \u2014 tests/performance-baseline.spec.js:69", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/performance-baseline.spec.js:69"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1db253c897d790f7", "name": "Stray `console.log` in TS/JS \u2014 tests/prefetch-metrics.spec.js:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/prefetch-metrics.spec.js:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e400e2ade161990e", "name": "Stray `console.log` in TS/JS \u2014 tests/test-all-nfts.spec.js:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/test-all-nfts.spec.js:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f78685bdc7d55bf", "name": "Stray `console.log` in TS/JS \u2014 tests/test-html-viewer.spec.js:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/test-html-viewer.spec.js:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-91c764b0e7b17226", "name": "Stray `console.log` in TS/JS \u2014 tests/debug-nft10.spec.js:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/debug-nft10.spec.js:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f249ae11c2217d8", "name": "Stray `console.log` in TS/JS \u2014 tests/prefetch.spec.js:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/prefetch.spec.js:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-809dd1973b03a01b", "name": "Stray `console.log` in TS/JS \u2014 tests/homepage-performance.spec.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/homepage-performance.spec.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0003c6248ba53d8", "name": "Stray `console.log` in TS/JS \u2014 tests/profile-performance.spec.js:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/profile-performance.spec.js:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-273a8272176057fd", "name": "Stray `console.log` in TS/JS \u2014 src/common/socket.js:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/common/socket.js:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a2b4dbc1e245a9d", "name": "Stray `console.log` in TS/JS \u2014 src/common/provider.jsx:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/common/provider.jsx:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8eb7bca29dccf8d2", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/UserHistory.jsx:122", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/UserHistory.jsx:122"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf42a45e300bf44a", "name": "`truncate` class without `title=` for hover reveal \u2014 src/pages/activity.jsx:192", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/pages/activity.jsx:192"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e149fe53754f0c6f", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/pages/nft.jsx:808", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/pages/nft.jsx:808"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb77b8c622a8fd8e", "name": "`truncate` class without `title=` for hover reveal \u2014 src/pages/profile.jsx:288", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/pages/profile.jsx:288"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-258300844cf8cb67", "name": "Insecure pattern 'cors_wildcard' in server.cjs:29", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in server.cjs:29"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c371ff15082a705", "name": "Insecure pattern 'dangerous_innerhtml' in playwright-report/index.html:58", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in playwright-report/index.html:58"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9029cfde635dd36d", "name": "Insecure pattern 'direct_innerhtml_assignment' in playwright-report/index.html:57", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in playwright-report/index.html:57"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fde9cc8c846f90bb", "name": "Insecure pattern 'dangerous_innerhtml' in src/pages/nft.jsx:808", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in src/pages/nft.jsx:808"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90711f6ce5de9364", "name": "Very large file: src/pages/nft.jsx (1185 lines)", "shortDescription": {"text": "Very large file: src/pages/nft.jsx (1185 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "12 tests / 74 src (ratio 0.16)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 88 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 21 placeholder/mock markers across 6 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0960f5d03e17027b", "name": "Commented-code block (5 lines) in scripts/test-base-rpcs.mjs:5", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/test-base-rpcs.mjs:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-26f67f24c38d72d7", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/blockchain.cjs:218", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/blockchain.cjs:218"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8978dafe1da8c4be", "name": "Commented-code block (10 lines) in src/common/ens.jsx:126", "shortDescription": {"text": "Commented-code block (10 lines) in src/common/ens.jsx:126"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7788df4108f3ff09", "name": "Commented-code block (5 lines) in src/common/gas.jsx:3", "shortDescription": {"text": "Commented-code block (5 lines) in src/common/gas.jsx:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-32d36fd41e6b2f28", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/components/NFTCard.jsx:103", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/components/NFTCard.jsx:103"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-38e7b43a51947379", "name": "Commented-code block (5 lines) in src/components/PrefetchLink.jsx:49", "shortDescription": {"text": "Commented-code block (5 lines) in src/components/PrefetchLink.jsx:49"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-45cdf31158731c8c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/pages/gallery.jsx:95", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/pages/gallery.jsx:95"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c959bcd4c542971b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/pages/profile.jsx:129", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/pages/profile.jsx:129"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad1f2c0971b89ce0", "name": "10 env vars used in code but missing from .env.example", "shortDescription": {"text": "10 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ADMIN_SECRET`, `ALCHEMY_BASE_API_KEY`, `BASE_RPC_URL`, `CI`, `DATABASE_URL`, `DEV`, `VITE_ALCHEMY_BASE_API_KEY`, `VITE_ALCHEMY_MAINNET_API_KEY` + 2 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b2ab34e33dabe5e", "name": "Frontend route `/nft` has no Link/navigate to it \u2014 src/main.jsx", "shortDescription": {"text": "Frontend route `/nft` has no Link/navigate to it \u2014 src/main.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c88301252c821b00", "name": "Frontend route `/profile` has no Link/navigate to it \u2014 src/main.jsx", "shortDescription": {"text": "Frontend route `/profile` has no Link/navigate to it \u2014 src/main.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c619aa5252d19d6", "name": "Frontend route `/bridge` has no Link/navigate to it \u2014 src/main.jsx", "shortDescription": {"text": "Frontend route `/bridge` has no Link/navigate to it \u2014 src/main.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3426cac333dc6f76", "name": "Unused endpoint: GET /og/:id.png", "shortDescription": {"text": "Unused endpoint: GET /og/:id.png"}, "fullDescription": {"text": "`server.cjs` declares `GET /og/:id.png` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33e3b77197129ef5", "name": "Unused endpoint: GET /nft", "shortDescription": {"text": "Unused endpoint: GET /nft"}, "fullDescription": {"text": "`server.cjs` declares `GET /nft` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9331fd384ba44a82", "name": "Unused endpoint: POST /api/sync", "shortDescription": {"text": "Unused endpoint: POST /api/sync"}, "fullDescription": {"text": "`server/routes.cjs` declares `POST /api/sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c3cdecb263117dff", "name": "Unused endpoint: GET /api/sync/status", "shortDescription": {"text": "Unused endpoint: GET /api/sync/status"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/sync/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b37265900e79a8a", "name": "Unused endpoint: GET /api/stats", "shortDescription": {"text": "Unused endpoint: GET /api/stats"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fc1fe75eafa3812", "name": "Unused endpoint: GET /api/token/:id/stats", "shortDescription": {"text": "Unused endpoint: GET /api/token/:id/stats"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/token/:id/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6c79c4242817159", "name": "Unused endpoint: GET /api/authors", "shortDescription": {"text": "Unused endpoint: GET /api/authors"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/authors` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e16b9202fdc3e256", "name": "Unused endpoint: GET /api/top-artists", "shortDescription": {"text": "Unused endpoint: GET /api/top-artists"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/top-artists` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1c87483719ffa4d", "name": "Unused endpoint: GET /api/top-collectors", "shortDescription": {"text": "Unused endpoint: GET /api/top-collectors"}, "fullDescription": {"text": "`server/routes.cjs` declares `GET /api/top-collectors` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f3b29485fc1bd1ef", "name": "Unused endpoint: POST /api/prewarm", "shortDescription": {"text": "Unused endpoint: POST /api/prewarm"}, "fullDescription": {"text": "`server/routes.cjs` declares `POST /api/prewarm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7dfae683877aae4", "name": "Unused endpoint: POST /api/nft/:id/refresh", "shortDescription": {"text": "Unused endpoint: POST /api/nft/:id/refresh"}, "fullDescription": {"text": "`server/routes.cjs` declares `POST /api/nft/:id/refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d8b184e22a2da5a", "name": "Unused endpoint: POST /api/sync/reset", "shortDescription": {"text": "Unused endpoint: POST /api/sync/reset"}, "fullDescription": {"text": "`server/routes.cjs` declares `POST /api/sync/reset` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ece2d920226d7bb", "name": "Unused endpoint: POST /api/blocks/batch", "shortDescription": {"text": "Unused endpoint: POST /api/blocks/batch"}, "fullDescription": {"text": "`server/routes.cjs` declares `POST /api/blocks/batch` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23529"}, "properties": {"repository": "zangGallery/frontend-v2", "repoUrl": "https://github.com/zangGallery/frontend-v2", "branch": "main"}, "results": [{"ruleId": "scanner-15bebf0cba690bff", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/performance.spec.js:25"}, "properties": {"repobilityId": "96fa02ce486c5997", "scanner": "scanner-primary", "fingerprint": "15bebf0cba690bff", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-96a8d9f857f83af6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/test-dompurify.spec.js:34"}, "properties": {"repobilityId": "145fa095d3749fb7", "scanner": "scanner-primary", "fingerprint": "96a8d9f857f83af6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-573a774f92891257", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/performance-baseline.spec.js:69"}, "properties": {"repobilityId": "eee639bdce8d7a6f", "scanner": "scanner-primary", "fingerprint": "573a774f92891257", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1db253c897d790f7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/prefetch-metrics.spec.js:7"}, "properties": {"repobilityId": "3711c22f853106a4", "scanner": "scanner-primary", "fingerprint": "1db253c897d790f7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e400e2ade161990e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/test-all-nfts.spec.js:12"}, "properties": {"repobilityId": "1927c8312ee15702", "scanner": "scanner-primary", "fingerprint": "e400e2ade161990e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4f78685bdc7d55bf", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/test-html-viewer.spec.js:22"}, "properties": {"repobilityId": "ac4f725cf62f471e", "scanner": "scanner-primary", "fingerprint": "4f78685bdc7d55bf", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-91c764b0e7b17226", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/debug-nft10.spec.js:11"}, "properties": {"repobilityId": "bff89fe6a54ccea8", "scanner": "scanner-primary", "fingerprint": "91c764b0e7b17226", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3f249ae11c2217d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/prefetch.spec.js:37"}, "properties": {"repobilityId": "461097e20d216389", "scanner": "scanner-primary", "fingerprint": "3f249ae11c2217d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-809dd1973b03a01b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/homepage-performance.spec.js:23"}, "properties": {"repobilityId": "05c72fc94e8a64ab", "scanner": "scanner-primary", "fingerprint": "809dd1973b03a01b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a0003c6248ba53d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/profile-performance.spec.js:54"}, "properties": {"repobilityId": "710873d3366505c2", "scanner": "scanner-primary", "fingerprint": "a0003c6248ba53d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-273a8272176057fd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/common/socket.js:17"}, "properties": {"repobilityId": "9780695be0fab9ea", "scanner": "scanner-primary", "fingerprint": "273a8272176057fd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2a2b4dbc1e245a9d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/common/provider.jsx:12"}, "properties": {"repobilityId": "073fa7c5c9aecf0c", "scanner": "scanner-primary", "fingerprint": "2a2b4dbc1e245a9d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8eb7bca29dccf8d2", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/UserHistory.jsx:122"}, "properties": {"repobilityId": "a1083141e1f920d7", "scanner": "scanner-primary", "fingerprint": "8eb7bca29dccf8d2", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-bf42a45e300bf44a", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/pages/activity.jsx:192"}, "properties": {"repobilityId": "4d2166d184d0946e", "scanner": "scanner-primary", "fingerprint": "bf42a45e300bf44a", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-e149fe53754f0c6f", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/pages/nft.jsx:808"}, "properties": {"repobilityId": "2643d6bedaf218e1", "scanner": "scanner-primary", "fingerprint": "e149fe53754f0c6f", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-bb77b8c622a8fd8e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/pages/profile.jsx:288"}, "properties": {"repobilityId": "7f5ef667b6359f29", "scanner": "scanner-primary", "fingerprint": "bb77b8c622a8fd8e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-258300844cf8cb67", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in server.cjs:29"}, "properties": {"repobilityId": "ff5083996e805530", "scanner": "scanner-primary", "fingerprint": "258300844cf8cb67", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server.cjs"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-9c371ff15082a705", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in playwright-report/index.html:58"}, "properties": {"repobilityId": "5c1a4d4daf334529", "scanner": "scanner-primary", "fingerprint": "9c371ff15082a705", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "playwright-report/index.html"}, "region": {"startLine": 58}}}]}, {"ruleId": "scanner-9029cfde635dd36d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in playwright-report/index.html:57"}, "properties": {"repobilityId": "72bf5b0e0e2b9155", "scanner": "scanner-primary", "fingerprint": "9029cfde635dd36d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "playwright-report/index.html"}, "region": {"startLine": 57}}}]}, {"ruleId": "scanner-fde9cc8c846f90bb", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in src/pages/nft.jsx:808"}, "properties": {"repobilityId": "01c622d0f2a30210", "scanner": "scanner-primary", "fingerprint": "fde9cc8c846f90bb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/pages/nft.jsx"}, "region": {"startLine": 808}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "989a74409a402368", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-90711f6ce5de9364", "level": "note", "message": {"text": "Very large file: src/pages/nft.jsx (1185 lines)"}, "properties": {"repobilityId": "3a0660c93add257f", "scanner": "scanner-primary", "fingerprint": "90711f6ce5de9364", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "cd711f2c17b52db7", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "432f943452c85a72", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "e67fb2440255a7c3", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "6ef29f1789645253", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-0960f5d03e17027b", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/test-base-rpcs.mjs:5"}, "properties": {"repobilityId": "88f7244da5d345e7", "scanner": "scanner-primary", "fingerprint": "0960f5d03e17027b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-26f67f24c38d72d7", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/blockchain.cjs:218"}, "properties": {"repobilityId": "69e8d58fa279e3de", "scanner": "scanner-primary", "fingerprint": "26f67f24c38d72d7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8978dafe1da8c4be", "level": "none", "message": {"text": "Commented-code block (10 lines) in src/common/ens.jsx:126"}, "properties": {"repobilityId": "2a19b6ecfd10b6e1", "scanner": "scanner-primary", "fingerprint": "8978dafe1da8c4be", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7788df4108f3ff09", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/common/gas.jsx:3"}, "properties": {"repobilityId": "62b4ecb1e74e32f1", "scanner": "scanner-primary", "fingerprint": "7788df4108f3ff09", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-32d36fd41e6b2f28", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/components/NFTCard.jsx:103"}, "properties": {"repobilityId": "61a467c5125dd8fc", "scanner": "scanner-primary", "fingerprint": "32d36fd41e6b2f28", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-38e7b43a51947379", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/components/PrefetchLink.jsx:49"}, "properties": {"repobilityId": "9101bf761fd94cb7", "scanner": "scanner-primary", "fingerprint": "38e7b43a51947379", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-45cdf31158731c8c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/pages/gallery.jsx:95"}, "properties": {"repobilityId": "8744c03f8b251cc6", "scanner": "scanner-primary", "fingerprint": "45cdf31158731c8c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c959bcd4c542971b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/pages/profile.jsx:129"}, "properties": {"repobilityId": "0c59b8c15f0b2ce8", "scanner": "scanner-primary", "fingerprint": "c959bcd4c542971b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ad1f2c0971b89ce0", "level": "note", "message": {"text": "10 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "3bfdc60c61f1870e", "scanner": "scanner-primary", "fingerprint": "ad1f2c0971b89ce0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-3b2ab34e33dabe5e", "level": "warning", "message": {"text": "Frontend route `/nft` has no Link/navigate to it \u2014 src/main.jsx"}, "properties": {"repobilityId": "0eef4b2dc45c1638", "scanner": "scanner-primary", "fingerprint": "3b2ab34e33dabe5e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-c88301252c821b00", "level": "warning", "message": {"text": "Frontend route `/profile` has no Link/navigate to it \u2014 src/main.jsx"}, "properties": {"repobilityId": "cfc5ae30a5e6cec8", "scanner": "scanner-primary", "fingerprint": "c88301252c821b00", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-3c619aa5252d19d6", "level": "warning", "message": {"text": "Frontend route `/bridge` has no Link/navigate to it \u2014 src/main.jsx"}, "properties": {"repobilityId": "ac78552dc7daae29", "scanner": "scanner-primary", "fingerprint": "3c619aa5252d19d6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-3426cac333dc6f76", "level": "note", "message": {"text": "Unused endpoint: GET /og/:id.png"}, "properties": {"repobilityId": "5cacb1b45ebfcfa1", "scanner": "scanner-primary", "fingerprint": "3426cac333dc6f76", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-33e3b77197129ef5", "level": "note", "message": {"text": "Unused endpoint: GET /nft"}, "properties": {"repobilityId": "75d282b101d88546", "scanner": "scanner-primary", "fingerprint": "33e3b77197129ef5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "dac2bd6a472f5d8f", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9331fd384ba44a82", "level": "note", "message": {"text": "Unused endpoint: POST /api/sync"}, "properties": {"repobilityId": "8e52d1c20c9f388e", "scanner": "scanner-primary", "fingerprint": "9331fd384ba44a82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c3cdecb263117dff", "level": "note", "message": {"text": "Unused endpoint: GET /api/sync/status"}, "properties": {"repobilityId": "8d9aaa78db3ae04f", "scanner": "scanner-primary", "fingerprint": "c3cdecb263117dff", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b37265900e79a8a", "level": "note", "message": {"text": "Unused endpoint: GET /api/stats"}, "properties": {"repobilityId": "d6ff2fdcb66e5f00", "scanner": "scanner-primary", "fingerprint": "3b37265900e79a8a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2fc1fe75eafa3812", "level": "note", "message": {"text": "Unused endpoint: GET /api/token/:id/stats"}, "properties": {"repobilityId": "63fec146183567cc", "scanner": "scanner-primary", "fingerprint": "2fc1fe75eafa3812", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b6c79c4242817159", "level": "note", "message": {"text": "Unused endpoint: GET /api/authors"}, "properties": {"repobilityId": "36d11576c2e8182f", "scanner": "scanner-primary", "fingerprint": "b6c79c4242817159", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e16b9202fdc3e256", "level": "note", "message": {"text": "Unused endpoint: GET /api/top-artists"}, "properties": {"repobilityId": "8cc08f8afc03b5af", "scanner": "scanner-primary", "fingerprint": "e16b9202fdc3e256", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1c87483719ffa4d", "level": "note", "message": {"text": "Unused endpoint: GET /api/top-collectors"}, "properties": {"repobilityId": "9e22cc8757f65f6c", "scanner": "scanner-primary", "fingerprint": "c1c87483719ffa4d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f3b29485fc1bd1ef", "level": "note", "message": {"text": "Unused endpoint: POST /api/prewarm"}, "properties": {"repobilityId": "8fd69b12454d15d0", "scanner": "scanner-primary", "fingerprint": "f3b29485fc1bd1ef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f7dfae683877aae4", "level": "note", "message": {"text": "Unused endpoint: POST /api/nft/:id/refresh"}, "properties": {"repobilityId": "bcff7215ccc7d840", "scanner": "scanner-primary", "fingerprint": "f7dfae683877aae4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d8b184e22a2da5a", "level": "note", "message": {"text": "Unused endpoint: POST /api/sync/reset"}, "properties": {"repobilityId": "594030a42b718840", "scanner": "scanner-primary", "fingerprint": "5d8b184e22a2da5a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ece2d920226d7bb", "level": "note", "message": {"text": "Unused endpoint: POST /api/blocks/batch"}, "properties": {"repobilityId": "7a2501dc84dde27e", "scanner": "scanner-primary", "fingerprint": "4ece2d920226d7bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}