{"version":"1.163.0","results":[{"check_id":"generic.secrets.security.detected-generic-api-key.detected-generic-api-key","path":"/src/.env","start":{"line":78,"col":9,"offset":1806},"end":{"line":78,"col":57,"offset":1854},"extra":{"message":"Generic API Key detected","metadata":{"source-rule-url":"https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json","category":"security","technology":["secrets"],"confidence":"LOW","references":["https://github.com/dxa4481/truffleHogRegexes/blob/master/truffleHogRegexes/regexes.json"],"owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"cwe":["CWE-798: Use of Hard-coded Credentials"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-generic-api-key.detected-generic-api-key","shortlink":"https://sg.run/qxj8"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Console/Commands/K6RunTest.php","start":{"line":53,"col":14,"offset":1659},"end":{"line":53,"col":30,"offset":1675},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Console/Commands/K6RunTest.php","start":{"line":66,"col":13,"offset":2268},"end":{"line":66,"col":33,"offset":2288},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Console/Commands/K6RunTest.php","start":{"line":75,"col":18,"offset":2740},"end":{"line":75,"col":34,"offset":2756},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Console/Commands/K6RunTest.php","start":{"line":83,"col":18,"offset":3054},"end":{"line":83,"col":34,"offset":3070},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Console/Commands/K6RunTest.php","start":{"line":95,"col":13,"offset":3505},"end":{"line":95,"col":27,"offset":3519},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Console/Commands/VulnScanCommand.php","start":{"line":69,"col":41,"offset":2456},"end":{"line":69,"col":57,"offset":2472},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Console/Commands/VulnScanCommand.php","start":{"line":103,"col":9,"offset":3947},"end":{"line":103,"col":41,"offset":3979},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Console/Commands/VulnScanCommand.php","start":{"line":105,"col":34,"offset":4014},"end":{"line":105,"col":80,"offset":4060},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Console/Commands/VulnScanCommand.php","start":{"line":126,"col":13,"offset":5052},"end":{"line":126,"col":128,"offset":5167},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/CveController.php","start":{"line":25,"col":9,"offset":588},"end":{"line":25,"col":61,"offset":640},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/GcbController.php","start":{"line":170,"col":10,"offset":6409},"end":{"line":170,"col":27,"offset":6426},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/GcbController.php","start":{"line":173,"col":14,"offset":6509},"end":{"line":173,"col":30,"offset":6525},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/HandoverController.php","start":{"line":287,"col":10,"offset":11453},"end":{"line":287,"col":27,"offset":11470},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/HandoverController.php","start":{"line":290,"col":14,"offset":11553},"end":{"line":290,"col":30,"offset":11569},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/HostController.php","start":{"line":368,"col":10,"offset":13142},"end":{"line":368,"col":27,"offset":13159},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/HostController.php","start":{"line":371,"col":14,"offset":13243},"end":{"line":371,"col":31,"offset":13260},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/HostController.php","start":{"line":406,"col":10,"offset":14630},"end":{"line":406,"col":27,"offset":14647},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/HostController.php","start":{"line":409,"col":14,"offset":14730},"end":{"line":409,"col":30,"offset":14746},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/K6TestController.php","start":{"line":212,"col":9,"offset":8685},"end":{"line":212,"col":114,"offset":8790},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/K6TestController.php","start":{"line":303,"col":10,"offset":13059},"end":{"line":303,"col":27,"offset":13076},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/K6TestController.php","start":{"line":306,"col":14,"offset":13159},"end":{"line":306,"col":30,"offset":13175},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/SslCsrController.php","start":{"line":221,"col":9,"offset":7982},"end":{"line":221,"col":29,"offset":8002},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/SslCsrController.php","start":{"line":223,"col":13,"offset":8057},"end":{"line":223,"col":33,"offset":8077},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":58,"col":9,"offset":1726},"end":{"line":58,"col":54,"offset":1771},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":64,"col":10,"offset":1939},"end":{"line":64,"col":28,"offset":1957},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":65,"col":10,"offset":1968},"end":{"line":65,"col":28,"offset":1986},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":66,"col":10,"offset":1997},"end":{"line":66,"col":25,"offset":2012},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":118,"col":9,"offset":3762},"end":{"line":118,"col":54,"offset":3807},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":124,"col":10,"offset":3969},"end":{"line":124,"col":28,"offset":3987},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":125,"col":10,"offset":3998},"end":{"line":125,"col":28,"offset":4016},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":126,"col":10,"offset":4027},"end":{"line":126,"col":25,"offset":4042},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":157,"col":17,"offset":5067},"end":{"line":157,"col":85,"offset":5135},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":262,"col":17,"offset":8908},"end":{"line":262,"col":91,"offset":8982},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":334,"col":9,"offset":11453},"end":{"line":334,"col":40,"offset":11484},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":343,"col":13,"offset":11783},"end":{"line":343,"col":47,"offset":11817},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":355,"col":9,"offset":12228},"end":{"line":355,"col":51,"offset":12270},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":973,"col":10,"offset":36459},"end":{"line":973,"col":26,"offset":36475},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":976,"col":14,"offset":36554},"end":{"line":976,"col":29,"offset":36569},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":989,"col":14,"offset":36998},"end":{"line":989,"col":29,"offset":37013},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":1026,"col":10,"offset":38374},"end":{"line":1026,"col":24,"offset":38388},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":1029,"col":14,"offset":38468},"end":{"line":1029,"col":30,"offset":38484},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":1045,"col":14,"offset":39005},"end":{"line":1045,"col":30,"offset":39021},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":1068,"col":10,"offset":39867},"end":{"line":1068,"col":24,"offset":39881},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":1071,"col":14,"offset":39961},"end":{"line":1071,"col":30,"offset":39977},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/TestReportController.php","start":{"line":1118,"col":17,"offset":41913},"end":{"line":1118,"col":91,"offset":41987},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/VulnScanController.php","start":{"line":177,"col":10,"offset":6538},"end":{"line":177,"col":27,"offset":6555},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.unlink-use.unlink-use","path":"/src/app/Http/Controllers/VulnScanController.php","start":{"line":180,"col":14,"offset":6638},"end":{"line":180,"col":30,"offset":6654},"extra":{"message":"Using user input when deleting files with `unlink()` is potentially dangerous. A malicious actor could use this to modify or access files they have no right to.","metadata":{"references":["https://www.php.net/manual/en/function.unlink","https://owasp.org/www-project-top-ten/2017/A5_2017-Broken_Access_Control.html"],"category":"security","technology":["php"],"owasp":["A05:2017 - Broken Access Control","A01:2021 - Broken Access Control","A01:2025 - Broken Access Control"],"cwe":["CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Path Traversal"],"source":"https://semgrep.dev/r/php.lang.security.unlink-use.unlink-use","shortlink":"https://sg.run/rYeR"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Http/Controllers/VulnScanController.php","start":{"line":247,"col":9,"offset":9106},"end":{"line":247,"col":20,"offset":9117},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/SslTestService.php","start":{"line":24,"col":9,"offset":562},"end":{"line":24,"col":208,"offset":761},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/SslTestService.php","start":{"line":30,"col":13,"offset":1025},"end":{"line":30,"col":95,"offset":1107},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/SslTestService.php","start":{"line":43,"col":9,"offset":1564},"end":{"line":43,"col":111,"offset":1666},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/SslTestService.php","start":{"line":56,"col":9,"offset":2056},"end":{"line":56,"col":125,"offset":2172},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/SslTestService.php","start":{"line":71,"col":9,"offset":2688},"end":{"line":71,"col":131,"offset":2810},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/SslTestService.php","start":{"line":80,"col":9,"offset":3108},"end":{"line":80,"col":100,"offset":3199},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/ZapService.php","start":{"line":77,"col":9,"offset":2897},"end":{"line":77,"col":41,"offset":2929},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/app/Services/ZapService.php","start":{"line":281,"col":9,"offset":12061},"end":{"line":281,"col":116,"offset":12168},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":224,"col":13,"offset":9486},"end":{"line":224,"col":118,"offset":9591},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":234,"col":17,"offset":10209},"end":{"line":234,"col":48,"offset":10240},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":411,"col":9,"offset":17801},"end":{"line":411,"col":91,"offset":17883},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":435,"col":13,"offset":18793},"end":{"line":435,"col":115,"offset":18895},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":462,"col":5,"offset":19932},"end":{"line":462,"col":87,"offset":20014},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":470,"col":9,"offset":20279},"end":{"line":470,"col":126,"offset":20396},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":487,"col":5,"offset":20989},"end":{"line":487,"col":128,"offset":21112},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":491,"col":9,"offset":21211},"end":{"line":491,"col":140,"offset":21342},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":497,"col":13,"offset":21546},"end":{"line":497,"col":134,"offset":21667},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":506,"col":17,"offset":21959},"end":{"line":506,"col":124,"offset":22066},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":536,"col":5,"offset":22995},"end":{"line":536,"col":121,"offset":23111},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":545,"col":9,"offset":23365},"end":{"line":545,"col":121,"offset":23477},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":548,"col":9,"offset":23520},"end":{"line":548,"col":155,"offset":23666},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":563,"col":13,"offset":24268},"end":{"line":563,"col":185,"offset":24440},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"php.lang.security.exec-use.exec-use","path":"/src/public/api.php","start":{"line":669,"col":13,"offset":29195},"end":{"line":669,"col":117,"offset":29299},"extra":{"message":"Executing non-constant commands. This can lead to command injection.","metadata":{"cwe":["CWE-94: Improper Control of Generation of Code ('Code Injection')"],"references":["https://github.com/FloeDesignTechnologies/phpcs-security-audit/blob/master/Security/Sniffs/BadFunctions/SystemExecFunctionsSniff.php"],"category":"security","technology":["php"],"owasp":["A03:2021 - Injection","A05:2025 - Injection"],"cwe2022-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"HIGH","confidence":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Code Injection"],"source":"https://semgrep.dev/r/php.lang.security.exec-use.exec-use","shortlink":"https://sg.run/5Q1j"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"bash.lang.security.ifs-tampering.ifs-tampering","path":"/src/public/log.sh","start":{"line":101,"col":4,"offset":4559},"end":{"line":101,"col":9,"offset":4564},"extra":{"message":"The special variable IFS affects how splitting takes place when expanding unquoted variables. Don't set it globally. Prefer a dedicated utility such as 'cut' or 'awk' if you need to split input data. If you must use 'read', set IFS locally using e.g. 'IFS=\",\" read -a my_array'.","metadata":{"cwe":["CWE-20: Improper Input Validation"],"category":"security","technology":["bash"],"confidence":"LOW","owasp":["A03:2021 - Injection","A05:2025 - Injection"],"references":["https://owasp.org/Top10/A03_2021-Injection"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Improper Validation"],"source":"https://semgrep.dev/r/bash.lang.security.ifs-tampering.ifs-tampering","shortlink":"https://sg.run/Q9pq"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"python.lang.security.audit.subprocess-shell-true.subprocess-shell-true","path":"/src/storage/app/gcb/gcb_check_apache.py","start":{"line":28,"col":39,"offset":835},"end":{"line":28,"col":43,"offset":839},"extra":{"message":"Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.","fix":"False","metadata":{"source-rule-url":"https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html","owasp":["A01:2017 - Injection","A03:2021 - Injection","A05:2025 - Injection"],"cwe":["CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"references":["https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess","https://docs.python.org/3/library/subprocess.html"],"category":"security","technology":["python"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["secure default"],"likelihood":"HIGH","impact":"LOW","confidence":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Command Injection"],"source":"https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true","shortlink":"https://sg.run/J92w"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"python.lang.security.audit.subprocess-shell-true.subprocess-shell-true","path":"/src/storage/app/gcb/gcb_check_ubuntu.py","start":{"line":31,"col":39,"offset":941},"end":{"line":31,"col":43,"offset":945},"extra":{"message":"Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.","fix":"False","metadata":{"source-rule-url":"https://bandit.readthedocs.io/en/latest/plugins/b602_subprocess_popen_with_shell_equals_true.html","owasp":["A01:2017 - Injection","A03:2021 - Injection","A05:2025 - Injection"],"cwe":["CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"],"references":["https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess","https://docs.python.org/3/library/subprocess.html"],"category":"security","technology":["python"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["secure default"],"likelihood":"HIGH","impact":"LOW","confidence":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Command Injection"],"source":"https://semgrep.dev/r/python.lang.security.audit.subprocess-shell-true.subprocess-shell-true","shortlink":"https://sg.run/J92w"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"html.security.audit.missing-integrity.missing-integrity","path":"/src/storage/app/public/k6/20_20250723_161813/report.html","start":{"line":6,"col":3,"offset":110},"end":{"line":6,"col":64,"offset":171},"extra":{"message":"This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you’re telling the browser to fetch in the 'integrity' attribute for all externally hosted files.","metadata":{"category":"security","technology":["html"],"cwe":["CWE-353: Missing Support for Integrity Check"],"owasp":["A08:2021 - Software and Data Integrity Failures","A08:2025 - Software or Data Integrity Failures"],"confidence":"LOW","references":["https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures"],"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Cryptographic Issues"],"source":"https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity","shortlink":"https://sg.run/krXA"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"html.security.audit.missing-integrity.missing-integrity","path":"/src/storage/app/public/k6/school_688092bd02dfb_20250723_154357/report.html","start":{"line":6,"col":3,"offset":110},"end":{"line":6,"col":64,"offset":171},"extra":{"message":"This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you’re telling the browser to fetch in the 'integrity' attribute for all externally hosted files.","metadata":{"category":"security","technology":["html"],"cwe":["CWE-353: Missing Support for Integrity Check"],"owasp":["A08:2021 - Software and Data Integrity Failures","A08:2025 - Software or Data Integrity Failures"],"confidence":"LOW","references":["https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures"],"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Cryptographic Issues"],"source":"https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity","shortlink":"https://sg.run/krXA"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"html.security.audit.missing-integrity.missing-integrity","path":"/src/storage/app/public/k6/school_68809b1bb16c8_20250723_161939/report.html","start":{"line":6,"col":3,"offset":110},"end":{"line":6,"col":64,"offset":171},"extra":{"message":"This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you’re telling the browser to fetch in the 'integrity' attribute for all externally hosted files.","metadata":{"category":"security","technology":["html"],"cwe":["CWE-353: Missing Support for Integrity Check"],"owasp":["A08:2021 - Software and Data Integrity Failures","A08:2025 - Software or Data Integrity Failures"],"confidence":"LOW","references":["https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures"],"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Cryptographic Issues"],"source":"https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity","shortlink":"https://sg.run/krXA"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"html.security.audit.missing-integrity.missing-integrity","path":"/src/storage/app/public/k6/school_68809ba7cc035_20250723_162159/report.html","start":{"line":6,"col":3,"offset":110},"end":{"line":6,"col":64,"offset":171},"extra":{"message":"This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you’re telling the browser to fetch in the 'integrity' attribute for all externally hosted files.","metadata":{"category":"security","technology":["html"],"cwe":["CWE-353: Missing Support for Integrity Check"],"owasp":["A08:2021 - Software and Data Integrity Failures","A08:2025 - Software or Data Integrity Failures"],"confidence":"LOW","references":["https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures"],"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Cryptographic Issues"],"source":"https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity","shortlink":"https://sg.run/krXA"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"html.security.audit.missing-integrity.missing-integrity","path":"/src/storage/app/public/k6/school_6880b79ebf277_20250723_182118/report.html","start":{"line":6,"col":3,"offset":110},"end":{"line":6,"col":64,"offset":171},"extra":{"message":"This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you’re telling the browser to fetch in the 'integrity' attribute for all externally hosted files.","metadata":{"category":"security","technology":["html"],"cwe":["CWE-353: Missing Support for Integrity Check"],"owasp":["A08:2021 - Software and Data Integrity Failures","A08:2025 - Software or Data Integrity Failures"],"confidence":"LOW","references":["https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures"],"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Cryptographic Issues"],"source":"https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity","shortlink":"https://sg.run/krXA"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"html.security.audit.missing-integrity.missing-integrity","path":"/src/storage/app/public/k6/school_688c2d1a6a610_20250801_105730/report.html","start":{"line":6,"col":3,"offset":110},"end":{"line":6,"col":64,"offset":171},"extra":{"message":"This tag is missing an 'integrity' subresource integrity attribute. The 'integrity' attribute allows for the browser to verify that externally hosted files (for example from a CDN) are delivered without unexpected manipulation. Without this attribute, if an attacker can modify the externally hosted resource, this could lead to XSS and other types of attacks. To prevent this, include the base64-encoded cryptographic hash of the resource (file) you’re telling the browser to fetch in the 'integrity' attribute for all externally hosted files.","metadata":{"category":"security","technology":["html"],"cwe":["CWE-353: Missing Support for Integrity Check"],"owasp":["A08:2021 - Software and Data Integrity Failures","A08:2025 - Software or Data Integrity Failures"],"confidence":"LOW","references":["https://owasp.org/Top10/A08_2021-Software_and_Data_Integrity_Failures"],"subcategory":["audit"],"likelihood":"LOW","impact":"LOW","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Cryptographic Issues"],"source":"https://semgrep.dev/r/html.security.audit.missing-integrity.missing-integrity","shortlink":"https://sg.run/krXA"},"severity":"WARNING","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/public/projects/173/docs/1884_AuthKey_HHGK68M5JZ.p8","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/public/projects/174/docs/1886_AuthKey_W3XDP5L96Z.p8","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/public/projects/90/docs/2078_AuthKey_DB8V78V3G4.p8","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":51,"offset":78},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67f886d87b2ba.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67f887087bc9e.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67f889d6b6b5b.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":61,"offset":88},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67f8e14eb3536.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67f8e59d09f56.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67f8e5c8eb5d6.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67fcb0a643818.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67fcb0c8c5683.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67fcb0ef9c252.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67fcb0f6cc7ea.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":55,"offset":82},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67fcb100901f9.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/67fcb103def18.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":61,"offset":88},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6805b0faa3135.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6805b10025ca9.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":59,"offset":86},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6805b10e46023.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":55,"offset":82},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6805b110d4a11.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":56,"offset":83},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6805e623c7153.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6805e626ecb33.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/680b572cd1491.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6811902814abc.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6811902c7cba4.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":65,"offset":92},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}},{"check_id":"generic.secrets.security.detected-private-key.detected-private-key","path":"/src/storage/app/ssl-csr/6862474bb8911.key","start":{"line":1,"col":1,"offset":0},"end":{"line":2,"col":62,"offset":89},"extra":{"message":"Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file.","metadata":{"cwe":["CWE-798: Use of Hard-coded Credentials"],"source-rule-url":"https://github.com/grab/secret-scanner/blob/master/scanner/signatures/pattern.go","category":"security","technology":["secrets"],"confidence":"LOW","owasp":["A07:2021 - Identification and Authentication Failures","A07:2025 - Authentication Failures"],"references":["https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures"],"cwe2022-top25":true,"cwe2021-top25":true,"subcategory":["audit"],"likelihood":"LOW","impact":"MEDIUM","license":"Semgrep Rules License v1.0. For more details, visit semgrep.dev/legal/rules-license","vulnerability_class":["Hard-coded Secrets"],"source":"https://semgrep.dev/r/generic.secrets.security.detected-private-key.detected-private-key","shortlink":"https://sg.run/b7dr"},"severity":"ERROR","fingerprint":"requires login","lines":"requires login","validation_state":"NO_VALIDATOR","engine_kind":"OSS"}}],"errors":[{"code":3,"level":"warn","type":["PartialParsing",[{"path":"/src/public/log.sh","start":{"line":143,"col":18,"offset":0},"end":{"line":143,"col":20,"offset":2}},{"path":"/src/public/log.sh","start":{"line":143,"col":38,"offset":0},"end":{"line":143,"col":39,"offset":1}},{"path":"/src/public/log.sh","start":{"line":143,"col":57,"offset":0},"end":{"line":143,"col":59,"offset":2}},{"path":"/src/public/log.sh","start":{"line":143,"col":79,"offset":0},"end":{"line":143,"col":80,"offset":1}}]],"message":"Syntax error at line /src/public/log.sh:143:\n `|*` was unexpected","path":"/src/public/log.sh","spans":[{"file":"/src/public/log.sh","start":{"line":143,"col":18,"offset":0},"end":{"line":143,"col":20,"offset":2}},{"file":"/src/public/log.sh","start":{"line":143,"col":38,"offset":0},"end":{"line":143,"col":39,"offset":1}},{"file":"/src/public/log.sh","start":{"line":143,"col":57,"offset":0},"end":{"line":143,"col":59,"offset":2}},{"file":"/src/public/log.sh","start":{"line":143,"col":79,"offset":0},"end":{"line":143,"col":80,"offset":1}}]}],"paths":{"scanned":["/src/.claude/settings.json","/src/.claude/settings.local.json","/src/.editorconfig","/src/.env","/src/.env.example","/src/.gitattributes","/src/.gitignore","/src/.resp","/src/.url","/src/MAINTENANCE_REPORT_README.md","/src/QUICK_START.md","/src/README.md","/src/app/Console/Commands/AttendanceCheckMissing.php","/src/app/Console/Commands/DisableExpiredVpnAccounts.php","/src/app/Console/Commands/FetchLatestCves.php","/src/app/Console/Commands/ForceUpdateSslvpnGroup.php","/src/app/Console/Commands/GenerateMaintenanceReports.php","/src/app/Console/Commands/K6RunTest.php","/src/app/Console/Commands/MonitorHosts.php","/src/app/Console/Commands/RedmineFixRelations.php","/src/app/Console/Commands/RedmineImport.php","/src/app/Console/Commands/SbomScanCommand.php","/src/app/Console/Commands/SyncGitlabProjects.php","/src/app/Console/Commands/VulnScanCommand.php","/src/app/Console/Commands/WarmNucleiCacheCommand.php","/src/app/Console/Kernel.php","/src/app/Events/GitlabRequestProcessed.php","/src/app/Exports/AssetExport.php","/src/app/Exports/HandoverApprovalSheet.php","/src/app/Exports/HandoverAssetSheet.php","/src/app/Exports/HandoverProjectSheet.php","/src/app/Exports/HandoverReportExport.php","/src/app/Exports/HandoverSummarySheet.php","/src/app/Exports/HostMaintenanceReportExport.php","/src/app/Exports/ProjectsExport.php","/src/app/Exports/TestCasesExport.php","/src/app/Http/Controllers/AdminPushController.php","/src/app/Http/Controllers/AgentInstallerController.php","/src/app/Http/Controllers/AgentReportController.php","/src/app/Http/Controllers/AssetController.php","/src/app/Http/Controllers/AttachmentController.php","/src/app/Http/Controllers/AttendanceController.php","/src/app/Http/Controllers/Auth/AuthenticatedSessionController.php","/src/app/Http/Controllers/Auth/ConfirmablePasswordController.php","/src/app/Http/Controllers/Auth/EmailVerificationNotificationController.php","/src/app/Http/Controllers/Auth/EmailVerificationPromptController.php","/src/app/Http/Controllers/Auth/NewPasswordController.php","/src/app/Http/Controllers/Auth/PasswordController.php","/src/app/Http/Controllers/Auth/PasswordResetLinkController.php","/src/app/Http/Controllers/Auth/RegisteredUserController.php","/src/app/Http/Controllers/Auth/VerifyEmailController.php","/src/app/Http/Controllers/BoardController.php","/src/app/Http/Controllers/ChatNotificationChannelController.php","/src/app/Http/Controllers/ClientController.php","/src/app/Http/Controllers/Controller.php","/src/app/Http/Controllers/CveController.php","/src/app/Http/Controllers/DashboardController.php","/src/app/Http/Controllers/DashboardController.php.old","/src/app/Http/Controllers/DeviceRequestController.php","/src/app/Http/Controllers/DocumentationController.php","/src/app/Http/Controllers/GcbController.php","/src/app/Http/Controllers/GitlabRequestController.php","/src/app/Http/Controllers/GoogleChatAppController.php","/src/app/Http/Controllers/HandoverController.php","/src/app/Http/Controllers/HostAlertController.php","/src/app/Http/Controllers/HostController.php","/src/app/Http/Controllers/HostMonitorSettingsController.php","/src/app/Http/Controllers/IsmsController.php","/src/app/Http/Controllers/IssueController.php","/src/app/Http/Controllers/K6TestController.php","/src/app/Http/Controllers/LogController.php","/src/app/Http/Controllers/MaintenanceReportSettingsController.php","/src/app/Http/Controllers/MenuSettingsController.php","/src/app/Http/Controllers/MenuSettingsController.php.old","/src/app/Http/Controllers/ModulePermissionController.php","/src/app/Http/Controllers/MyRedmineController.php","/src/app/Http/Controllers/NotificationController.php","/src/app/Http/Controllers/NucleiInfoController.php","/src/app/Http/Controllers/OvertimeRequestController.php","/src/app/Http/Controllers/ProfileController.php","/src/app/Http/Controllers/ProjectCalendarController.php","/src/app/Http/Controllers/ProjectController.php","/src/app/Http/Controllers/ProjectFileController.php","/src/app/Http/Controllers/ProjectGanttController.php","/src/app/Http/Controllers/ProjectGitlabController.php","/src/app/Http/Controllers/ProjectIssueController.php","/src/app/Http/Controllers/ProjectMemberController.php","/src/app/Http/Controllers/ProjectPortalController.php","/src/app/Http/Controllers/ProjectSettingController.php","/src/app/Http/Controllers/ProjectTimeController.php","/src/app/Http/Controllers/ProjectVersionController.php","/src/app/Http/Controllers/PsmsController.php","/src/app/Http/Controllers/PushSubscriptionController.php","/src/app/Http/Controllers/RedmineAccountRequestController.php","/src/app/Http/Controllers/RedmineProjectController.php","/src/app/Http/Controllers/RepairRequestController.php","/src/app/Http/Controllers/ScanController.php","/src/app/Http/Controllers/SslCsrController.php","/src/app/Http/Controllers/StatisticController.php","/src/app/Http/Controllers/TestReportController.php","/src/app/Http/Controllers/UiPreferenceController.php","/src/app/Http/Controllers/UserController.php","/src/app/Http/Controllers/UserFolderPreferenceController.php","/src/app/Http/Controllers/UserGroupController.php","/src/app/Http/Controllers/VpnAccountController.php","/src/app/Http/Controllers/VpnRequestController.php","/src/app/Http/Controllers/VulnScanController.php","/src/app/Http/Controllers/WorkBoardController.php","/src/app/Http/Kernel.php","/src/app/Http/Middleware/Authenticate.php","/src/app/Http/Middleware/CheckModuleAccess.php","/src/app/Http/Middleware/CheckModuleAdmin.php","/src/app/Http/Middleware/EnsureAdmin.php","/src/app/Http/Middleware/OperationLogger.php","/src/app/Http/Middleware/RedirectIfAuthenticated.php","/src/app/Http/Middleware/VerifyCsrfToken.php","/src/app/Http/Requests/Auth/LoginRequest.php","/src/app/Http/Requests/ProfileUpdateRequest.php","/src/app/Http/Requests/StoreDeviceRequest.php","/src/app/Imports/ClientsImport.php","/src/app/Jobs/GenerateMaintenanceReportJob.php","/src/app/Jobs/GenerateReportJob.php","/src/app/Jobs/LaunchNessusScan.php","/src/app/Jobs/ParseCsvFindings.php","/src/app/Jobs/PollNessusScan.php","/src/app/Jobs/WaitExportAndDownload.php","/src/app/Listeners/LogSuccessfulLogin.php","/src/app/Listeners/LogSuccessfulLogout.php","/src/app/Listeners/SendGitlabNotification.php","/src/app/Mail/DeviceRequestApproved.php","/src/app/Mail/DeviceRequestPendingAdmin.php","/src/app/Mail/DeviceRequestPendingSupervisor.php","/src/app/Mail/DeviceRequestRejected.php","/src/app/Mail/GitlabRequestApproved.php","/src/app/Mail/GitlabRequestPendingAdmin.php","/src/app/Mail/GitlabRequestPendingSupervisor.php","/src/app/Mail/GitlabRequestRejected.php","/src/app/Mail/HandoverApprovedMail.php","/src/app/Mail/HandoverReceiverNotifyMail.php","/src/app/Mail/HandoverRejectedMail.php","/src/app/Mail/HandoverStagePendingMail.php","/src/app/Mail/IssueAssignedMail.php","/src/app/Mail/IssueCommentedMail.php","/src/app/Mail/IssueStatusChangedMail.php","/src/app/Mail/MaintenanceReportMail.php","/src/app/Mail/OvertimeRequestApproved.php","/src/app/Mail/OvertimeRequestPendingAdmin.php","/src/app/Mail/OvertimeRequestPendingSupervisor.php","/src/app/Mail/OvertimeRequestRejected.php","/src/app/Mail/VpnAccountApproved.php","/src/app/Mail/VpnExpiredDisabledMail.php","/src/app/Mail/VpnRequestPendingAdmin.php","/src/app/Mail/VpnRequestPendingSupervisor.php","/src/app/Mail/WorkBoardCardNotification.php","/src/app/Models/Asset.php","/src/app/Models/Attachment.php","/src/app/Models/Attendance.php","/src/app/Models/Card.php","/src/app/Models/CardFolder.php","/src/app/Models/ChatAppSubscription.php","/src/app/Models/ChatNotificationChannel.php","/src/app/Models/ChatNotificationLog.php","/src/app/Models/Client.php","/src/app/Models/DashboardFolder.php","/src/app/Models/DeviceRequest.php","/src/app/Models/DocCategory.php","/src/app/Models/DocTemplate.php","/src/app/Models/Documentation.php","/src/app/Models/DocumentationLog.php","/src/app/Models/GcbExclusion.php","/src/app/Models/GcbProfile.php","/src/app/Models/GcbReport.php","/src/app/Models/GitlabAccountRequest.php","/src/app/Models/GitlabProjectCache.php","/src/app/Models/GitlabRequest.php","/src/app/Models/Handover.php","/src/app/Models/HandoverApproval.php","/src/app/Models/HandoverAsset.php","/src/app/Models/HandoverChecklistTemplate.php","/src/app/Models/HandoverProject.php","/src/app/Models/HandoverResponse.php","/src/app/Models/HandoverStageApprover.php","/src/app/Models/Host.php","/src/app/Models/HostAlert.php","/src/app/Models/IsmsCategory.php","/src/app/Models/IsmsDocument.php","/src/app/Models/Issue.php","/src/app/Models/IssueCategory.php","/src/app/Models/IssueComment.php","/src/app/Models/IssuePriority.php","/src/app/Models/IssueStatus.php","/src/app/Models/IssueTracker.php","/src/app/Models/K6Result.php","/src/app/Models/K6Test.php","/src/app/Models/Log.php","/src/app/Models/Module.php","/src/app/Models/ModulePermission.php","/src/app/Models/NvdCve.php","/src/app/Models/OvertimeRequest.php","/src/app/Models/Project.php","/src/app/Models/ProjectNotificationSetting.php","/src/app/Models/ProjectVersion.php","/src/app/Models/PushSubscription.php","/src/app/Models/RedmineAccountRequest.php","/src/app/Models/RepairRequest.php","/src/app/Models/Role.php","/src/app/Models/ScanFinding.php","/src/app/Models/ScanReport.php","/src/app/Models/ScanTarget.php","/src/app/Models/ScanTask.php","/src/app/Models/SiteNotification.php","/src/app/Models/SystemSetting.php","/src/app/Models/TestCase.php","/src/app/Models/TestReport.php","/src/app/Models/TimeActivity.php","/src/app/Models/TimeEntry.php","/src/app/Models/User.php","/src/app/Models/UserCardSetting.php","/src/app/Models/UserFolderPreference.php","/src/app/Models/UserGroup.php","/src/app/Models/UserUiPreference.php","/src/app/Models/VpnAccount.php","/src/app/Models/VpnAccountRequest.php","/src/app/Models/VulnScan.php","/src/app/Models/WorkBoardCard.php","/src/app/Models/WorkBoardCategory.php","/src/app/Models/WorkBoardColumn.php","/src/app/Models/WorkBoardNotificationSetting.php","/src/app/Models/WorkBoardSubtask.php","/src/app/Observers/LogObserver.php","/src/app/Observers/SslCsrObserver.php","/src/app/Policies/ProjectPolicy.php","/src/app/Providers/AppServiceProvider.php","/src/app/Providers/AuthServiceProvider.php","/src/app/Services/CveService.php","/src/app/Services/FortiGateService.php","/src/app/Services/FortiGateService.php.old","/src/app/Services/GitlabService.php","/src/app/Services/GoogleChatAppService.php","/src/app/Services/GoogleChatService.php","/src/app/Services/LineNotifyService.php","/src/app/Services/LogService.php","/src/app/Services/MaintenanceReportScheduleService.php","/src/app/Services/NessusClient.php","/src/app/Services/NessusService.php","/src/app/Services/NucleiService.php","/src/app/Services/PdfTextExtractor.php","/src/app/Services/RedmineService.php","/src/app/Services/SbomVulnService.php","/src/app/Services/SslTestService.php","/src/app/Services/SystemReportService.php","/src/app/Services/VisionService.php","/src/app/Services/WebPushService.php","/src/app/Services/ZapService.php","/src/app/View/Components/AppLayout.php","/src/app/View/Components/GuestLayout.php","/src/artisan","/src/bootstrap/app.php","/src/bootstrap/app.php.old","/src/bootstrap/cache/.gitignore","/src/bootstrap/cache/packages.php","/src/bootstrap/cache/services.php","/src/bootstrap/providers.php","/src/composer.json","/src/composer.lock","/src/config/app.php","/src/config/auth.php","/src/config/cache.php","/src/config/database.php","/src/config/dompdf.php","/src/config/filesystems.php","/src/config/fortigate.php","/src/config/gemini.php","/src/config/log_actions.php","/src/config/logging.php","/src/config/mail.php","/src/config/nessus.php","/src/config/p.crt","/src/config/pake.crt","/src/config/queue.php","/src/config/redmine.php","/src/config/services.php","/src/config/session.php","/src/database/.gitignore","/src/database/database.sqlite","/src/database/factories/UserFactory.php","/src/database/migrations/0001_01_01_000000_create_users_table.php","/src/database/migrations/0001_01_01_000001_create_cache_table.php","/src/database/migrations/0001_01_01_000002_create_jobs_table.php","/src/database/migrations/2025_04_07_085427_create_vpn_accounts_table.php","/src/database/migrations/2025_04_11_143725_create_logs_table.php","/src/database/migrations/2025_04_15_154055_create_hosts_table.php","/src/database/migrations/2025_04_22_154749_add_role_to_users_table.php","/src/database/migrations/2025_04_24_110010_alter_logs_table_add_columns.php","/src/database/migrations/2025_04_25_100516_create_vpn_account_requests_table.php","/src/database/migrations/2025_04_25_111141_add_role_to_users_table.php","/src/database/migrations/2025_04_28_090707_add_department_and_position_to_users_table.php","/src/database/migrations/2025_04_29_112325_add_group_to_vpn_accounts_table.php","/src/database/migrations/2025_04_29_163107_create_redmine_account_requests_table.php","/src/database/migrations/2025_04_29_165821_add_password_to_redmine_account_requests_table.php","/src/database/migrations/2025_04_29_165911_add_expire_date_to_redmine_account_requests_table.php","/src/database/migrations/2025_04_29_170024_add_project_id_to_redmine_account_requests_table.php","/src/database/migrations/2025_04_29_170130_create_redmine_account_requests_table.php","/src/database/migrations/2025_04_29_182314_alter_redmine_requests_projects_column.php","/src/database/migrations/2025_04_30_000000_create_device_requests_table.php","/src/database/migrations/2025_04_30_173955_add_note_to_device_requests_table.php","/src/database/migrations/2025_05_05_182230_make_device_type_nullable_on_device_requests.php","/src/database/migrations/2025_05_07_114032_add_approved_columns_to_device_requests.php","/src/database/migrations/2025_05_14_211316_alter_device_requests_for_out_flow.php","/src/database/migrations/2025_05_16_165547_add_asset_columns_to_device_requests_table.php","/src/database/migrations/2025_05_20_113957_create_assets_table.php","/src/database/migrations/2025_05_20_114951_update_assets_table_add_manager_id.php","/src/database/migrations/2025_05_20_140653_add_asset_id_to_device_requests_table.php","/src/database/migrations/2025_05_21_112850_add_supervisor_id_to_users_table.php","/src/database/migrations/2025_05_21_153337_create_repair_requests_table.php","/src/database/migrations/2025_05_21_224046_create_cards_table.php","/src/database/migrations/2025_05_21_224052_create_user_card_settings_table.php","/src/database/migrations/2025_05_22_004407_add_card_display_fields_to_cards_table.php","/src/database/migrations/2025_05_22_175939_create_gitlab_requests_table.php","/src/database/migrations/2025_05_23_013854_add_user_id_to_gitlab_requests_table.php","/src/database/migrations/2025_05_23_014457_add_supervisor_id_to_gitlab_requests_table.php","/src/database/migrations/2025_05_23_132826_make_project_id_nullable_on_gitlab_requests_table.php","/src/database/migrations/2025_05_23_133007_make_project_and_access_nullable_on_gitlab_requests.php","/src/database/migrations/2025_05_23_134218_add_fields_to_gitlab_requests_table.php","/src/database/migrations/2025_05_23_163444_fill_and_make_not_null_on_gitlab_requests.php","/src/database/migrations/2025_05_23_163651_sync_gitlab_requests_columns.php","/src/database/migrations/2025_05_23_164402_rename_gitlab_requests_to_gitlab_accounts.php","/src/database/migrations/2025_05_23_164457_create_gitlab_account_requests_table.php","/src/database/migrations/2025_05_26_163746_create_gitlab_project_cache_table.php","/src/database/migrations/2025_05_28_142319_add_group_id_to_gitlab_account_requests_table.php","/src/database/migrations/2025_05_28_144503_add_group_id_to_gitlab_account_requests_table.php","/src/database/migrations/2025_06_11_170134_create_clients_table.php","/src/database/migrations/2025_06_11_170139_create_projects_table.php","/src/database/migrations/2025_06_11_170318_add_client_project_to_test_reports.php","/src/database/migrations/2025_06_11_181155_create_test_cases_table.php","/src/database/migrations/2025_06_12_140245_add_contact_fields_to_clients_table.php","/src/database/migrations/2025_06_12_141250_add_fields_to_projects_table.php","/src/database/migrations/2025_06_12_144356_make_file_path_nullable_on_test_reports_table.php","/src/database/migrations/2025_06_12_145055_add_content_to_test_reports_table.php","/src/database/migrations/2025_06_12_155659_add_client_id_to_hosts_table.php","/src/database/migrations/2025_06_12_161131_add_project_id_and_drop_client_id_from_hosts_table.php","/src/database/migrations/2025_06_25_180759_add_ai_explanation_to_test_reports_table.php","/src/database/migrations/2025_06_26_135136_add_input_type_and_ai_explanation_to_test_reports_table.php","/src/database/migrations/2025_06_27_002702_add_credentials_to_hosts_table.php","/src/database/migrations/2025_06_27_140103_create_project_user_table.php","/src/database/migrations/2025_06_27_140438_create_documentations_table.php","/src/database/migrations/2025_06_27_140623_create_attachments_table.php","/src/database/migrations/2025_07_01_160207_add_parent_id_to_projects_table.php","/src/database/migrations/2025_07_03_003726_create_overtime_requests_table.php","/src/database/migrations/2025_07_18_134429_create_k6_results_table.php","/src/database/migrations/2025_07_18_140033_create_k6_tests_table.php","/src/database/migrations/2025_07_18_143759_update_k6_results_add_details.php","/src/database/migrations/2025_07_18_150944_alter_k6_results_stages_json.php","/src/database/migrations/2025_07_23_134203_add_login_fields_to_k6_results_table.php","/src/database/migrations/2025_07_24_101248_add_dev_tool_to_projects_table.php","/src/database/migrations/2025_07_29_100552_create_modules_table.php","/src/database/migrations/2025_07_29_100629_create_module_user_tabl.php","/src/database/migrations/2025_07_29_114838_create_module_permissions_table.php","/src/database/migrations/2025_07_29_120304_drop_module_user_table.php","/src/database/migrations/2025_07_29_121026_create_module_permissions_table.php","/src/database/migrations/2025_07_29_135830_add_contract_and_maintenance_to_clients_table.php","/src/database/migrations/2025_07_29_160707_add_is_active_to_users_table.php","/src/database/migrations/2025_07_29_163202_add_contract_and_maintenance_to_projects_table.php","/src/database/migrations/2025_07_30_144055_add_controller_to_cards_table.php","/src/database/migrations/2025_07_30_145203_add_invoice_and_notes_to_projects_table.php","/src/database/migrations/2025_07_30_162957_add_module_controller_to_cards_table.php","/src/database/migrations/2025_07_30_175340_add_route_name_to_module_permissions_table.php","/src/database/migrations/2025_07_30_175437_add_route_name_to_cards_table.php","/src/database/migrations/2025_07_31_002659_create_modules_table.php","/src/database/migrations/2025_07_31_014739_create_module_permissions_table.php","/src/database/migrations/2025_07_31_135312_create_issue_categories_table.php","/src/database/migrations/2025_07_31_135316_create_issues_table.php","/src/database/migrations/2025_07_31_151639_alter_status_enum_in_issues_table.php","/src/database/migrations/2025_08_07_115354_create_dashboard_folders_table.php","/src/database/migrations/2025_08_07_115358_create_dashboard_folder_cards_table.php","/src/database/migrations/2025_08_07_134638_create_card_folders_table.php","/src/database/migrations/2025_08_07_140859_add_folder_id_to_user_card_settings_table.php","/src/database/migrations/2025_08_07_154108_add_sort_to_card_folders_and_cards.php","/src/database/migrations/2025_08_07_155251_add_card_folder_id_to_cards.php","/src/database/migrations/2025_08_07_164232_alter_user_id_nullable_in_card_folders.php","/src/database/migrations/2025_08_08_000001_create_user_folder_preferences_table.php","/src/database/migrations/2025_08_08_120000_create_user_ui_preferences_table.php","/src/database/migrations/2025_08_22_105017_create_scan_tasks_table.php","/src/database/migrations/2025_08_22_105021_create_scan_targets_table.php","/src/database/migrations/2025_08_22_105028_create_scan_reports_table.php","/src/database/migrations/2025_08_22_105032_create_scan_findings_table.php","/src/database/migrations/2026_03_16_135139_add_is_doc_controller_to_module_permissions_table.php","/src/database/migrations/2026_03_16_180000_create_gcb_profiles_table.php","/src/database/migrations/2026_03_16_190000_create_gcb_reports_table.php","/src/database/migrations/2026_03_18_154425_add_email_to_redmine_account_requests_table.php","/src/database/migrations/2026_03_18_155742_add_request_type_to_redmine_account_requests_table.php","/src/database/migrations/2026_04_15_155901_add_code_content_and_ai_code_review_to_test_reports_table.php","/src/database/migrations/2026_04_15_162845_add_code_files_and_scan_to_test_reports_table.php","/src/database/migrations/2026_04_16_114805_add_test_checklist_to_test_reports_table.php","/src/database/migrations/2026_04_16_180154_add_ai_provider_to_test_reports_table.php","/src/database/migrations/2026_04_22_101342_add_schedule_fields_to_projects_table.php","/src/database/migrations/2026_04_22_115434_create_nvd_cves_table.php","/src/database/migrations/2026_04_22_140423_create_chat_notification_channels_table.php","/src/database/migrations/2026_04_22_140423_create_chat_notification_logs_table.php","/src/database/migrations/2026_04_22_200000_add_line_support_to_chat_notification_channels_table.php","/src/database/migrations/2026_04_22_210000_add_monitor_fields_to_hosts_table.php","/src/database/migrations/2026_04_22_220000_add_lat_lng_to_clients_table.php","/src/database/migrations/2026_04_23_182307_add_address_to_clients_table.php","/src/database/migrations/2026_04_24_174714_create_chat_app_subscriptions_table.php","/src/database/migrations/2026_05_04_170050_make_api_url_nullable_in_hosts.php","/src/database/migrations/2026_05_12_112813_create_work_board_columns_table.php","/src/database/migrations/2026_05_12_112814_create_work_board_cards_table.php","/src/database/migrations/2026_05_12_115305_add_category_to_work_board.php","/src/database/migrations/2026_05_12_121000_add_project_to_work_board.php","/src/database/migrations/2026_05_12_130000_add_start_date_and_subtasks_to_work_board.php","/src/database/migrations/2026_05_12_165000_add_user_id_to_work_board_columns.php","/src/database/migrations/2026_05_12_170000_add_user_id_to_work_board_categories.php","/src/database/migrations/2026_05_12_180000_add_work_hours_to_work_board_cards.php","/src/database/migrations/2026_05_13_101807_create_work_board_card_users_table.php","/src/database/migrations/2026_05_13_103050_create_work_board_notification_settings_table.php","/src/database/migrations/2026_05_13_112431_add_redmine_fields_to_issues_table.php","/src/database/migrations/2026_05_13_112431_create_issue_comments_table.php","/src/database/migrations/2026_05_13_134126_fix_issues_table_for_import.php","/src/database/migrations/2026_05_13_143456_add_doc_and_redmine_id_to_attachments_table.php","/src/database/migrations/2026_05_13_200000_add_type_to_documentations_table.php","/src/database/migrations/2026_05_13_210000_add_redmine_id_to_documentations_table.php","/src/database/migrations/2026_05_14_104759_make_projects_client_id_nullable.php","/src/database/migrations/2026_05_15_000001_create_documentation_logs_table.php","/src/database/migrations/2026_05_15_100001_create_handovers_table.php","/src/database/migrations/2026_05_15_110000_enhance_handover_checklist.php","/src/database/migrations/2026_05_15_132844_create_handover_stage_approvers_table.php","/src/database/migrations/2026_05_15_150000_add_confirm_dept_to_assets.php","/src/database/migrations/2026_05_15_160000_add_receiver_confirm_to_handover_projects.php","/src/database/migrations/2026_05_15_170000_add_excluded_projects_to_handovers.php","/src/database/migrations/2026_05_15_180000_add_attachment_to_handover_responses.php","/src/database/migrations/2026_05_18_100000_add_product_to_project_type_enum.php","/src/database/migrations/2026_05_18_110000_rename_product_to_goods_in_project_type.php","/src/database/migrations/2026_05_18_120000_add_reason_to_handovers.php","/src/database/migrations/2026_05_18_172233_create_notifications_tables.php","/src/database/migrations/2026_05_18_172233_create_push_subscriptions_table.php","/src/database/migrations/2026_05_19_114931_add_project_role_to_project_user_table.php","/src/database/migrations/2026_05_19_115722_create_project_roles_table.php","/src/database/migrations/2026_05_19_123515_create_time_entries_table.php","/src/database/migrations/2026_05_19_133853_convert_to_global_project_settings.php","/src/database/migrations/2026_05_19_151034_add_view_perms_to_roles_table.php","/src/database/migrations/2026_05_19_151752_create_user_groups_tables.php","/src/database/migrations/2026_05_19_160000_create_project_versions_table.php","/src/database/migrations/2026_05_19_170000_add_version_id_to_documentation_table.php","/src/database/migrations/2026_05_19_180000_create_project_version_members_table.php","/src/database/migrations/2026_05_19_190000_add_gitlab_project_id_to_projects_table.php","/src/database/migrations/2026_05_20_111128_create_doc_categories_table.php","/src/database/migrations/2026_05_20_111129_add_category_id_to_documentations_table.php","/src/database/migrations/2026_05_20_112437_create_doc_templates_table.php","/src/database/migrations/2026_05_20_150000_add_extended_perms_to_roles_table.php","/src/database/migrations/2026_05_20_160000_add_manage_roadmap_to_roles_table.php","/src/database/migrations/2026_05_20_170000_create_project_notification_settings_table.php","/src/database/migrations/2026_05_21_100000_add_ip_address_to_hosts_table.php","/src/database/migrations/2026_05_21_110000_add_host_type_to_hosts_table.php","/src/database/migrations/2026_05_21_120000_add_geo_to_hosts_table.php","/src/database/migrations/2026_05_21_200000_add_agent_fields_to_hosts_table.php","/src/database/migrations/2026_05_21_210000_add_disk_alert_threshold_to_hosts.php","/src/database/migrations/2026_05_21_220000_create_system_settings_table.php","/src/database/migrations/2026_05_21_220001_add_cpu_mem_thresholds_to_hosts.php","/src/database/migrations/2026_05_21_230000_add_critical_thresholds_to_hosts.php","/src/database/migrations/2026_05_21_240000_create_host_alerts_table.php","/src/database/migrations/2026_05_21_250000_add_categories_to_host_alerts.php","/src/database/migrations/2026_05_22_100000_add_alert_email_to_hosts.php","/src/database/migrations/2026_05_22_200000_extend_host_alerts_level_enum.php","/src/database/migrations/2026_05_22_220000_add_sbom_data_to_hosts_table.php","/src/database/migrations/2026_05_22_300000_add_av_fields_to_hosts.php","/src/database/migrations/2026_05_25_100000_add_os_type_to_hosts_table.php","/src/database/migrations/2026_05_26_100000_add_agent_version_to_hosts_table.php","/src/database/migrations/2026_05_27_021412_create_attendances_table.php","/src/database/migrations/2026_05_27_021753_add_attendance_ip_settings.php","/src/database/migrations/2026_05_27_022419_add_attendance_module.php","/src/database/migrations/2026_05_27_023712_add_is_contractor_to_users_table.php","/src/database/migrations/2026_05_27_030000_add_work_schedule_group_to_users.php","/src/database/migrations/2026_05_27_030100_add_attendance_group_settings.php","/src/database/migrations/2026_05_27_040000_add_attendance_exempt_to_users.php","/src/database/migrations/2026_05_27_050000_add_attendance_cards.php","/src/database/migrations/2026_05_27_060000_create_isms_tables.php","/src/database/migrations/2026_05_27_060100_add_system_to_isms_tables.php","/src/database/migrations/2026_05_27_060200_add_isms_psms_cards.php","/src/database/migrations/2026_05_27_070000_add_status_to_k6_results.php","/src/database/migrations/2026_05_27_080000_add_joined_at_to_users.php","/src/database/migrations/2026_05_28_090000_add_sbom_vuln_data_to_hosts.php","/src/database/migrations/2026_05_29_100000_create_vuln_scans_table.php","/src/database/migrations/2026_05_30_100000_add_scanner_type_to_vuln_scans.php","/src/database/seeders/CardSeeder.php","/src/database/seeders/DatabaseSeeder.php","/src/database/seeders/IssueCategorySeeder.php","/src/database/seeders/ModuleSeeder.php","/src/database/seeders/PermissionSeeder.php","/src/database/seeders/UserSeeder.php","/src/deploy-board-to-portal.sh","/src/deploy-project-features-to-portal.sh","/src/docker/apache-data/000-default.conf","/src/docker/init.sh","/src/docker.sh","/src/package-lock.json","/src/package.json","/src/phpunit.xml","/src/postcss.config.js","/src/public/.htaccess","/src/public/.user.ini","/src/public/111.html","/src/public/api.php","/src/public/cert.crt","/src/public/favicon.ico","/src/public/geo/taiwan.geojson","/src/public/git","/src/public/index.php","/src/public/install.sh","/src/public/log.sh","/src/public/robots.txt","/src/public/stepshost.php","/src/public/sw.js","/src/resources/css/app.css","/src/resources/js/app.js","/src/resources/js/bootstrap.js","/src/resources/lang/zh_TW/validation.php","/src/resources/sass/app.scss","/src/resources/views/agent/installer.blade.php","/src/resources/views/agent/installer_windows.blade.php","/src/resources/views/assets/by-user.blade.php","/src/resources/views/assets/byuser.blade.php","/src/resources/views/assets/byuser.blade.php.old","/src/resources/views/assets/create.blade.php","/src/resources/views/assets/edit.blade.php","/src/resources/views/assets/index.blade.php","/src/resources/views/assets/report.blade.php","/src/resources/views/assets/show.blade.php","/src/resources/views/assets/subordinates.blade.php","/src/resources/views/attendance/admin.blade.php","/src/resources/views/attendance/index.blade.php","/src/resources/views/attendance/settings.blade.php","/src/resources/views/attendance/stats.blade.php","/src/resources/views/auth/confirm-password.blade.php","/src/resources/views/auth/forgot-password.blade.php","/src/resources/views/auth/login.blade.php","/src/resources/views/auth/register.blade.php.old","/src/resources/views/auth/reset-password.blade.php","/src/resources/views/auth/verify-email.blade.php","/src/resources/views/boards/index.blade.php","/src/resources/views/clients/_location.blade.php","/src/resources/views/clients/create.blade.php","/src/resources/views/clients/edit.blade.php","/src/resources/views/clients/import.blade.php","/src/resources/views/clients/index.blade.php","/src/resources/views/clients/show.blade.php","/src/resources/views/components/application-logo.blade.php","/src/resources/views/components/auth-session-status.blade.php","/src/resources/views/components/danger-button.blade.php","/src/resources/views/components/dropdown-link.blade.php","/src/resources/views/components/dropdown.blade.php","/src/resources/views/components/folder-card.blade.php","/src/resources/views/components/input-error.blade.php","/src/resources/views/components/input-label.blade.php","/src/resources/views/components/ios-folder-link.blade.php.bak","/src/resources/views/components/ios-folders-link.blade.php","/src/resources/views/components/modal.blade.php","/src/resources/views/components/nav-link.blade.php","/src/resources/views/components/primary-button.blade.php","/src/resources/views/components/responsive-nav-link.blade.php","/src/resources/views/components/secondary-button.blade.php","/src/resources/views/components/text-input.blade.php","/src/resources/views/cve/index.blade.php","/src/resources/views/dashboard/cards/_template.blade.php","/src/resources/views/dashboard/cards/account-management.blade.php","/src/resources/views/dashboard/cards/asset-management.blade.php","/src/resources/views/dashboard/cards/asset-personal.blade.php","/src/resources/views/dashboard/cards/attendance.blade.php","/src/resources/views/dashboard/cards/client-management.blade.php","/src/resources/views/dashboard/cards/device-request.blade.php","/src/resources/views/dashboard/cards/gitlab-request.blade.php","/src/resources/views/dashboard/cards/host-management.blade.php","/src/resources/views/dashboard/cards/host-personal.blade.php","/src/resources/views/dashboard/cards/isms.blade.php","/src/resources/views/dashboard/cards/issues.blade.php","/src/resources/views/dashboard/cards/k6-test.blade.php","/src/resources/views/dashboard/cards/overtimerequest.blade.php","/src/resources/views/dashboard/cards/project-management.blade.php","/src/resources/views/dashboard/cards/project-warranty.blade.php","/src/resources/views/dashboard/cards/psms.blade.php","/src/resources/views/dashboard/cards/repair.blade.php","/src/resources/views/dashboard/cards/ssl-csr.blade.php","/src/resources/views/dashboard/cards/stats.blade.php","/src/resources/views/dashboard/cards/system-log.blade.php","/src/resources/views/dashboard/cards/test-report.blade.php","/src/resources/views/dashboard/cards/vpn-request.blade.php","/src/resources/views/dashboard.blade.php","/src/resources/views/dashboard.blade.php.old","/src/resources/views/device-requests/_table.blade.php","/src/resources/views/device-requests/admin-index.blade.php","/src/resources/views/device-requests/approved-index.blade.php","/src/resources/views/device-requests/create-in.blade.php","/src/resources/views/device-requests/create.blade.php.old","/src/resources/views/device-requests/entry.blade.php","/src/resources/views/device-requests/index.blade.php","/src/resources/views/device-requests/index.blade.php.old","/src/resources/views/device-requests/out-admin-index.blade.php","/src/resources/views/device-requests/out-create.blade.php","/src/resources/views/device-requests/out-supervisor-index.blade.php","/src/resources/views/device-requests/partials/out-modal.blade.php","/src/resources/views/device-requests/show.blade.php","/src/resources/views/device-requests/show.blade.php.old","/src/resources/views/device-requests/supervisor-index.blade.php","/src/resources/views/emails/device/approved.blade.php","/src/resources/views/emails/device/pending-admin.blade.php","/src/resources/views/emails/device/pending-supervisor.blade.php","/src/resources/views/emails/device/rejected.blade.php","/src/resources/views/emails/gitlab/approved.blade.php","/src/resources/views/emails/gitlab/pending-admin.blade.php","/src/resources/views/emails/gitlab/pending-supervisor.blade.php","/src/resources/views/emails/gitlab/rejected.blade.php","/src/resources/views/emails/handover/approved.blade.php","/src/resources/views/emails/handover/receiver-notify.blade.php","/src/resources/views/emails/handover/rejected.blade.php","/src/resources/views/emails/handover/stage-pending.blade.php","/src/resources/views/emails/issues/assigned.blade.php","/src/resources/views/emails/issues/commented.blade.php","/src/resources/views/emails/issues/status-changed.blade.php","/src/resources/views/emails/ssl_notification_plain.blade.php","/src/resources/views/emails/vpn/expired-disabled.blade.php","/src/resources/views/emails/vpn/pending-admin.blade.php","/src/resources/views/emails/vpn/pending-supervisor.blade.php","/src/resources/views/emails/vpn_approved.blade.php","/src/resources/views/emails/work-board/card-notification.blade.php","/src/resources/views/folders/show.blade.php","/src/resources/views/gcb/_item_table.blade.php","/src/resources/views/gcb/index.blade.php","/src/resources/views/gcb/profile-edit.blade.php","/src/resources/views/gcb/report-pdf.blade.php","/src/resources/views/gcb/report.blade.php","/src/resources/views/gitlab-requests/admin.blade.php","/src/resources/views/gitlab-requests/create.blade.php","/src/resources/views/gitlab-requests/index.blade.php","/src/resources/views/gitlab-requests/list.blade.php","/src/resources/views/gitlab-requests/supervisor.blade.php","/src/resources/views/handovers/_response_item.blade.php","/src/resources/views/handovers/checklist.blade.php","/src/resources/views/handovers/create.blade.php","/src/resources/views/handovers/index.blade.php","/src/resources/views/handovers/pdf.blade.php","/src/resources/views/handovers/review.blade.php","/src/resources/views/handovers/review_history.blade.php","/src/resources/views/handovers/settings.blade.php","/src/resources/views/handovers/show.blade.php","/src/resources/views/hosts/_agent_cell.blade.php","/src/resources/views/hosts/_quick_agent.blade.php","/src/resources/views/hosts/_quick_av.blade.php","/src/resources/views/hosts/_quick_sbom.blade.php","/src/resources/views/hosts/alerts.blade.php","/src/resources/views/hosts/create.blade.php","/src/resources/views/hosts/doc.blade.php","/src/resources/views/hosts/edit.blade.php","/src/resources/views/hosts/import.blade.php","/src/resources/views/hosts/index.blade.php","/src/resources/views/hosts/index.blade.php.old","/src/resources/views/hosts/monitor-settings.blade.php","/src/resources/views/hosts/pdf.blade.php","/src/resources/views/hosts/show.blade.php","/src/resources/views/isms/_doc_row.blade.php","/src/resources/views/isms/categories.blade.php","/src/resources/views/isms/category.blade.php","/src/resources/views/isms/create.blade.php","/src/resources/views/isms/edit.blade.php","/src/resources/views/isms/index.blade.php","/src/resources/views/isms/show.blade.php","/src/resources/views/issues/create.blade.php","/src/resources/views/issues/index.blade.php","/src/resources/views/issues/show.blade.php","/src/resources/views/issues/stats.blade.php","/src/resources/views/k6/edit.blade.php","/src/resources/views/k6/index.blade.php","/src/resources/views/k6/report-pdf.blade.php","/src/resources/views/k6/run.blade.php","/src/resources/views/k6/show.blade.php","/src/resources/views/k6/waiting.blade.php","/src/resources/views/layouts/app.blade.php","/src/resources/views/layouts/app.blade.php.old","/src/resources/views/layouts/app1.blade.php","/src/resources/views/layouts/app2.blade.php","/src/resources/views/layouts/appd.blade.php","/src/resources/views/layouts/appd.blade.php.old","/src/resources/views/layouts/guest.blade.php","/src/resources/views/layouts/navbar.blade.php","/src/resources/views/layouts/navigation.blade.php","/src/resources/views/logs/index.blade.php","/src/resources/views/mails/maintenance-report.blade.php","/src/resources/views/menu-settings/_card.blade.php","/src/resources/views/menu-settings.blade.php","/src/resources/views/menu-settings.blade.php.old","/src/resources/views/my-redmine/board.blade.php","/src/resources/views/my-redmine/issue.blade.php","/src/resources/views/my-redmine/project.blade.php","/src/resources/views/overtime-requests/admin-index.blade.php","/src/resources/views/overtime-requests/create.blade.php","/src/resources/views/overtime-requests/department-index.blade.php","/src/resources/views/overtime-requests/index.blade.php","/src/resources/views/overtime-requests/show.blade.php","/src/resources/views/overtime-requests/supervisor-index.blade.php","/src/resources/views/overtime-requests/team-index.blade.php","/src/resources/views/partials/alert.blade.php","/src/resources/views/partials/dashboard/admin-functions.blade.php","/src/resources/views/partials/dashboard/cve-feed.blade.php","/src/resources/views/partials/dashboard/supervisor-functions.blade.php","/src/resources/views/partials/dashboard/user-functions.blade.php","/src/resources/views/permissions/edit.blade.php","/src/resources/views/permissions/index.blade.php","/src/resources/views/profile/edit.blade.php","/src/resources/views/profile/partials/delete-user-form.blade.php","/src/resources/views/profile/partials/update-password-form.blade.php","/src/resources/views/profile/partials/update-profile-information-form.blade.php","/src/resources/views/projects/_nav.blade.php","/src/resources/views/projects/_project_row.blade.php","/src/resources/views/projects/calendar/index.blade.php","/src/resources/views/projects/create.blade.php","/src/resources/views/projects/docs/_card.blade.php","/src/resources/views/projects/docs/_doc_list.blade.php","/src/resources/views/projects/docs/create.blade.php","/src/resources/views/projects/docs/edit.blade.php","/src/resources/views/projects/docs/index.blade.php","/src/resources/views/projects/docs/logs.blade.php","/src/resources/views/projects/docs/show.blade.php","/src/resources/views/projects/edit.blade.php","/src/resources/views/projects/files/index.blade.php","/src/resources/views/projects/gantt/index.blade.php","/src/resources/views/projects/gitlab/index.blade.php","/src/resources/views/projects/index.blade.php","/src/resources/views/projects/issues/create.blade.php","/src/resources/views/projects/issues/edit.blade.php","/src/resources/views/projects/issues/index.blade.php","/src/resources/views/projects/issues/show.blade.php","/src/resources/views/projects/list.blade.php","/src/resources/views/projects/list.blade.php.old","/src/resources/views/projects/manage/index.blade.php","/src/resources/views/projects/manage/show.blade.php","/src/resources/views/projects/members/index.blade.php","/src/resources/views/projects/reassign-client.blade.php","/src/resources/views/projects/roadmap/index.blade.php","/src/resources/views/projects/roadmap/version-form.blade.php","/src/resources/views/projects/show.blade.php","/src/resources/views/projects/time/index.blade.php","/src/resources/views/push/admin.blade.php","/src/resources/views/redmine-projects/create.blade.php","/src/resources/views/redmine-projects/edit.blade.php","/src/resources/views/redmine-projects/index.blade.php","/src/resources/views/redmine-projects/show.blade.php","/src/resources/views/redmine-requests/admin.blade.php","/src/resources/views/redmine-requests/create.blade.php","/src/resources/views/redmine-requests/index.blade.php","/src/resources/views/redmine-requests/show.blade.php","/src/resources/views/redmine-requests/supervisor.blade.php","/src/resources/views/repair-requests/index.blade.php","/src/resources/views/scans/bind.blade.php","/src/resources/views/scans/create.blade.php","/src/resources/views/scans/index.blade.php","/src/resources/views/scans/show.blade.php","/src/resources/views/service-center.blade.php","/src/resources/views/settings/chat-app.blade.php","/src/resources/views/settings/chat-channels.blade.php","/src/resources/views/settings/maintenance-reports.blade.php","/src/resources/views/settings/projects.blade.php","/src/resources/views/ssl/_navbar.blade.php","/src/resources/views/ssl/ssl_csr.blade.php","/src/resources/views/ssl/ssl_csr_list.blade.php","/src/resources/views/ssl/ssl_csr_list.blade.php.bak","/src/resources/views/ssl/ssl_csr_result.blade.php","/src/resources/views/ssl/ssl_csr_verify.blade.php","/src/resources/views/ssl/ssl_csr_verify_result.blade.php","/src/resources/views/stats/.vpn.blade.php.swp","/src/resources/views/stats/_chart_tab.blade.php","/src/resources/views/stats/device_in.blade.php","/src/resources/views/stats/device_out.blade.php","/src/resources/views/stats/index.blade.php","/src/resources/views/stats/repair.blade.php","/src/resources/views/stats/vpn.blade.php","/src/resources/views/test-reports/_form.blade.php","/src/resources/views/test-reports/create.blade.php","/src/resources/views/test-reports/edit.blade.php","/src/resources/views/test-reports/index.blade.php","/src/resources/views/test-reports/report-pdf.blade.php","/src/resources/views/test-reports/show.blade.php","/src/resources/views/users/create.blade.php","/src/resources/views/users/edit.blade.php","/src/resources/views/users/index.blade.php","/src/resources/views/vpn-accounts/create.blade.php","/src/resources/views/vpn-accounts/create.blade.php.old","/src/resources/views/vpn-accounts/edit.blade.php","/src/resources/views/vpn-accounts/index.blade.php","/src/resources/views/vpn-accounts/index.blade.php.old","/src/resources/views/vpn-requests/admin-index.blade.php","/src/resources/views/vpn-requests/create.blade.php","/src/resources/views/vpn-requests/create.blade.php.old","/src/resources/views/vpn-requests/docx-template.blade.php","/src/resources/views/vpn-requests/index.blade.php","/src/resources/views/vpn-requests/show.blade.php","/src/resources/views/vpn-requests/supervisor-index.blade.php","/src/resources/views/vuln_scan/create.blade.php","/src/resources/views/vuln_scan/engine.blade.php","/src/resources/views/vuln_scan/index.blade.php","/src/resources/views/vuln_scan/pdf.blade.php","/src/resources/views/vuln_scan/show.blade.php","/src/resources/views/welcome.blade.php","/src/resources/views/work-board/index.blade.php","/src/routes/api.php","/src/routes/auth.php","/src/routes/console.php","/src/routes/web.php","/src/routes/web.php.old","/src/scripts/html2pdf.py","/src/semgrep_out.json","/src/storage/app/.gitignore","/src/storage/app/fix-docx-tables.py","/src/storage/app/gcb/apache_gcb.json","/src/storage/app/gcb/gcb_check_apache.py","/src/storage/app/gcb/gcb_check_ubuntu.py","/src/storage/app/gcb/ubuntu_gcb.json","/src/storage/app/google-service.json","/src/storage/app/k6-report/script.js","/src/storage/app/k6-report/src/cli.cjs","/src/storage/app/nuclei_scan_1.log","/src/storage/app/nuclei_scan_5.log","/src/storage/app/private/.gitignore","/src/storage/app/private/gcb-reports/gcb_ubuntu_20260316_175806.json","/src/storage/app/private/specs/2jIdNCO6FdtehPRMf8PJbATeP0AOIW5xXQvh1Xgo.pdf","/src/storage/app/private/specs/TILjxEIz4WQxJntyhvVfT85rHnV4N5Vh7hBX9dQT.pdf","/src/storage/app/private/specs/gQD7RLADyqXiEZC6nMiw7GiHN3qVK6YWGKLkXJXi.pdf","/src/storage/app/private/specs/p1UrYsjrHhbsd1lPWx9aXX6Hj9oTdGl2tENzF1te.pdf","/src/storage/app/public/.gitignore","/src/storage/app/public/handover-attachments/16/Sv99y8jFfCv3ieLFmBsZ2sVuSOkJasMBAf3OkFwN.jpg","/src/storage/app/public/handover-attachments/16/aT02W8yfyLi4TJc7Rhsz6xRxBEsnL4FlQE4vox80.jpg","/src/storage/app/public/k6/20_20250723_161813/metadata-20.json","/src/storage/app/public/k6/20_20250723_161813/report.html","/src/storage/app/public/k6/20_20250723_161813/result-20.json","/src/storage/app/public/k6/school_688092bd02dfb_20250723_154357/metadata-10.json","/src/storage/app/public/k6/school_688092bd02dfb_20250723_154357/metadata-20.json","/src/storage/app/public/k6/school_688092bd02dfb_20250723_154357/report.html","/src/storage/app/public/k6/school_688092bd02dfb_20250723_154357/result-10.json","/src/storage/app/public/k6/school_688092bd02dfb_20250723_154357/result-20.json","/src/storage/app/public/k6/school_68809b1bb16c8_20250723_161939/metadata-30.json","/src/storage/app/public/k6/school_68809b1bb16c8_20250723_161939/report.html","/src/storage/app/public/k6/school_68809b1bb16c8_20250723_161939/result-30.json","/src/storage/app/public/k6/school_68809ba7cc035_20250723_162159/metadata-1.json","/src/storage/app/public/k6/school_68809ba7cc035_20250723_162159/metadata-2.json","/src/storage/app/public/k6/school_68809ba7cc035_20250723_162159/report.html","/src/storage/app/public/k6/school_68809ba7cc035_20250723_162159/result-1.json","/src/storage/app/public/k6/school_68809ba7cc035_20250723_162159/result-2.json","/src/storage/app/public/k6/school_6880b79ebf277_20250723_182118/metadata-100.json","/src/storage/app/public/k6/school_6880b79ebf277_20250723_182118/metadata-50.json","/src/storage/app/public/k6/school_6880b79ebf277_20250723_182118/report.html","/src/storage/app/public/k6/school_6880b79ebf277_20250723_182118/result-100.json","/src/storage/app/public/k6/school_6880b79ebf277_20250723_182118/result-50.json","/src/storage/app/public/k6/school_688c2d1a6a610_20250801_105730/metadata-10.json","/src/storage/app/public/k6/school_688c2d1a6a610_20250801_105730/metadata-20.json","/src/storage/app/public/k6/school_688c2d1a6a610_20250801_105730/report.html","/src/storage/app/public/k6/school_688c2d1a6a610_20250801_105730/result-10.json","/src/storage/app/public/k6/school_688c2d1a6a610_20250801_105730/result-20.json","/src/storage/app/public/projects/1/OkiCZJJbVenEJRwrqAKc23YjBeVSoqNfKBZzbypy.docx","/src/storage/app/public/projects/107/docs/1863_ntua-app-firebase-adminsdk-8d87j-60293aae67.json","/src/storage/app/public/projects/109/docs/1864_nfuapp-firebase-adminsdk-yq58a-d14bc39fef.json","/src/storage/app/public/projects/114/docs/1849_MSSQL 使用 DBLIB.pdf","/src/storage/app/public/projects/118/docs/1879_Laravel 連線 MSSQL (dblib) v1.pdf","/src/storage/app/public/projects/127/docs/1876_building-security-233e5-firebase-adminsdk-mes3l-62ccbf18fb.json","/src/storage/app/public/projects/153/docs/1877_宜蘭教育局專案_LAMP_AI_交付後驗收設定_20240816 (1).pdf","/src/storage/app/public/projects/160/files/宜蘭發稿平台 - 開發備忘錄 (副本).odt","/src/storage/app/public/projects/173/docs/1847_API相關說明.pdf","/src/storage/app/public/projects/173/docs/1848_HK_Oauth.js","/src/storage/app/public/projects/173/docs/1872_hkapp-df6f3-firebase-adminsdk-8an6i-4d6b039a05.json","/src/storage/app/public/projects/173/docs/1884_AuthKey_HHGK68M5JZ.p8","/src/storage/app/public/projects/173/docs/1885_magicsquare.keystore","/src/storage/app/public/projects/173/docs/1889_hkapp-df6f3-firebase-adminsdk-8an6i-4d6b039a05.json","/src/storage/app/public/projects/174/docs/1886_AuthKey_W3XDP5L96Z.p8","/src/storage/app/public/projects/174/docs/1887_com.toeicexam.app.chunshin.key.jks","/src/storage/app/public/projects/174/docs/1888_tw-steps-toeic-debb0-firebase-adminsdk-fbsvc-b9bd515783.json","/src/storage/app/public/projects/182/docs/1859_Github Account Transfer.pdf","/src/storage/app/public/projects/182/docs/1860_github-recovery-codes.ru8tp6.steps.txt","/src/storage/app/public/projects/190/docs/1890_SoundBox API V3.4 zh.pdf","/src/storage/app/public/projects/197/docs/1861_service-account.scu.json","/src/storage/app/public/projects/215/docs/1865_GoogleService-Info.dgm.plist","/src/storage/app/public/projects/215/docs/1866_google-services.dgm.json","/src/storage/app/public/projects/215/docs/1878_dgm-platform-apps-firebase-adminsdk-so6bb-0e6a629944.json","/src/storage/app/public/projects/234/docs/1868_chihleeapp-b1c85-firebase-adminsdk-r97y2-07ced48666.json","/src/storage/app/public/projects/256/files/Centos7安裝GlobalProtect-Portal and Connect to SSLVPN.docx","/src/storage/app/public/projects/271/files/KUROGO_ST.xls","/src/storage/app/public/projects/271/files/KUROGO_TDdata(增加欄位).xls","/src/storage/app/public/projects/271/files/KUROGO_TR.xls","/src/storage/app/public/projects/286/docs/1867_lhuapp-161805-firebase-adminsdk-09l0j-63a0db1cfd.json","/src/storage/app/public/projects/286/docs/1881_antennaLhu.jks","/src/storage/app/public/projects/59/hJh5vrlmR7GkI25CibGxTSmGYCiM6gX5ikymddKX.pdf","/src/storage/app/public/projects/60/qzpeNCQv2P2UuvIyXRms4fN4x9ax5Zo4jduYwcj7.txt","/src/storage/app/public/projects/60/wBf8tz97pPGbc0KEdWzWoZSpk63pbKt5CfK25G3g.pdf","/src/storage/app/public/projects/73/docs/1850_nutc.odt","/src/storage/app/public/projects/82/docs/1869_國教署文心機房連線步驟.pdf","/src/storage/app/public/projects/82/docs/1875_SFTP用戶使用手冊v1.3.pdf","/src/storage/app/public/projects/82/docs/2165_gitlab-recovery-codes (2).txt","/src/storage/app/public/projects/86/docs/2090_google-services.json","/src/storage/app/public/projects/86/docs/2091_nccu.jks","/src/storage/app/public/projects/86/docs/2142_政大正式機.jpg","/src/storage/app/public/projects/86/docs/2143_政大測試機.jpg","/src/storage/app/public/projects/86/docs/2146_政大正式機.jpg","/src/storage/app/public/projects/86/docs/2147_政大測試機.jpg","/src/storage/app/public/projects/86/docs/2149_政大-身份驗證時序圖.jpg","/src/storage/app/public/projects/86/docs/2150_政大-代登入流程時序圖.jpg","/src/storage/app/public/projects/86/docs/2152_政大-簽到退時序圖.jpg","/src/storage/app/public/projects/90/docs/1874_nouapp-9abbd-firebase-adminsdk-801c2-b3fd1fe972.json","/src/storage/app/public/projects/90/docs/2078_AuthKey_DB8V78V3G4.p8","/src/storage/app/public/projects/95/docs/1862_tnua-app-firebase-adminsdk-tjumd-1b07b96db4.json","/src/storage/app/public/reports/IaGqO045P5lR3j4LENK954BmdfgdOLX73dYpJtYR.pdf","/src/storage/app/public/reports/VM4vQ49COcae552ZrU4SczsJJOwfxc0HB1iAY0m8.pdf","/src/storage/app/public/reports/lE7ZBoyO9ZJZK81K2P4eUqy1qaZTGrhROJ3fjY7A.pdf","/src/storage/app/reference.docx","/src/storage/app/reports/1.html","/src/storage/app/reports/12.html","/src/storage/app/reports/1_report.html","/src/storage/app/reports/2.html","/src/storage/app/reports/2_report.html","/src/storage/app/reports/4.html","/src/storage/app/reports/5.html","/src/storage/app/reports/k6_test.html","/src/storage/app/reports/k6_test.pdf","/src/storage/app/reports/k6_test5.html","/src/storage/app/reports/k6_test5.pdf","/src/storage/app/ssl-csr/67f886d87b2ba.csr","/src/storage/app/ssl-csr/67f886d87b2ba.key","/src/storage/app/ssl-csr/67f887087bc9e.csr","/src/storage/app/ssl-csr/67f887087bc9e.key","/src/storage/app/ssl-csr/67f889d6b6b5b.csr","/src/storage/app/ssl-csr/67f889d6b6b5b.key","/src/storage/app/ssl-csr/67f8e14eb3536.csr","/src/storage/app/ssl-csr/67f8e14eb3536.key","/src/storage/app/ssl-csr/67f8e59d09f56.csr","/src/storage/app/ssl-csr/67f8e59d09f56.key","/src/storage/app/ssl-csr/67f8e5c8eb5d6.csr","/src/storage/app/ssl-csr/67f8e5c8eb5d6.key","/src/storage/app/ssl-csr/67fcb0a643818.csr","/src/storage/app/ssl-csr/67fcb0a643818.key","/src/storage/app/ssl-csr/67fcb0c8c5683.csr","/src/storage/app/ssl-csr/67fcb0c8c5683.key","/src/storage/app/ssl-csr/67fcb0ef9c252.csr","/src/storage/app/ssl-csr/67fcb0ef9c252.key","/src/storage/app/ssl-csr/67fcb0f6cc7ea.csr","/src/storage/app/ssl-csr/67fcb0f6cc7ea.key","/src/storage/app/ssl-csr/67fcb100901f9.csr","/src/storage/app/ssl-csr/67fcb100901f9.key","/src/storage/app/ssl-csr/67fcb103def18.csr","/src/storage/app/ssl-csr/67fcb103def18.key","/src/storage/app/ssl-csr/6805b0faa3135.csr","/src/storage/app/ssl-csr/6805b0faa3135.key","/src/storage/app/ssl-csr/6805b10025ca9.csr","/src/storage/app/ssl-csr/6805b10025ca9.key","/src/storage/app/ssl-csr/6805b10e46023.csr","/src/storage/app/ssl-csr/6805b10e46023.key","/src/storage/app/ssl-csr/6805b110d4a11.csr","/src/storage/app/ssl-csr/6805b110d4a11.key","/src/storage/app/ssl-csr/6805e623c7153.csr","/src/storage/app/ssl-csr/6805e623c7153.key","/src/storage/app/ssl-csr/6805e626ecb33.csr","/src/storage/app/ssl-csr/6805e626ecb33.key","/src/storage/app/ssl-csr/680b572cd1491.csr","/src/storage/app/ssl-csr/680b572cd1491.key","/src/storage/app/ssl-csr/6811902814abc.csr","/src/storage/app/ssl-csr/6811902814abc.key","/src/storage/app/ssl-csr/6811902c7cba4.csr","/src/storage/app/ssl-csr/6811902c7cba4.key","/src/storage/app/ssl-csr/6862474bb8911.csr","/src/storage/app/ssl-csr/6862474bb8911.key","/src/storage/app/templates/.gitignore","/src/storage/app/templates/ISMS-2-009-02-A.docx","/src/storage/app/templates/ISMS-2-009-02-B.docx","/src/storage/app/templates/gitlab_request_template.docx","/src/storage/app/templates/redmine_request_template.docx","/src/storage/app/templates/vpn_request_template.docx","/src/storage/app/vuln_scan_10.log","/src/storage/app/vuln_scan_11.log","/src/storage/app/vuln_scan_2.log","/src/storage/app/vuln_scan_3.log","/src/storage/app/vuln_scan_4.log","/src/storage/app/vuln_scan_6.log","/src/storage/app/vuln_scan_7.log","/src/storage/app/vuln_scan_8.log","/src/storage/app/vuln_scan_9.log","/src/storage/fonts/DejaVuSans-Bold.ufm.json","/src/storage/fonts/Helvetica-Bold.afm.json","/src/storage/fonts/installed-fonts.json","/src/storage/framework/.gitignore","/src/storage/framework/cache/.gitignore","/src/storage/framework/cache/data/.gitignore","/src/storage/framework/sessions/.gitignore","/src/storage/framework/testing/.gitignore","/src/storage/framework/views/.gitignore","/src/storage/framework/views/03e4411bb5cd45191f32e82063f2b244.php","/src/storage/framework/views/064959ab8647b3e1e0373ef607ad48b1.php","/src/storage/framework/views/1271d3037b6d711575dda5ed04e4d207.php","/src/storage/framework/views/281475e6f809fb93725d8e48c30a0d5b.php","/src/storage/framework/views/2e1c0d7ca092ed80308fc353f4f18769.php","/src/storage/framework/views/3756143cf41bad082f7cb43b3fab8c8c.php","/src/storage/framework/views/3dca0ebcf2f311d6eff62d8dea5ff0cd.php","/src/storage/framework/views/3f30876eede0e229e7e419a46911ecff.php","/src/storage/framework/views/4063ec56829fa67516f6cabc3de87220.php","/src/storage/framework/views/4408fbcea35a1aa95d10fb4a681eab08.php","/src/storage/framework/views/46089f48abd81948ac1e8ce1507b11ee.php","/src/storage/framework/views/46b92496561c5feafe9831a4612a6791.php","/src/storage/framework/views/4c0328cc0987d023398037f165e90c84.php","/src/storage/framework/views/66d01dea2dc1397fef76743b18b03b15.php","/src/storage/framework/views/6a4e2051e1ff3207bca30f2aac0fdf65.php","/src/storage/framework/views/97c46cea54599195d6183e04e2b01d6a.php","/src/storage/framework/views/9b35765b2c99153dd98e8a16188e8823.php","/src/storage/framework/views/9f1edf6964c27a6b930cf6824bed334b.php","/src/storage/framework/views/9fc7e03b44f026e76d08b43deab55d35.php","/src/storage/framework/views/a4bcba114de6cf9a1bbed8f7532c83e3.php","/src/storage/framework/views/a50a54d385d1af4b0a2301e46997c4f3.php","/src/storage/framework/views/ad4d611c83cfbfd37d4ab83f4359c079.php","/src/storage/framework/views/afc151c280b179f7c791d9e97d827116.php","/src/storage/framework/views/b054ea774a1badbbe6d066364799d451.php","/src/storage/framework/views/b3d9aed49a32e1464092f7f22923f4b3.php","/src/storage/framework/views/bc9a67051bc493879e9d0b93e2645f81.php","/src/storage/framework/views/ca5384bf1313dcd2baef9f207603acf0.php","/src/storage/framework/views/cab7ee56c2bc81a25d0a164d82c01c59.php","/src/storage/framework/views/d0bb2861d2d83c780c4bf56a1f75dc1f.php","/src/storage/framework/views/dc8c4d8cdfed1395221d0344de6dd069.php","/src/storage/framework/views/e4cbf667f57b76c5fb1ac4d24a4783c3.php","/src/storage/framework/views/f264e986c5de4f13e93cb3d46ac49379.php","/src/storage/logs/.gitignore","/src/storage/logs/queue.log","/src/tailwind.config.js","/src/trivy_out.json","/src/vite.config.js","/src/vpn-queue.conf"]},"time":{"rules":[],"rules_parse_time":0.2983129024505615,"profiling_times":{"config_time":1.0852210521697998,"core_time":3.9288430213928223,"ignores_time":0.0014133453369140625,"total_time":5.023620128631592},"parsing_time":{"total_time":0.0,"per_file_time":{"mean":0.0,"std_dev":0.0},"very_slow_stats":{"time_ratio":0.0,"count_ratio":0.0},"very_slow_files":[]},"scanning_time":{"total_time":17.683430194854736,"per_file_time":{"mean":0.006080959489289803,"std_dev":0.0009929411134512942},"very_slow_stats":{"time_ratio":0.0,"count_ratio":0.0},"very_slow_files":[]},"matching_time":{"total_time":0.0,"per_file_and_rule_time":{"mean":0.0,"std_dev":0.0},"very_slow_stats":{"time_ratio":0.0,"count_ratio":0.0},"very_slow_rules_on_files":[]},"tainting_time":{"total_time":0.0,"per_def_and_rule_time":{"mean":0.0,"std_dev":0.0},"very_slow_stats":{"time_ratio":0.0,"count_ratio":0.0},"very_slow_rules_on_defs":[]},"fixpoint_timeouts":[],"prefiltering":{"project_level_time":0.0,"file_level_time":0.0,"rules_with_project_prefilters_ratio":0.0,"rules_with_file_prefilters_ratio":0.9878413022375986,"rules_selected_ratio":0.043445254747741247,"rules_matched_ratio":0.043445254747741247},"targets":[],"total_bytes":0,"max_memory_bytes":1459304320},"engine_requested":"OSS","skipped_rules":[],"profiling_results":[]}