503
Critical
86
High
107
Medium
8
Low
704
Total
critical
81
mcp/create-server.mjs::mountKnowtationMcp
critical
81
hub/gateway/mcp-hosted-server.mjs::createHostedMcpServer
critical
80
cli/index.mjs::main
critical
78
web/hub/hub.js::attachNoteDetailReadActions
critical
78
test/section-source-hosted-implementation-spec.test.mjs::assertHostedSectionSourceAbsent
critical
78
test/hub-note-outline-self-hosted-route.test.mjs::routeSource
critical
78
web/hub/hub.js::renderSectionSourceData
critical
76
test/companion-loopback-guard-performance.test.mjs::base
critical
76
test/companion-loopback-guard-data-integrity.test.mjs::base
critical
76
test/companion-loopback-guard-security.test.mjs::base
critical
76
lib/model-runtime-lane.mjs::enforceConsentPolicy
critical
76
lib/model-runtime-lane.mjs::selectLane
critical
76
test/companion-loopback-guard-e2e.test.mjs::listenerDecide
critical
76
test/companion-loopback-guard-integration.test.mjs::step
critical
76
lib/companion-token-custody.mjs::serializeMeta
critical
76
lib/companion-token-custody.mjs::decide
critical
76
lib/companion-token-custody.mjs::storeLoopbackToken
critical
76
lib/companion-spawn-adapter.mjs::requireAbsolutePath
critical
76
lib/companion-token-custody.mjs::clearLoopbackToken
critical
76
lib/companion-token-custody.mjs::createTokenCustody
critical
76
lib/companion-token-custody.mjs::loadSession
critical
76
lib/companion-token-custody.mjs::rotateLoopbackToken
critical
76
lib/companion-token-custody.mjs::updateAccessToken
critical
76
test/section-source-hosted-implementation-spec.test.mjs::connectPair
critical
76
test/section-source-hosted-implementation-spec.test.mjs::hostedRuntimeSource
critical
76
lib/model-runtime-lane.mjs::isManagedLane
critical
76
test/section-source-hosted-implementation-spec.test.mjs::installFetchMock
critical
76
test/section-source-policy.test.mjs::readRepoFile
critical
76
test/section-source-hosted-implementation-spec.test.mjs::makeCtx
critical
76
test/companion-loopback-guard-integration.test.mjs::req
critical
76
lib/companion-spawn-adapter.mjs::kill
critical
76
lib/companion-spawn-adapter.mjs::spawn
critical
76
test/section-source-hosted-implementation-spec.test.mjs::restore
critical
76
hub/lib/refresh-token-core.mjs::sanitizeMeta
critical
76
test/mcp-section-source.test.mjs::readRepoFile
critical
76
lib/companion-spawn-adapter.mjs::healthCheck
critical
76
test/mcp-section-source.test.mjs::parseToolResult
critical
76
lib/companion-spawn-adapter.mjs::reclaimStaleRuntime
critical
76
test/auth-session.test.mjs::cookieOptions
critical
76
lib/companion-token-custody.mjs::buildSessionMeta
critical
76
test/mcp-section-source.test.mjs::sectionSourceToolSource
critical
76
lib/companion-token-custody.mjs::clearSession
critical
76
test/gateway-refresh-token-store.test.mjs::createStubBlobStore
critical
76
lib/companion-token-custody.mjs::getLoopbackToken
critical
76
lib/companion-token-custody.mjs::requireAdapter
critical
76
lib/companion-token-custody.mjs::requireSecret
critical
76
test/gateway-session-introspection.test.mjs::validPayload
critical
76
test/refresh-tokens-store.test.mjs::storeFile
critical
76
hub/auth-session.mjs::refreshCookieOptions
critical
76
hub/gateway/refresh-token-store.mjs::refreshFilePath
critical
76
hub/gateway/refresh-token-store.mjs::revokeAllRefreshTokensForSub
critical
76
hub/gateway/refresh-token-store.mjs::revokeRefreshToken
critical
76
hub/gateway/refresh-token-store.mjs::rotateRefreshToken
critical
76
hub/gateway/refresh-token-store.mjs::saveRefreshRecords
critical
76
hub/gateway/refresh-token-store.mjs::writeToBlob
critical
76
hub/gateway/refresh-token-store.mjs::writeToFile
critical
76
hub/lib/refresh-token-core.mjs::cloneRecords
critical
76
hub/lib/refresh-token-core.mjs::generateRefreshToken
critical
76
hub/lib/refresh-token-core.mjs::hashSecret
critical
76
hub/lib/refresh-token-core.mjs::issueToken
critical
76
hub/lib/refresh-token-core.mjs::parseToken
critical
76
hub/lib/refresh-token-core.mjs::pruneExpired
critical
76
lib/companion-spawn-adapter.mjs::createCompanionSpawnAdapter
critical
76
hub/lib/refresh-token-core.mjs::safeEqualHashes
critical
76
hub/lib/refresh-token-core.mjs::rotateToken
critical
76
test/section-source-hosted-implementation-spec.test.mjs::readRepoFile
critical
76
hub/gateway/native-oauth-provider.mjs::_nativeRefreshError
critical
76
hub/refresh-tokens.mjs::filePathFor
critical
76
hub/refresh-tokens.mjs::pruneRefreshTokens
critical
76
hub/refresh-tokens.mjs::readRefreshTokens
critical
76
hub/refresh-tokens.mjs::revokeAllRefreshTokensForSub
critical
76
hub/refresh-tokens.mjs::revokeRefreshToken
critical
76
hub/refresh-tokens.mjs::rotateRefreshToken
critical
76
hub/refresh-tokens.mjs::writeRefreshTokens
critical
76
test/auth-refresh-wiring.test.mjs::load
critical
76
test/auth-session.test.mjs::asyncSigner
critical
76
test/auth-session.test.mjs::clearCookie
critical
76
test/auth-session.test.mjs::cookie
critical
76
lib/companion-inference-listener.mjs::port
critical
76
test/auth-session.test.mjs::fileStore
critical
76
test/auth-session.test.mjs::issueAccessToken
critical
76
test/auth-session.test.mjs::json
critical
76
test/auth-session.test.mjs::mockRes
critical
76
test/auth-session.test.mjs::set
critical
76
test/auth-session.test.mjs::status
critical
76
test/gateway-auth-refresh-wiring.test.mjs::load
critical
76
lib/companion-loopback-guard.mjs::constantTimeStringEqual
critical
76
test/gateway-refresh-token-store.test.mjs::get
critical
76
test/gateway-refresh-token-store.test.mjs::setJSON
critical
76
test/gateway-session-introspection.test.mjs::adminPayload
critical
76
test/gateway-session-introspection.test.mjs::createGateway
critical
76
test/gateway-session-introspection.test.mjs::get
critical
76
test/gateway-session-introspection.test.mjs::makeJwt
critical
76
test/gateway-session-introspection.test.mjs::startServer
critical
76
lib/companion-oauth-pkce.mjs::buildRefreshRequest
critical
76
test/refresh-token-core.test.mjs::buildLargeStore
critical
76
lib/companion-oauth-pkce.mjs::createNonce
critical
76
hub/gateway/server.mjs::decodeVerifiedToken
critical
76
hub/gateway/server.mjs::issueAccessTokenForSub
critical
76
hub/gateway/server.mjs::issueRefreshCookieSafe
critical
76
hub/gateway/server.mjs::refreshCookiePolicy
critical
76
hub/gateway/server.mjs::scopesForRole
critical
76
hub/server.mjs::issueSession
critical
76
hub/server.mjs::refreshCookiePolicy
critical
76
hub/server.mjs::handleAuthCallback
critical
76
netlify/functions/gateway.mjs::handler
critical
76
web/hub/hub.js::refreshAccessToken
critical
76
web/hub/hub.js::api
critical
76
test/hub-integration-guides.test.mjs::onOpen
critical
76
test/hub-integration-guides.test.mjs::querySelectorAll
critical
76
web/hub/hub-integration-guides.mjs::escapeHtml
critical
76
web/hub/hub-integration-guides.mjs::getIntegrationGuide
critical
76
web/hub/hub-integration-guides.mjs::listIntegrationGuideIds
critical
76
web/hub/hub-integration-guides.mjs::renderIntegrationGuideHtml
critical
76
web/hub/hub-integration-guides.mjs::wireIntegrationTiles
critical
76
web/hub/hub.js::bindIntegrationGuideModalControlsOnce
critical
76
web/hub/hub.js::closeIntegGuideModal
critical
76
web/hub/hub.js::openIntegGuideModal
critical
76
web/hub/hub.js::scheduleIntegrationGuidesInit
critical
76
web/hub/hub.js::openImportModal
critical
76
web/hub/hub.js::openSettingsIntegrationsTab
critical
76
hub/gateway/native-as-store.mjs::_nativeCodePath
critical
76
hub/gateway/native-as-store.mjs::_normalizeCodes
critical
76
hub/gateway/native-as-store.mjs::_pruneExpired
critical
76
hub/gateway/native-as-store.mjs::_readCodes
critical
76
hub/gateway/native-as-store.mjs::_writeCodes
critical
76
hub/gateway/native-as-store.mjs::savePendingCode
critical
76
hub/gateway/native-as-store.mjs::pruneExpiredCodes
critical
76
hub/lib/refresh-token-core.mjs::revokeFamily
critical
76
hub/gateway/native-as-store.mjs::consumePendingCode
critical
76
hub/gateway/native-oauth-provider.mjs::NativeClientStore
critical
76
hub/gateway/native-oauth-provider.mjs::NativeClientStore.constructor
critical
76
hub/gateway/native-oauth-provider.mjs::NativeClientStore.getClient
critical
76
hub/gateway/native-oauth-provider.mjs::NativeClientStore.registerClient
critical
76
hub/gateway/native-as-store.mjs::bindUserToCode
critical
76
hub/gateway/native-oauth-provider.mjs::_sha256Base64url
critical
76
hub/gateway/native-oauth-provider.mjs::applyScopeCeiling
critical
76
hub/gateway/native-oauth-provider.mjs::completeNativeAuthorization
critical
76
hub/gateway/native-oauth-provider.mjs::createNativeOAuthRouter
critical
76
hub/gateway/native-oauth-provider.mjs::isLoopbackUri
critical
76
lib/companion-artifact-writer.mjs::_safeProvenanceFields
critical
76
lib/companion-artifact-writer.mjs::_scopeForArtifact
critical
76
lib/companion-artifact-writer.mjs::_storeArtifact
critical
76
lib/companion-artifact-writer.mjs::checkReEnrichmentEligibility
critical
76
lib/companion-artifact-writer.mjs::createDerivedArtifactWriter
critical
76
lib/companion-artifact-writer.mjs::deleteArtifacts
critical
76
lib/companion-artifact-writer.mjs::write
critical
76
lib/companion-client-encryptor.mjs::createClientEncryptor
critical
76
lib/companion-client-encryptor.mjs::encrypt
critical
76
lib/companion-client-encryptor.mjs::isAvailable
critical
76
lib/companion-download-adapter.mjs::createCompanionDownloadAdapter
critical
76
lib/companion-download-adapter.mjs::download
critical
76
lib/companion-download-adapter.mjs::requireHttpsDownloadUrl
critical
76
lib/companion-inference-listener.mjs::allowedHosts
critical
76
lib/companion-inference-listener.mjs::buildAllowedHosts
critical
76
lib/companion-inference-listener.mjs::close
critical
76
lib/companion-inference-listener.mjs::createCompanionInferenceListener
critical
76
lib/companion-inference-listener.mjs::extractLoopbackBearerToken
critical
76
hub/lib/refresh-token-core.mjs::revokeAllForSub
critical
76
lib/companion-inference-listener.mjs::start
critical
76
lib/companion-keychain-adapter.mjs::accountFile
critical
76
lib/companion-keychain-adapter.mjs::createCompanionKeychainAdapter
critical
76
lib/companion-keychain-adapter.mjs::createLinuxSecretServiceBackend
critical
76
lib/companion-keychain-adapter.mjs::createMacOSKeychainBackend
critical
76
lib/companion-keychain-adapter.mjs::createWindowsDpapiBackend
critical
76
lib/companion-keychain-adapter.mjs::delete
critical
76
lib/companion-keychain-adapter.mjs::dpapiProtect
critical
76
lib/companion-keychain-adapter.mjs::dpapiUnprotect
critical
76
lib/companion-keychain-adapter.mjs::get
critical
76
lib/companion-keychain-adapter.mjs::requireKeychainSecret
critical
76
lib/companion-keychain-adapter.mjs::requireKnownKeychainAccount
critical
76
lib/companion-keychain-adapter.mjs::run
critical
76
lib/companion-keychain-adapter.mjs::selectKeychainBackend
critical
76
lib/companion-keychain-adapter.mjs::set
critical
76
lib/companion-spawn-adapter.mjs::buildRuntimeArgv
critical
76
lib/companion-loopback-guard.mjs::createLoopbackRateState
critical
76
lib/companion-loopback-guard.mjs::deny
critical
76
lib/companion-loopback-guard.mjs::evaluateRateLimit
critical
76
lib/companion-loopback-guard.mjs::getHeader
critical
76
lib/companion-loopback-guard.mjs::isLoopbackHost
critical
76
lib/companion-loopback-guard.mjs::parseHostHeader
critical
76
lib/companion-loopback-guard.mjs::recordLoopbackRequest
critical
76
lib/companion-loopback-guard.mjs::shouldCountTowardRateLimit
critical
76
lib/companion-loopback-guard.mjs::verifyLoopbackRequest
critical
76
lib/companion-oauth-flow.mjs::close
critical
76
lib/companion-oauth-flow.mjs::createOAuthRedirectAttempt
critical
76
lib/companion-oauth-flow.mjs::openSystemBrowser
critical
76
lib/companion-oauth-flow.mjs::registerNativeClient
critical
76
lib/companion-oauth-flow.mjs::runCompanionOAuthFlow
critical
76
lib/companion-oauth-pkce.mjs::buildAuthorizationUrl
critical
76
lib/companion-spawn-adapter.mjs::createScrubbedRuntimeEnv
critical
76
lib/companion-oauth-pkce.mjs::buildTokenRequest
critical
76
lib/companion-oauth-pkce.mjs::computeCodeChallenge
critical
76
lib/companion-oauth-pkce.mjs::constantTimeEqual
critical
76
lib/companion-tier-resolver.mjs::resolveTier
critical
76
lib/companion-oauth-pkce.mjs::createOAuthState
critical
76
lib/companion-oauth-pkce.mjs::createPkcePair
critical
76
lib/companion-oauth-pkce.mjs::validateAuthorizationResponse
critical
76
lib/companion-oauth-pkce.mjs::validateRedirectUri
critical
76
lib/companion-oauth-pkce.mjs::validateScopes
critical
76
lib/companion-oauth-pkce.mjs::validateTokenResponse
critical
76
lib/companion-provenance-validator.mjs::buildConvenienceProvenance
critical
76
lib/companion-provenance-validator.mjs::isIso8601
critical
76
lib/companion-provenance-validator.mjs::validateProvenance
critical
76
lib/companion-resource-probe.mjs::createCompanionResourceProbe
critical
76
lib/companion-resource-probe.mjs::probeByPlatform
critical
76
lib/companion-resource-probe.mjs::probeLinuxProc
critical
76
lib/companion-resource-probe.mjs::probeWindows
critical
76
lib/companion-resource-probe.mjs::probeWithPs
critical
76
lib/companion-resource-probe.mjs::requireRuntimePid
critical
76
lib/companion-resource-probe.mjs::statResources
critical
76
lib/companion-runtime-manager.mjs::abort
critical
76
lib/companion-runtime-manager.mjs::canServeInference
critical
76
lib/companion-runtime-manager.mjs::createAdmissionState
critical
76
lib/companion-runtime-manager.mjs::createIntegrityAccumulator
critical
76
lib/companion-runtime-manager.mjs::createLifecycleState
critical
76
lib/companion-runtime-manager.mjs::createResourceLimits
critical
76
lib/companion-runtime-manager.mjs::evaluateAdmission
critical
76
lib/companion-runtime-manager.mjs::evaluateResourceLimits
critical
76
lib/companion-runtime-manager.mjs::evaluateRuntimeRequest
critical
76
lib/companion-runtime-manager.mjs::finalize
critical
76
lib/companion-runtime-manager.mjs::getReceivedBytes
critical
76
lib/companion-runtime-manager.mjs::recordCompletion
critical
76
lib/companion-runtime-manager.mjs::recordDequeued
critical
76
lib/companion-runtime-manager.mjs::recordInFlight
critical
76
lib/companion-runtime-manager.mjs::recordQueued
critical
76
lib/companion-runtime-manager.mjs::transitionLifecycle
critical
76
lib/companion-runtime-manager.mjs::update
critical
76
lib/companion-runtime-manager.mjs::validateIntegritySpec
critical
76
lib/companion-runtime-manager.mjs::validateSourceUrl
critical
76
lib/companion-runtime-manager.mjs::verifyModelBytes
critical
76
lib/companion-shell.mjs::companionAvailable
critical
76
lib/companion-shell.mjs::computeCompanionAvailable
critical
76
lib/companion-shell.mjs::createAuthorityGroup
critical
76
lib/companion-shell.mjs::createCompanionShell
critical
76
lib/companion-shell.mjs::createRuntimeGroup
critical
76
lib/companion-shell.mjs::downloadVerifyAndStageModel
critical
76
lib/companion-shell.mjs::healthProbe
critical
76
lib/companion-shell.mjs::laneCapabilities
critical
76
lib/companion-shell.mjs::markIntegrityFailed
critical
76
lib/companion-shell.mjs::markIntegrityVerified
critical
76
lib/companion-shell.mjs::markUnavailable
critical
76
lib/companion-shell.mjs::selectLane
critical
76
lib/companion-shell.mjs::setListenerBound
critical
76
lib/companion-shell.mjs::setLoopbackTokenPresent
critical
76
lib/companion-shell.mjs::shutdown
critical
76
lib/companion-shell.mjs::startRuntime
critical
76
lib/companion-shell.mjs::state
critical
76
lib/companion-shell.mjs::validateManifestTrustAnchor
critical
76
lib/companion-token-custody.mjs::storeSession