{
  "schema_version": "scan_result.v1",
  "scan_id": "3f2f0cb4",
  "project_name": "venruk",
  "timestamp": "2026-06-27T12:52:03.488669+00:00",
  "scan_started_at": "2026-06-27T12:52:03.138071+00:00",
  "scan_completed_at": "2026-06-27T12:52:03.488669+00:00",
  "duration_seconds": 0.35,
  "scan_mode": "quick",
  "profile": null,
  "files_scanned": 120,
  "lines_scanned": 360,
  "languages": [
    "python"
  ],
  "frameworks": [],
  "scanners_run": [
    "secrets",
    "quality",
    "sast",
    "dependencies"
  ],
  "scores": {
    "security": 100.0,
    "quality": 100.0,
    "maintainability": 100.0,
    "architecture": 77.0,
    "compliance": 100.0,
    "overall": 96.5,
    "grade": "A+"
  },
  "summary": {
    "total": 2,
    "critical": 1,
    "high": 1,
    "medium": 0,
    "low": 0,
    "info": 0
  },
  "findings": [
    {
      "schema_version": "finding.v1",
      "id": "2ea19893",
      "title": "Root Cause: Architectural Flaw 'CC-CRY-001'",
      "description": "Systemic issue detected. The rule 'CC-CRY-001' triggered 
120 times across the repository. This indicates a missing centralized security 
mechanism or lack of developer awareness.\nSample: Variable `token` is assigned 
a hardcoded string literal. Credentials in source code are exposed in version 
control and build artifacts.",
      "severity": "high",
      "category": "architecture",
      "confidence": "high",
      "location": {
        "file": "Multiple Files",
        "start_line": 1,
        "end_line": 1,
        "start_col": null,
        "end_col": null,
        "snippet": null
      },
      "rule_id": "root-cause-systemic",
      "scanner": "intelligence-correlation",
      "cwe_id": null,
      "owasp_id": null,
      "cvss_score": null,
      "fix_suggestion": null,
      "fix_diff": null,
      "effort_minutes": null,
      "references": [],
      "tags": [],
      "metadata": {
        "ownership_resolution_method": "Fallback",
        "reachability": {
          "status": "unknown",
          "confidence": "LOW",
          "entrypoint_ids": [],
          "attack_path_ids": [],
          "unresolved_call_count": 0,
          "analysis_version": "reachability.v2"
        }
      },
      "ai_status": null,
      "ai_confidence": null,
      "ai_reasoning": null,
      "is_root_cause": true,
      "related_findings": [
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001",
        "CC-CRY-001"
      ],
      "owner": "Unknown",
      "fingerprint": "d9136c0a55ff94af",
      "timestamp": "2026-06-27T12:52:03.307480+00:00"
    },
    {
      "schema_version": "finding.v1",
      "id": "ARCH-CHOKE-file:Multiple Files",
      "title": "High-Risk Chokepoint: file:Multiple Files",
      "description": "This FILE is depended upon by 1 components but contains a 
vulnerability: Root Cause: Architectural Flaw 'CC-CRY-001'.",
      "severity": "critical",
      "category": "architecture",
      "confidence": "high",
      "location": {
        "file": "file:Multiple Files",
        "start_line": 1,
        "end_line": 1,
        "start_col": null,
        "end_col": null,
        "snippet": ""
      },
      "rule_id": "ARCH-CHOKEPOINT",
      "scanner": "tech-debt",
      "cwe_id": "",
      "owasp_id": "",
      "cvss_score": null,
      "fix_suggestion": null,
      "fix_diff": null,
      "effort_minutes": null,
      "references": [],
      "tags": [],
      "metadata": {
        "ownership_resolution_method": "Fallback"
      },
      "ai_status": null,
      "ai_confidence": null,
      "ai_reasoning": null,
      "is_root_cause": false,
      "related_findings": [],
      "owner": "Unknown",
      "fingerprint": "98f6c588e1dad8e5",
      "timestamp": "2026-06-27T12:52:03.454863+00:00"
    }
  ],
  "metadata": {
    "risk_attribution": {
      "Unknown": {
        "critical": 1,
        "high": 1,
        "medium": 0,
        "low": 0,
        "info": 0,
        "total_findings": 2,
        "risk_score": 23.0,
        "blast_radius_services": 0
      }
    },
    "reachability": {
      "schema_version": "reachability.v1",
      "entrypoints_detected": 0,
      "findings_analyzed": 1,
      "findings_reachable": 0,
      "findings_unreachable": 0,
      "findings_unknown": 1,
      "attack_paths_total": 0,
      "attack_paths_max_length": 0,
      "attack_paths_min_length": 0,
      "entrypoints_used": 0,
      "unresolved_calls": 0
    },
    "ownership": {
      "schema_version": "ownership.v1",
      "unique_owners": 0,
      "findings_with_owner": 0,
      "findings_without_owner": 2
    },
    "risk_attribution_v2": {
      "schema_version": "risk_attribution_v2.v1",
      "findings_scope": "scanner_findings_only",
      "owners": {
        "Unknown": {
          "reachable_findings": 0,
          "unreachable_findings": 0,
          "unknown_findings": 1,
          "not_analyzed_findings": 0,
          "attack_path_count": 0,
          "total_findings": 1,
          "risk_score": 8.0
        }
      }
    },
    "attack_paths": {
      "schema_version": "attack_paths.v1",
      "entrypoints": [],
      "attack_paths": [],
      "finding_meta": {
        "2ea19893": {
          "finding_id": "2ea19893",
          "status": "unknown",
          "confidence": "LOW",
          "entrypoint_ids": [],
          "attack_path_ids": [],
          "unresolved_call_count": 0,
          "analysis_version": "reachability.v2"
        }
      },
      "stats": {
        "entrypoints": 0,
        "attack_paths": 0,
        "unresolved_calls": 0,
        "findings_analyzed": 1,
        "findings_reachable": 0,
        "findings_unreachable": 0,
        "findings_unknown": 1
      },
      "node_locations": {},
      "limits_hit": {},
      "finding_diagnostics": {
        "2ea19893": {
          "finding_id": "2ea19893",
          "entrypoints_checked": 0,
          "nodes_visited": 0,
          "hard_gaps_in_scope": 0,
          "soft_gaps_in_scope": 0,
          "depth_limit_hit": false,
          "ghost_entrypoints_skipped": 0,
          "target_callables_found": 0,
          "ambiguous_aliases_in_resolution": 0
        }
      },
      "analysis_complete": true
    },
    "pipeline": {
      "schema_version": "pipeline.v1",
      "stages": {
        "discovery": {
          "duration_ms": 59.17,
          "status": "success"
        },
        "scanning": {
          "duration_ms": 96.51,
          "status": "success"
        },
        "correlation": {
          "duration_ms": 13.92,
          "status": "success"
        },
        "graph": {
          "duration_ms": 58.36,
          "status": "success"
        },
        "enrichment": {
          "duration_ms": 42.14,
          "status": "success"
        },
        "risk": {
          "duration_ms": 40.69,
          "status": "success"
        }
      },
      "total_duration_ms": 311.1
    }
  }
}
