{
  "description": "Synthetic demonstration only. Invented SHA identifies a fixture, not a GitHub commit. Finding supplied for report-rendering demonstration; not a live scanner result.",
  "review": {
    "head_sha": "0123456789abcdef0123456789abcdef01234567",
    "analyzed_files": 1,
    "ai_status": "disabled",
    "decision": "review",
    "summary": "An added HTML sink warrants checking the origin of input and intended rendering behavior.",
    "findings": [
      {
        "severity": "high",
        "source": "codecr",
        "title": "Unsafe HTML injection sink",
        "path": "src/render.js",
        "line": 2,
        "evidence": "element.innerHTML = input;",
        "explanation": "The changed line assigns input to an HTML sink. Input provenance and attacker reachability are not established by this fixture.",
        "suggestion": "If plain text is intended, use textContent. If HTML is required, validate the input boundary and use a reviewed sanitizer.",
        "confidence": 0.8,
        "blocking": false
      }
    ],
    "limitations": [
      "Synthetic fixture with an invented changed file, caller and test; not a customer result",
      "No AI or repository tests executed",
      "No GitHub CI inspected"
    ],
    "repository_context": {
      "version": 1,
      "head_sha": "0123456789abcdef0123456789abcdef01234567",
      "status": "bounded",
      "bytes_scanned": 420,
      "files": [
        {
          "path": "src/render.js",
          "blob_sha": "1111111111111111111111111111111111111111",
          "changed": true,
          "test": false
        },
        {
          "path": "src/page.js",
          "blob_sha": "2222222222222222222222222222222222222222",
          "changed": false,
          "test": false
        },
        {
          "path": "test/render.test.js",
          "blob_sha": "3333333333333333333333333333333333333333",
          "changed": false,
          "test": true
        }
      ],
      "edges": [
        {
          "kind": "call",
          "from": "src/page.js",
          "to": "src/render.js",
          "symbol": "render",
          "evidence": {
            "path": "src/page.js",
            "line": 2,
            "quote": "render(element, new URLSearchParams(location.search).get('message'));"
          },
          "target_evidence": {
            "path": "src/render.js",
            "line": 1,
            "quote": "export function render(element, input) {"
          }
        },
        {
          "kind": "test-import",
          "from": "test/render.test.js",
          "to": "src/render.js",
          "evidence": {
            "path": "test/render.test.js",
            "line": 1,
            "quote": "import { render } from '../src/render.js';"
          }
        }
      ],
      "unknowns": [
        "All source records are invented synthetic fixtures, not a inspected customer repository.",
        "The test reference establishes a static relationship only. The test was not executed.",
        "Production caller reach, intended HTML behavior and deployment are unknown."
      ]
    }
  },
  "files": [
    {
      "filename": "src/render.js",
      "status": "added",
      "additions": 3,
      "deletions": 0,
      "patch": "@@ -0,0 +1,3 @@\n+export function render(element, input) {\n+  element.innerHTML = input;\n+}"
    }
  ],
  "pull": {
    "head": {
      "sha": "0123456789abcdef0123456789abcdef01234567"
    },
    "changed_files": 1,
    "title": "Render supplied content",
    "body": "Synthetic rendering example for the CodeCR product walkthrough."
  },
  "checks": null,
  "statuses": null,
  "observedAt": "2026-10-04T19:00:00.000Z"
}
