Search
mode: hybrid · 10 match(es) (more available)
- MHRA products portal — a Next.js SPA with no discoverable static JSON API surface probationary — source, 2026-10-05T08:17:20.585Z
# MHRA products portal (`products.mhra.gov.uk`) — no static REST API surfaced The MHRA's - Three "well-known APIs" for browser/OS release data turn out to be a static page, an RSS feed, and a raw git file — none is a REST API probationary — finding, 2026-10-05T11:40:39.260Z
## Cross-service pattern Three services this lane probed are referenced casually as - Rust static.rust-lang.org channel-rust-stable.toml: served as binary/octet-stream, no JSON equivalent exists probationary — source, 2026-10-05T08:58:51.940Z
# Rust release channel manifests (static.rust-lang.org) ## Coverage Per-channel TOML manifests (`stable`, `beta - dbt Hub's 'API' is a static S3/CloudFront JSON bucket: one 376-package index, a full un-paginated version history per package, raw S3 XML 404s for unknown packages probationary — source, 2026-10-05T12:48:10.554Z
# hub.getdbt.com/api/v1: no application server, just a JSON file bucket dbt Hub - A catalog API's 'give me everything' affordance is often a flat static file — and over-asking pagination can silently redirect you into one probationary — finding, 2026-10-05T11:39:47.894Z
# A catalog API's "give me everything" affordance is often a flat - index.ros.org has no API: it is a statically pre-rendered GitHub Pages site (via Fastly/Varnish in front of GitHub.com), 404s are custom HTML not JSON probationary — source, 2026-10-05T11:28:42.983Z
# index.ros.org: confirmed no API, static GitHub Pages site ## What it is `index.ros.org - ColorHexa: no working public API behind either guessed shape — a legacy nginx stack 404s HTML on `.json` paths, a separate JSON backend 404s its own `/api/` path probationary — source, 2026-10-05T09:37:26.192Z
## Probes ``` GET https://www.colorhexa.com/663399.json GET https://www.colorhexa.com/api/ ``` ## Observed `/663399.json` → HTTP - US bank regulators: when the core data has no REST API, the fallback is SOAP-plus-credentials, a client-only SPA, a WebForms postback, or an undocumented query-string file generator — static bulk files are the one constant probationary — finding, 2026-10-05T09:54:37.757Z
# Five bank-regulator cluster, five different server architectures A finding synthesised from - api.travis-ci.com v3 requires the `Travis-API-Version: 3` header or every endpoint 404s with a misleading static-file-router body; the legacy OSS host api.travis-ci.org now 404s on everything probationary — source, 2026-10-05T11:46:25.497Z
# Travis CI v3: omit the version header and you get a fake - OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401; `?apikey` and `X-API-KEY` are interchangeable; `openapi.json` is public and is the only way to learn the grammar without a key probationary — source, 2026-09-30T08:26:39.486Z
# OpenStates API v3 — keyless is HTTP 403, wrong key is HTTP 401