# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 55 → 52 (-2.5)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 99 → 99 (+0.0)
- Architecture 99 → 98 (-1.6)
- Maturity 70 → 73 (+3.0)
- Readiness 44 → 39 (-4.8)
- Security 43 → 44 (+1.3)

## Resolved (50)

- Boundary-crossing change coupling: config.exs ↔ connection_init.ex (config/config.exs)
- Change coupling: dev.exs ↔ prod.exs (config/dev.exs)
- Change coupling: http.ex ↔ kafka.ex (lib/rig_inbound_gateway/api_proxy/handler/http.ex)
- Dependency hygiene not measured — no supported dependency manifest was read
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (lib/rig_api/v2/session_blacklist.ex)
- Duplicated block (10 lines × 2) (lib/rig_inbound_gateway/api_proxy/handler/kafka.ex)
- Duplicated block (11 lines × 2) (lib/rig_api/v2/session_blacklist.ex)
- Duplicated block (15 lines × 2) (lib/rig_inbound_gateway_web/v1/sse.ex)
- Duplicated block (27 lines × 2) (lib/rig_api/v2/apis.ex)
- Duplicated block (32 lines × 2) (lib/rig_api/v2/responses.ex)
- Duplicated block (8 lines × 2) (lib/rig_api/v2/apis.ex)
- Duplicated block (9 lines × 2) (lib/rig_api/v2/apis.ex)
- High IaC: DS-0002 (examples/channels-example/frontend/Dockerfile)
- High IaC: DS-0002 (examples/channels-example/service/Dockerfile)
- High IaC: DS-0002 (smoke_tests.dockerfile)
- High IaC: DS-0002 (smoke_tests/rest-api/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 30 more

## New (61)

- Change coupling: event_controller.ex ↔ subscription_controller.ex (lib/rig_inbound_gateway_web/v1/event_controller.ex)
- Change coupling: health.ex ↔ router.ex (lib/rig_api/health.ex)
- Change coupling: kafka_to_filter.ex ↔ kinesis_to_filter.ex (lib/rig/event_stream/kafka_to_filter.ex)
- Change coupling: router.ex ↔ event_controller.ex (lib/rig_inbound_gateway_web/router.ex)
- Change coupling: sse.ex ↔ subscription_controller.ex (lib/rig_inbound_gateway_web/v1/sse.ex)
- Context and decision are both present but the body is largely boilerplate boilerplate with a one-line 'In a nutshell' summary plus a bulleted list of ADR rules (immutable decisions, numbered without reuse, new ADR replaces old) that gives no real context or consequences (guides/architecture/decisions/0001-record-architecture-decisions.md)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (lib/rig_api/v2/session_blacklist.ex)
- Duplicated block (14 lines × 2) (lib/rig_inbound_gateway_web/v1/sse.ex)
- Duplicated block (25 lines × 2) (lib/rig_api/v2/apis.ex)
- Duplicated block (30 lines × 2) (lib/rig_api/v2/responses.ex)
- Duplicated block (7 lines × 2) (lib/rig_api/v2/apis.ex)
- Duplicated block (8 lines × 2) (lib/rig_api/v2/apis.ex)
- Duplicated block (9 lines × 2) (lib/rig_api/v2/session_blacklist.ex)
- Duplicated block (9 lines × 2) (lib/rig_inbound_gateway/api_proxy/handler/kafka.ex)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- High CVE: [GHSA redacted] (mix.lock)
- …and 41 more
