# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 28 → 44 (+16.0)

## Lenses

- Code Health 76 (new)
- Architecture 87 (new)
- Maturity 13 → 46 (+32.7)
- Readiness 15 → 44 (+28.7)
- Security 100 → 35 (-64.6)
- Accessibility 63 (new)

## Resolved (4)

- Dependency hygiene not measured — no supported dependency manifest was read
- bus factor not measured — no commits were sampled
- early-stage repository — too little history to judge knowledge freshness
- single-commit history — no usable git history window to measure hotspots

## New (75)

- Bounded contexts not declared
- Further orphaned files (smaller)
- High IaC: DS-0002 (src/Dotnet6.GraphQL4.Store.WebAPI/Dockerfile)
- High IaC: DS-0002 (src/Dotnet6.GraphQL4.Store.WebMVC/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 55 more

## API surface

- 1 added · 0 removed (a removed endpoint is potentially breaking)

## Added endpoints (1)

- POST /
