# Changelog

## Score

- CAI 47 → 49 (+1.7)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 82 → 84 (+2.2)
- Architecture 58 → 65 (+6.7)
- Maturity 54 → 54 (+0.2)
- Readiness 64 → 58 (-6.9)
- Security 43 → 50 (+7.1)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 40 → 39 (-0.4)
- Performance 100 (new)

## Resolved (75)

- Change coupling: lib.rs ↔ lib.rs (crates/arroyo-controller/src/lib.rs)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [CVE redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- …and 55 more

## New (52)

- FunctionTooLong: PipelineConfigs.PipelineConfigs (webui/src/routes/pipelines/PipelineConfigs.tsx)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- Inconsistent parameter naming for identical signatures. Most connectors use `options` (plural), while ConfluentConnector uses `opts` (abbreviated).
- Inconsistent parameter naming for identical signatures. Most connectors use `options` (plural), while ConfluentConnector uses `opts` (abbreviated). Note: ConfluentConnector does not expose `table_from_options`, but the inconsistency in `connection_from_options` is sufficient to flag the naming convention drift.
- Medium CVE: [GHSA redacted] (webui/pnpm-lock.yaml)
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Off the main sequence: arroyo-datastream
- Off the main sequence: arroyo-rpc
- Off the main sequence: arroyo-storage
- Off the main sequence: arroyo-types
- Off the main sequence: arroyo-udf-common
- Off the main sequence: arroyo-udf-host
- Off the main sequence: arroyo-udf-python
- Off-boarding risk: anonymized user #1
- Orphaned knowledge (crates/arroyo-connectors/src/nats/source/mod.rs)
- Outdated: arc-swap
- …and 32 more

## Changes since last survey

- 11 commits — 8 feature/other, 3 fixes

## By area

- crates/arroyo-connectors — 2 commits
- crates/arroyo-controller — 2 commits
- crates/arroyo-sql-testing — 2 commits
- crates/arroyo-udf — 2 commits
- crates/arroyo-api — 1 commit
- docker/Dockerfile — 1 commit
- webui/pnpm-lock.yaml — 1 commit

## Notable commits

- fix: Fix udf macro by tagging no_mangle unsafe (#1157)
- fix: fix(filesystem): classify recovery auth errors as user failures (#1168)
- fix: fix(worker): drain and restore async UDF calls correctly (#1150)
- change: Add support for pipeline-level configs (#1151)
- change: Decouple Controller scheduling from DataFusion (#1148)
- change: Introduce connection table versioning (#1147)
- change: Run the Iceberg commit in the background (#1170)
- change: Test string-numeric comparison coercion (#1169)
- change: Update version of pnpm in docker (#1166)
- change: Upgrade js-yaml to 4.3.2 (from 4.3.1) (#1152)
- change: test(sql): cover null aggregate inputs (#1153)
