# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 46 → 31 (-14.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 73 → 79 (+6.2)
- Maturity 66 → 58 (-7.7)
- Readiness 28 → 11 (-16.9)
- Security 58 → 40 (-18.3)

## Resolved (42)

- Change coupling: amp.rs ↔ droid.rs (crates/executors/src/executors/amp.rs)
- Change coupling: codex.rs ↔ qwen.rs (crates/executors/src/executors/codex.rs)
- Change coupling: coding_agent_follow_up.rs ↔ coding_agent_initial.rs (crates/executors/src/actions/coding_agent_follow_up.rs)
- Change coupling: copilot.rs ↔ droid.rs (crates/executors/src/executors/copilot.rs)
- Change coupling: copilot.rs ↔ opencode.rs (crates/executors/src/executors/copilot.rs)
- Change coupling: copilot.rs ↔ qwen.rs (crates/executors/src/executors/copilot.rs)
- Change coupling: cursor.rs ↔ droid.rs (crates/executors/src/executors/cursor.rs)
- Change coupling: cursor.rs ↔ qwen.rs (crates/executors/src/executors/cursor.rs)
- Change coupling: droid.rs ↔ opencode.rs (crates/executors/src/executors/droid.rs)
- Change coupling: opencode.rs ↔ qwen.rs (crates/executors/src/executors/opencode.rs)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further sole-owners (lower concentration)
- High CVE: [GHSA redacted] (crates/remote/Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (crates/relay-tunnel/Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (crates/relay-tunnel/Cargo.lock)
- High: security finding (details withheld)
- …and 22 more

## New (41)

- (anonymous) (cognitive 21) (crates/preview-proxy/src/click_to_component_script.js)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 21 more
