# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 49 → 50 (+0.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 91 → 94 (+3.2)
- Architecture 100 → 92 (-8.0)
- Maturity 80 → 66 (-14.2)
- Readiness 31 → 35 (+3.6)
- Security 70 → 70 (+0.4)
- Domain Modelling 72 → 76 (+4.3)
- Accessibility 52 → 52 (+0.0)

## Resolved (24)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (12 lines × 2) (modules/user/repository/user_repository.go)
- Duplicated block (16 lines × 2) (database/manager.go)
- Further orphaned files (smaller)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 4 more

## New (32)

- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/common-nighthawk/go-figure
- Dependency pinned to a stale untagged commit: gopkg.in/gomail.v2
- Duplicated block (11 lines × 2) (modules/auth/repository/refresh_token_repository.go)
- Duplicated block (11 lines × 2) (modules/user/repository/user_repository.go)
- Duplicated block (34 lines × 2) (database/manager.go)
- Duplicated block (9 lines × 2) (modules/auth/controller/auth_controller.go)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2026-4599 (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium IaC: WD-DOCKER-0003 (docker/Dockerfile)
- Medium IaC: WD-DOCKER-0010 (docker/Dockerfile)
- …and 12 more
