# Changelog

## Score

- CAI 37 → 39 (+2.4)

## Lenses

- Code Health 63 → 63 (-0.1)
- Architecture 69 → 69 (+0.0)
- Maturity 44 → 44 (+0.0)
- Readiness 27 → 32 (+5.3)
- Security 47 → 52 (+4.6)
- Accessibility 38 → 37 (-0.8)
- Performance 60 → 70 (+9.7)

## Resolved (35)

- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High vulnerability: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- Inconsistent naming for RabbitMQ configuration methods: 'WithClientName', 'WithConsumer', 'WithConnectionString'. The pattern 'With...' is used, but the nouns vary significantly.
- Inconsistent naming for base domain models: 'ValueObject', 'Entity', 'IEntity'. Some use 'Entity' while others use 'IEntity' or 'ValueObject'.
- Inconsistent naming for date/time properties: 'UploadDate', 'PublishedAt', 'IsDeleted'. Some use 'Date' suffix, others use 'At' suffix.
- Inconsistent naming for financial data link models: 'Links' is used in multiple places but sometimes as a container and sometimes as a specific link type. Also, 'Insighify' is a typo in some fully qualified names compared to 'Insightify'.
- Inconsistent naming for financial data properties: 'LastUpdated' vs 'HashingAlgorithm' vs 'SentimentVotesDownPercentage'. The structure of property names varies between camelCase and PascalCase or mixed styles.
- Inconsistent naming for pagination header/value objects: some use 'PaginationHeaderValue' while others use 'Page' or 'PaginationHeaders'. Similarly, the property for the current page is named 'CurrentPage' in some places but 'CurrentPage' is also used in a class named 'Page' vs 'PaginationHeaderValue'.
- Inconsistent naming for pagination metadata: 'TotalCount' vs 'TotalPages' vs 'PageSize'. Some interfaces use 'IPage' while others use 'IPagedList'.
- Inconsistent naming for pagination-related types: 'PagedList', 'PaginationHeaderValue', 'PaginationHeadersFilter', 'IPage'. The concept of a 'Page' of results is represented by 'PagedList', 'Page', and 'PaginationHeaderValue' in different modules.
- Inconsistent naming for test methods: some use 'Should' pattern (e.g., 'Remove_Comment_Should...') while others use 'Should' in a different way or no 'Should' at all. Also, 'PostSpecs' vs 'CommentSpecs' vs 'SaveSpecs' for test classes.
- Inconsistent naming for user-related properties: 'AuthorId', 'Username', 'ImageUrl'. The concept of 'Author' is sometimes 'Author' and sometimes 'User'.
- Medium CVE: Azure.Identity 1.6.0
- Medium CVE: Azure.Identity 1.6.0
- Medium CVE: Azure.Identity 1.7.0
- Medium CVE: Azure.Identity 1.7.0
- Medium CVE: BouncyCastle.Cryptography 2.2.1
- Medium CVE: BouncyCastle.Cryptography 2.2.1
- Medium CVE: BouncyCastle.Cryptography 2.2.1
- …and 15 more

## New (27)

- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High CVE: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High vulnerability: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- High vulnerability: [GHSA redacted] (src/Web/Angular.Client/insightify-client/package-lock.json)
- Medium CVE: Azure.Identity 1.6.0
- Medium CVE: Azure.Identity 1.6.0
- Medium CVE: Azure.Identity 1.7.0
- Medium CVE: Azure.Identity 1.7.0
- Medium CVE: BouncyCastle.Cryptography 2.2.1
- Medium CVE: BouncyCastle.Cryptography 2.2.1
- …and 7 more

## API surface

- Unchanged — 37 HTTP endpoints
