# Changelog

## Score

- CAI 39 → 41 (+2.3)

## Lenses

- Code Health 56 → 56 (-0.0)
- Architecture 69 → 69 (+0.2)
- Maturity 47 → 47 (+0.0)
- Readiness 30 → 37 (+6.5)
- Security 68 → 69 (+1.5)
- Event-Driven 100 → 100 (+0.0)
- Accessibility 33 → 33 (+0.0)

## Resolved (73)

- Critical CVE: System.Text.Encodings.Web 4.5.0
- Deprecated: Blazored.Modal
- Deprecated: Microsoft.ApplicationInsights
- Deprecated: Microsoft.AspNetCore.Authorization.Policy
- Deprecated: Microsoft.AspNetCore.Http.Extensions
- Deprecated: Microsoft.AspNetCore.Identity
- Deprecated: Microsoft.AspNetCore.Mvc.Core
- Deprecated: Microsoft.AspNetCore.Mvc.RazorPages
- Deprecated: Microsoft.AspNetCore.Mvc.Versioning
- Deprecated: Microsoft.AspNetCore.Mvc.ViewFeatures
- Deprecated: xunit
- High CVE: AutoMapper 13.0.1
- High CVE: Microsoft.Build 17.10.4
- High CVE: Newtonsoft.Json 9.0.1
- High CVE: System.Net.Http 4.3.0
- High CVE: System.Text.RegularExpressions 4.3.0
- Inconsistent naming for the command handler of 'DeleteChannel'. One is named 'DeleteChannelCommandCommandHandler' (redundant 'Command' in name) while the command itself is 'DeleteChannel'.
- Low CVE: NuGet.Packaging 6.11.0
- Low CVE: NuGet.Protocol 6.11.0
- Medium CVE: System.Security.Cryptography.Xml 4.5.0
- …and 53 more

## New (5)

- Build status unknown
- Inconsistent casing in query names: 'GetTenantByID' uses uppercase 'ID' while 'GetTenantByIdQueryHandler' uses lowercase 'Id'.
- Inconsistent namespace structure: 'StripeCustomers' is under 'DomainFeatures' but 'StripeSubscriptionPlan' is also under 'DomainFeatures', yet the typo 'Aplication' exists in one namespace path.
- Off-boarding risk: anonymized user #1
- Typo in namespace: 'Aplication' is misspelled (should be 'Application').

## API surface

- Unchanged — 22 HTTP endpoints
