# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 62 → 64 (+1.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 89 → 89 (-0.1)
- Architecture 100 → 100 (+0.0)
- Maturity 65 → 65 (+0.0)
- Readiness 64 → 64 (+0.0)
- Security 57 → 63 (+5.4)
- Domain Modelling 100 → 100 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 59 → 59 (+0.0)

## Resolved (15)

- Dependency hygiene not measured — no supported dependency manifest was read
- ExecutionGateway.start_user_data_stream (cyclomatic 16) (crates/atomic-feed/src/gateway.rs)
- ExecutionGateway.submit_order (cyclomatic 17) (crates/atomic-feed/src/gateway.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- main$module.handle_mesh_message (cyclomatic 17) (crates/atomic-node/src/main.rs)

## New (20)

- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: src/main.rs (crates/atomic-node/src/main.rs)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium advisory (unmaintained): RUSTSEC-2025-0141 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0097 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0190 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0204 (Cargo.lock)
