# Changelog

## Score

- CAI 38 → 38 (+0.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 40 → 40 (+0.7)
- Readiness 15 → 15 (+0.0)
- Security 76 → 81 (+4.5)

## Resolved (22)

- Critical CVE: [GHSA redacted] (poetry.lock)
- Critical CVE: [GHSA redacted] (poetry.lock)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: PYSEC-2024-38 (poetry.lock)
- Medium CVE: PYSEC-2026-2132 (poetry.lock)
- Medium IaC: CKV_DOCKER_3 (docker/Dockerfile.backend)
- Medium IaC: CKV_DOCKER_3 (docker/Dockerfile.migration)
- …and 2 more

## New (28)

- Critical CVE: [GHSA redacted] (poetry.lock)
- Critical CVE: [GHSA redacted] (poetry.lock)
- Critical CVE: [GHSA redacted] (poetry.lock)
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High IaC: WD-DOCKER-0001 (docker/Dockerfile.backend)
- High IaC: WD-DOCKER-0001 (docker/Dockerfile.migration)
- Low IaC: DS-0026 (docker/Dockerfile.backend)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- …and 8 more
