# Changelog

## Score

- CAI 41 → 42 (+0.7)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 39 → 38 (-0.6)
- Architecture 97 → 87 (-10.1)
- Maturity 60 → 60 (+0.0)
- Readiness 40 → 40 (+0.2)
- Security 57 → 63 (+6.2)
- Accessibility 35 → 35 (+0.0)
- Performance 100 (new)

## Resolved (11)

- Concentrated knowledge decay
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- parseGitLog (cyclomatic 24) (source/git-parser.js)
- parsePatchDiffResult (cognitive 20) (source/git-parser.js)
- queryPromise (cognitive 25) (public/source/server.js)

## New (23)

- Documentation: no usage examples (README.md)
- Dormant codebase
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Low cohesion: AppViewModel (LCOM4 6) (components/app/app.js)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): @primer/octicons
- Outdated (npm): bootstrap
- Outdated (npm): ignore
- Outdated (npm): jquery
- Outdated (npm): moment
- Outdated (npm): open
- Outdated (npm): p-limit
- Outdated (npm): socket.io
- Outdated (npm): typescript
- Outdated (npm): yargs
- Projects may be oversized for their cohesion
- …and 3 more
