# Changelog

## Score

- CAI 38 → 41 (+3.1)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 64 → 64 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 22 → 29 (+6.5)
- Readiness 29 → 29 (+0.0)
- Security 88 → 92 (+3.2)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (9)

- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)

## New (3)

- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
