# Changelog

## Score

- CAI 37 → 33 (-4.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 82 → 61 (-21.1)
- Maturity 57 → 56 (-1.2)
- Readiness 14 → 12 (-2.2)
- Security 51 → 49 (-2.7)

## Resolved (14)

- Change coupling: Attach.tsx ↔ AttachSmall.tsx (src/components/MessageInputActions/Attach.tsx)
- Change coupling: EmptyChatMessageInput.tsx ↔ MessageInput.tsx (src/components/EmptyChatMessageInput.tsx)
- Change coupling: SearchImages.tsx ↔ SearchVideos.tsx (src/components/SearchImages.tsx)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (yarn.lock)
- High vulnerability: [GHSA redacted] (yarn.lock)
- Low CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium vulnerability: [GHSA redacted] (yarn.lock)
- Off-boarding risk: anonymized user #1
- Rotate the exposed credentials — git history can't be un-committed
- Workflow token permissions not restricted

## New (46)

- Dimension evaluation failed
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- …and 26 more
