# Changelog

## Score

- CAI 39 → 40 (+1.2)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 62 → 66 (+4.8)
- Architecture 91 → 91 (-0.2)
- Maturity 57 → 57 (+0.0)
- Readiness 20 → 20 (+0.0)
- Security 58 → 62 (+3.4)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 46 → 49 (+2.9)

## Resolved (42)

- (anonymous) (cognitive 17) (client/src/assets/games/rock_paper_scissors/script.js)
- Change coupling: AccountController.cs ↔ ExceptionMiddleware.cs (server/WebAPI/Controllers/AccountController.cs)
- Change coupling: AccountController.cs ↔ UsersController.cs (server/WebAPI/Controllers/AccountController.cs)
- Change coupling: UserLoginCommandHandler.cs ↔ UserRegistrationCommandHandler.cs (server/Application/Features/Authentication/UserLogin/UserLoginCommandHandler.cs)
- Change coupling: UserRegistrationCommandHandler.cs ↔ UserRegistrationCommandValidator.cs (server/Application/Features/Authentication/UserRegistration/UserRegistrationCommandHandler.cs)
- Change coupling: UsersController.cs ↔ ExceptionMiddleware.cs (server/WebAPI/Controllers/UsersController.cs)
- Change coupling: home.component.ts ↔ posts.component.ts (client/src/app/features/home/home.component.ts)
- Change coupling: post.component.ts ↔ upload-post.component.ts (client/src/app/shared/components/post/post.component.ts)
- Coverage not measured — analyzer environment
- FileTooLong: hollow_x_hollow/script.js (client/src/assets/games/hollow_x_hollow/script.js)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- …and 22 more

## New (38)

- Change coupling: PostDto.cs ↔ PostsController.cs (server/Application/Features/Posts/Common/PostDto.cs)
- Change coupling: app-routing.module.ts ↔ route-animations.ts (client/src/app/app-routing.module.ts)
- Change coupling: app.module.ts ↔ auth-form.component.ts (client/src/app/app.module.ts)
- Change coupling: app.module.ts ↔ nav-links.ts (client/src/app/app.module.ts)
- Change coupling: app.module.ts ↔ route-animations.ts (client/src/app/app.module.ts)
- Change coupling: route-animations.ts ↔ UsersController.cs (client/src/app/core/animations/route-animations.ts)
- Change coupling: route-animations.ts ↔ nav-links.ts (client/src/app/core/animations/route-animations.ts)
- Coverage not measured — analyzer environment
- Critical CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- High CVE: [GHSA redacted] (client/package-lock.json)
- …and 18 more

## API surface

- Unchanged — 37 HTTP endpoints
