# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 37 → 37 (+0.3)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 47 → 49 (+1.8)
- Architecture 100 → 100 (+0.0)
- Maturity 38 → 38 (+0.0)
- Readiness 20 → 20 (+0.0)
- Security 74 → 75 (+1.3)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 66 → 66 (+0.0)

## Resolved (4)

- Medium CVE: [GHSA redacted] (packages/iridium/components/navigator/assets/_scripts/yarn.lock)
- Medium CVE: [GHSA redacted] (packages/iridium/components/navigator/assets/_scripts/yarn.lock)
- Medium: security finding (details withheld)
- The README states 'Any Operating System' and 'Any IDE with Flutter SDK installed', but no OS or IDE version requirements are specified (e.g. Dart 3, Flutter 2.x). (README.md)

## New (3)

- Medium CVE: [GHSA redacted] (packages/iridium/components/navigator/assets/_scripts/yarn.lock)
- Medium CVE: [GHSA redacted] (packages/iridium/components/navigator/assets/_scripts/yarn.lock)
- The asset README is thin and only explains how to replace images in this directory; it does not cover the broader launch-screen customization workflow. (ios/Runner/Assets.xcassets/LaunchImage.imageset/README.md)
