# Changelog

## Score

- CAI 54 → 55 (+1.6)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 98 → 99 (+0.7)
- Architecture 69 → 69 (+0.0)
- Maturity 67 → 66 (-0.3)
- Readiness 31 → 38 (+7.4)
- Security 100 → 76 (-24.5)

## Resolved (9)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (10–11 lines × 2) (app/adapters/sqlite.py)
- No exposed public API
- Test reliability not included
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk

## New (37)

- Critical CVE: [GHSA redacted] (requirements.txt)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10–11 lines × 2) (app/adapters/sqlite.py)
- High CVE: [GHSA redacted] (requirements.txt)
- High CVE: [GHSA redacted] (requirements.txt)
- High CVE: [GHSA redacted] (requirements.txt)
- High CVE: [GHSA redacted] (requirements.txt)
- Hotspot: app/__main__.py (app/__main__.py)
- Medium CVE: [GHSA redacted] (requirements.txt)
- Medium CVE: [GHSA redacted] (requirements.txt)
- Medium CVE: [GHSA redacted] (requirements.txt)
- Medium CVE: [GHSA redacted] (requirements.txt)
- Medium CVE: PYSEC-2026-2132 (requirements.txt)
- No ADRs found
- Outdated: aniso8601
- Outdated: certifi
- Outdated: chardet
- Outdated: click
- …and 17 more
