# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 28 → 48 (+20.2)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 71 (new)
- Architecture 95 (new)
- Maturity 13 → 57 (+44.0)
- Readiness 15 → 57 (+41.7)
- Security 100 → 33 (-67.3)

## Resolved (7)

- Dependency hygiene not measured — no supported dependency manifest was read
- No automated tests
- No tests found
- Test reliability not included
- bus factor not measured — no commits were sampled
- early-stage repository — too little history to judge knowledge freshness
- single-commit history — no usable git history window to measure hotspots

## New (34)

- Coverage not measured — analyzer environment
- Critical CVE: System.Text.Encodings.Web 4.5.0
- High CVE: AutoMapper 10.1.1
- High CVE: Newtonsoft.Json 11.0.2
- High CVE: System.Net.Http 4.3.0
- High CVE: System.Text.RegularExpressions 4.3.0
- High IaC: DS-0002 (WizardWorldApi/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low: security finding (details withheld)
- Medium CVE: System.Security.Cryptography.Xml 4.5.0
- Medium IaC: CKV2_GHA_1 (.github/workflows/deploy.yml)
- Medium IaC: CKV2_GHA_1 (.github/workflows/main.yml)
- Medium IaC: CKV_DOCKER_3 (WizardWorldApi/Dockerfile)
- Medium IaC: CKV_SECRET_6 (WizardWorldApi/compose.yaml)
- Mock framework: Moq
- No ADRs found
- …and 14 more

## API surface

- 13 added · 0 removed (a removed endpoint is potentially breaking)

## Added endpoints (13)

- GET /elixirs
- GET /elixirs/{id}
- GET /houses
- GET /houses/{id}
- GET /ingredients
- GET /ingredients/{id}
- GET /magicalcreature
- GET /magicalcreature/{id}
- GET /spells
- GET /spells/{id}
- GET /wizards
- GET /wizards/{id}
- POST /feedback
