# Changelog

## Score

- CAI 64 → 67 (+3.5)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 97 → 97 (-0.1)
- Architecture 100 → 99 (-0.7)
- Maturity 55 → 56 (+0.3)
- Readiness 67 → 69 (+1.7)
- Security 62 → 73 (+10.9)
- Performance 100 (new)

## Resolved (2)

- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2

## New (12)

- Duplicated block (16 lines × 2) (graphql-dgs-example-shared/src/main/java/com/netflix/graphql/dgs/example/shared/datafetcher/ConcurrentDataFetcher.java)
- Duplicated block (35 lines × 2) (graphql-dgs-example-shared/src/main/java/com/netflix/graphql/dgs/example/shared/dataLoader/MessageDataLoader.java)
- Duplicated block (6 lines × 2) (graphql-dgs-spring-graphql-example-java-webflux/src/main/java/com/netflix/graphql/dgs/example/reactive/ReactiveSpringGraphQLExampleApp.java)
- Flaky test: com.netflix.graphql.dgs.metrics.micrometer.MicrometerServletSmokeTest.Assert metrics for a successful async response with errors()
- Further sole-owners (lower concentration)
- Inconsistent identification of DataLoaders. `getDataLoader` takes a `Class` type, while instrumentation and options providers often rely on a `String` name. This creates a dual-identity problem for DataLoaders (by Class vs by Name), which can lead to bugs if the name generated does not match the class name or if users mix these approaches.
- Inconsistent method naming for the primary execution operation across client types. Synchronous clients use `executeQuery`, while reactive clients use `reactiveExecuteQuery`. This forces developers to remember different method names based on the return type (blocking vs reactive), rather than a unified interface.
- Inconsistent parameter naming for the executor in overloaded methods. The synchronous `GraphQLClient` interface uses `requestExecutor`, while the reactive `MonoGraphQLClient` interface uses `requestExecutor` as well, but the types differ (`RequestExecutor` vs `MonoRequestExecutor`). More critically, the synchronous interface has an overload with `requestExecutor` but the reactive one does not have a direct equivalent overload structure in the same way, leading to confusion about which executor type to pass when implementing custom clients.
- Low cohesion: DgsGraphQLSourceBuilder (LCOM4 4) (graphql-dgs-spring-graphql/src/main/kotlin/com/netflix/graphql/dgs/springgraphql/DgsGraphQLSourceBuilder.kt)
- No ADRs found
- Off the main sequence: :graphql-dgs-subscription-types
- Off-boarding risk: anonymized user #1

## Changes since last survey

- 4 commits — 4 feature/other, 0 fixes

## By area

- (repo) — 2 commits
- (root) — 1 commit
- graphql-dgs-extended-scalars/src — 1 commit

## Notable commits

- change: Bump org.slf4j:slf4j-api from 2.0.18 to 2.0.19
- change: Merge pull request #2348 from voidstackloop/feature/extended-scalars-24
- change: Merge pull request #2349 from Netflix/dependabot/gradle/org.slf4j-slf4j-api-2.0.19
- change: feat(extended-scalars): bump graphql-java-extended-scalars to 24.0 and register new scalars

## Architecture

- Containers 0 added · 0 removed · contexts 8 added · 1 removed · edges 5 added · 0 removed

## Added bounded contexts (8)

- graphql-dgs
- graphql-dgs-client
- graphql-dgs-reactive
- graphql-dgs-spring-boot-micrometer
- graphql-dgs-spring-graphql
- graphql-dgs-spring-graphql-example-java
- graphql-dgs-spring-graphql-example-java-webflux
- graphql-dgs-subscription-types

## Removed bounded contexts (1)

- .

## Added dependency edges (5)

- graphql-dgs-client → graphql-dgs-subscription-types (coupling)
- graphql-dgs-reactive → graphql-dgs
- graphql-dgs-spring-boot-micrometer → graphql-dgs
- graphql-dgs-spring-graphql → graphql-dgs (coupling)
- graphql-dgs-spring-graphql → graphql-dgs-reactive
