# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 43 → 59 (+16.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 72 → 71 (-0.7)
- Architecture 97 → 96 (-0.2)
- Maturity 62 → 69 (+6.9)
- Readiness 14 → 80 (+66.0)
- Security 70 → 71 (+1.0)
- Accessibility 44 (new)

## Resolved (20)

- Dimension evaluation failed
- Duplicated block (18 lines × 2) (bin/spec/options/option.py)
- Leaked secret: private-key (integration/hurl/tests_ssl/certs/ca/key.pem)
- Leaked secret: private-key (integration/hurl/tests_ssl/certs/client/key.pem)
- Leaked secret: private-key (integration/hurl/tests_ssl/certs/server/key.pem)
- Low IaC: DS-0026 (contrib/docker/Dockerfile)
- No SBOM
- No artifact signing
- No automated tests
- No exposed public API
- No tests found
- Secret: private-key (integration/hurl/tests_ssl/certs/ca/key.pem)
- Secret: private-key (integration/hurl/tests_ssl/certs/ca/key.pem)
- Secret: private-key (integration/hurl/tests_ssl/certs/client/encrypted.key.pem)
- Secret: private-key (integration/hurl/tests_ssl/certs/client/key.pem)
- Secret: private-key (integration/hurl/tests_ssl/certs/client/key.pem)
- Secret: private-key (integration/hurl/tests_ssl/certs/server/key.pem)
- Secret: private-key (integration/hurl/tests_ssl/certs/server/key.pem)
- Test reliability not included
- The What's Hurl? section mentions curl but does not state which CLI tools or libraries Hurl depends on (e.g., Rust/Python). (README.md)

## New (62)

- CI runs a third-party container image from a mutable tag (.github/workflows/check.yml)
- Coverage not measured — no coverage collector is wired up
- Duplicated block (6 lines × 3) (integration/hurl/tests_failed/runner_errors/runner_errors.py)
- Duplicated block (6 lines × 7) (integration/hurl/tests_failed/assert_bytearray/assert_bytearray.py)
- Duplicated block (9 lines × 6) (integration/hurl/tests_ok/compressed/compressed.py)
- FixmeComment (contrib/sample/src/main.rs)
- High CVE: [GHSA redacted] (contrib/npm/hurl/package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: packages/hurl/src/cli/options/config_file/mod.rs (packages/hurl/src/cli/options/config_file/mod.rs)
- Hotspot: packages/hurl/src/http/client.rs (packages/hurl/src/http/client.rs)
- Hotspot: packages/hurl/src/http/curl_cmd.rs (packages/hurl/src/http/curl_cmd.rs)
- Hotspot: packages/hurl/src/runner/options.rs (packages/hurl/src/runner/options.rs)
- …and 42 more

## Changes since last survey

- 97 commits — 88 feature/other, 9 fixes

## By area

- (root) — 33 commits
- packages/hurl — 18 commits
- integration/hurl — 17 commits
- .github/workflows — 13 commits
- docs/spec — 8 commits
- art/branding.md — 1 commit
- bin/install_prerequisites_windows.ps1 — 1 commit
- contrib/sublime-text — 1 commit
- docs/asserting-response.md — 1 commit
- docs/filters.md — 1 commit
- docs/grammar.md — 1 commit
- docs/installation.md — 1 commit
- docs/manual — 1 commit

## Notable commits

- fix: Fix CodeQL access on invalid pointer warnings.
- fix: Fix XSS: HTML escape all debug tables values (headers, captures etc...)
- fix: Fix credentials leaking using --header and following redirection.
- fix: Fix hurl.dev ssl integration test.
- fix: Fix integration test for cookie value on curl 8.22 due to <https://github.com/curl/curl/pull/22730>
- fix: Fix libcurl-8.18 downgrade on Windows vcpkg
- fix: Fix output_type configuration.
- fix: Fix symlinks escaping file root.
- fix: Minor typo fix to test the CodeQL config file.
- change: Add CodeQL analysis configuration file.
- change: Add Sublime Text syntax highlighting
- change: Add Validation step for workflow_call input branch in package.yml
- change: Add deprecation notice for `decode` in filters page
- change: Add integ test for assert body JSON
- change: Add integration test for no-proxy option
- change: Add integration test for proxy_header option
- change: Add max_filesize option in config file
- change: Add more unit tests.
- change: Add no_pretty option in config_file
- change: Add no_proxy option in config_file
- …and 77 more
