# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 46 → 49 (+2.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 87 → 87 (+0.0)
- Architecture 97 → 96 (-1.0)
- Maturity 59 → 62 (+3.9)
- Readiness 39 → 39 (+0.3)
- Security 41 → 51 (+10.1)
- Event Sourcing 49 → 49 (+0.0)
- Performance 94 (new)

## Resolved (20)

- Change coupling: prover.rs ↔ worker.rs (node/bft/ledger-service/src/prover.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (12 lines × 2) (node/src/client/mod.rs)
- Duplicated block (12–13 lines × 2) (node/src/client/mod.rs)
- Duplicated block (16 lines × 2) (node/src/client/mod.rs)
- Duplicated block (6 lines × 3) (node/bft/src/primary.rs)
- High: security finding (details withheld)
- Hotspot: node/bft/events/src/lib.rs (node/bft/events/src/lib.rs)
- Hotspot: node/bft/src/sync/mod.rs (node/bft/src/sync/mod.rs)
- Hotspot: node/router/messages/src/lib.rs (node/router/messages/src/lib.rs)
- Hotspot: node/sync/src/block_sync.rs (node/sync/src/block_sync.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (node/bft/src/gateway.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (node/rest/src/routes.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- TodoComment (node/rest/src/lib.rs)
- TodoComment (node/rest/src/routes.rs)
- TodoComment (node/rest/src/routes.rs)
- calculateAverageBlockTime (cognitive 18) (.devnet/.analytics/analytics.js)

## New (35)

- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Documentation: no installation or build instructions (node/sync/locators/README.md)
- Documentation: no usage examples (node/sync/locators/README.md)
- Duplicate function signatures with different parameter names (one named 'path', one '_path'). This suggests an overload or a copy-paste error in the API surface, which is confusing for consumers.
- Duplicated block (13 lines × 2) (cli/src/commands/developer/deploy.rs)
- Duplicated block (13 lines × 2) (node/src/client/mod.rs)
- Duplicated block (16–17 lines × 2) (node/consensus/src/lib.rs)
- Duplicated block (18 lines × 2) (node/src/client/mod.rs)
- Duplicated block (5 lines × 2) (node/bft/src/gateway.rs)
- End-of-life runtime: Rust 1.96
- High: security finding (details withheld)
- Hotspot: cli/src/commands/start.rs (cli/src/commands/start.rs)
- Inconsistent naming convention for data type variants. 'sign_bytes' uses the type name, while 'sign_bits' uses the pluralized type name. 'sign' is ambiguous as it takes a generic Field array but lacks a suffix.
- Inconsistent return types for 'contains' operations. 'Storage' returns a boolean, while 'LedgerService' returns a Result. This forces callers to handle errors differently for similar existence checks.
- Low cohesion: Client (LCOM4 4) (node/src/client/mod.rs)
- Low cohesion: Gateway (LCOM4 4) (node/bft/src/gateway.rs)
- Low cohesion: MockLedgerService (LCOM4 7) (node/bft/ledger-service/src/mock.rs)
- Low cohesion: Prover (LCOM4 4) (node/src/prover/mod.rs)
- Low cohesion: Storage (LCOM4 6) (node/bft/src/helpers/storage.rs)
- Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
- …and 15 more

## Changes since last survey

- 86 commits — 70 feature/other, 16 fixes

## By area

- (repo) — 29 commits
- node/bft — 19 commits
- node/rest — 11 commits
- (root) — 9 commits
- node/metrics — 7 commits
- .circleci/config.yml — 4 commits
- cli/src — 2 commits
- .devnet/.analytics — 1 commit
- node/consensus — 1 commit
- node/router — 1 commit
- node/src — 1 commit
- node/sync — 1 commit

## Notable commits

- fix: Converted several untracked tokio tasks to tracked ones. This is from a pre-existing issue. There were several tokio tasks and were spawned and never had any way of being shutdown. The current method of handling this is that we have some Vec<JoinHandle>s that we then use to shutdown all tasks when we shutdown the node. There's also a check that waits for 1s (arbitrary value) after the shutdown signal and then just checks for the number of live tasks, if it's more than 1 it errors. The problem is that these untracked tasks would stay alive (since they never got any shutdown signal) for a little longer than 1s and cause the error. Given that there exist JoinSets and CancellationTokens, this is a weird way of handling shutdowns, but it's way outside the scope of this PR to fix this.
- fix: Fix overzealous error logging. It would make the merge devnet workflow fail, even though all nodes were successful (test requires no error logs). This is a reasonable solution since what was happenning was not a real error, we have the exact same pattern a few lines below.
- fix: Merge pull request #4472 from ProvableHQ/fix/rest-forward-retry-after
- fix: Merge pull request #4478 from ProvableHQ/fix/cli-static-query
- fix: devnet.sh small fixes. It's running.
- fix: fix backoff
- fix: fix certificate storage race
- fix: fix gc round update race. Not an actual bug, but would cause unnecessary error logging.
- fix: fix out of date dependency
- fix: fix storage logging
- fix: fix storage round update race
- fix: fix wrong logging at bft.rs
- fix: fix(cli): accept static queries on developer endpoints
- fix: fix(rest): compat routes always ask the upstream; the node's own height plays no part
- fix: fix(rest): forward the rate limiter's retry-after header on a 429
- fix: fixed concurrent updates test. it was not sound.
- change: Allow operators to limit REST verification concurrency at startup.
- change: Check the full feature graph in cargo-deny.
- change: Clean stale JoinHandles when you spawn new tasks.
- change: Enable extended CI
- …and 66 more
