# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 69 → 78 (+8.9)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 89 → 89 (-0.1)
- Architecture 99 → 95 (-3.6)
- Maturity 85 → 89 (+3.3)
- Readiness 79 → 71 (-7.8)
- Security 50 → 74 (+23.7)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (35)

- Base-context workflow trigger runs with an unscoped token
- Change coupling: chrono.rs ↔ jiff.rs (src/conversions/chrono.rs)
- Change coupling: chrono.rs ↔ time.rs (src/conversions/chrono.rs)
- Decision is a bare "drop" with no context/problem and no consequences/trade-offs (newsfragments/6128.packaging.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (12 lines × 2) (src/internal_tricks.rs)
- Duplicated block (6 lines × 2) (pyo3-ffi-check/src/main.rs)
- FixmeComment (tests/test_gc.rs)
- Fork-triggerable workflow runs with an unscoped write token
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: pyo3-build-config/src/impl_.rs (pyo3-build-config/src/impl_.rs)
- Hotspot: pyo3-macros-backend/src/pyfunction/signature.rs (pyo3-macros-backend/src/pyfunction/signature.rs)
- Hotspot: pyo3-macros-backend/src/pymethod.rs (pyo3-macros-backend/src/pymethod.rs)
- Hotspot: src/buffer.rs (src/buffer.rs)
- Hotspot: src/err/impls.rs (src/err/impls.rs)
- …and 15 more

## New (57)

- Boundary-crossing change coupling: lib.rs ↔ macros.rs (pyo3-ffi-check/macro/src/lib.rs)
- Change coupling: anyhow.rs ↔ eyre.rs (src/conversions/anyhow.rs)
- Decision is a bare "drop support for Python 3.8." with no context/problem and no consequences/trade-offs (newsfragments/6128.packaging.md)
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicated block (16–21 lines × 2) (noxfile.py)
- Duplicated block (6 lines × 2) (pyo3-ffi-check/macro/src/lib.rs)
- Duplicated block (6 lines × 2) (pyo3-ffi-check/src/main.rs)
- Duplicated block (9–10 lines × 5) (examples/decorator/noxfile.py)
- FileTooLong: src/stubs.rs (pyo3-introspection/src/stubs.rs)
- FixmeComment (pyo3-ffi/build.rs)
- FixmeComment (tests/test_gc.rs)
- FixmeComment (tests/test_gc.rs)
- High vulnerability: [GHSA redacted] (.github/tools/netlify/package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: noxfile.py (noxfile.py)
- Medium CVE: PYSEC-2026-2132 (uv.lock)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (examples/decorator/noxfile.py)
- Naming inconsistency for context attachment methods. 'context' implies a static string or simple value, while 'with_context' implies a lazy evaluation (closure). In many Rust error handling libraries (like this one appears to be, given the `Error`/`ErrorReport` types), these are often unified under a single name (e.g., `with_context` or `context`) with overloads or distinct parameter types, or clearly distinguished by prefix (e.g., `context_static` vs `context_lazy`). Here, the verb 'with' is inconsistently applied.
- No context/problem (which Python versions the bug affects) and no consequences/trade-offs; only a one-line decision with no rationale (newsfragments/6410.fixed.2.md)
- …and 37 more

## Changes since last survey

- 37 commits — 30 feature/other, 7 fixes

## By area

- (root) — 6 commits
- pyo3-ffi/src — 6 commits
- src/conversions — 3 commits
- pytests/tests — 2 commits
- src/buffer.rs — 2 commits
- tests/ui — 2 commits
- .github/tools — 1 commit
- .github/workflows — 1 commit
- newsfragments/6382.added.md — 1 commit
- newsfragments/6404.fixed.md — 1 commit
- newsfragments/6412.added.md — 1 commit
- newsfragments/6420.fixed.md — 1 commit
- newsfragments/6424.fixed.md — 1 commit
- newsfragments/6425.fixed.md — 1 commit
- newsfragments/6446.changed.md — 1 commit
- newsfragments/6450.fixed.md — 1 commit
- pyo3-macros-backend/src — 1 commit
- pytests/noxfile.py — 1 commit
- pytests/stubs — 1 commit
- src/impl_ — 1 commit

## Notable commits

- fix: fix FFI cases where PyPy replaced function with macro (#6422)
- fix: fix `#[pyfunction]` being marked `METH_STATIC` (#6428)
- fix: fix `jiff::Zoned` extraction for nonexistent datetimes in transition gap (#6450)
- fix: fix crash with GC during attribute initialization (#6453)
- fix: fix new contiguous-slice accessor (#6409)
- fix: fix raw-dylib opt-out on windows x86 (#6410)
- fix: fix reference to type being borrowed inside `#[classmethod]` dunder methods (#6420)
- change: Add `DuringGC` FFI bindings for 3.15 (#6419)
- change: Add batched positional-only call benchmarks (#6447)
- change: Always use `PyDeltaAccess` in `conversions/std/time.rs` (#6461)
- change: Introspection: collect the names used in default values and attribute values (#6425)
- change: Introspection: keep the local binding named like the root module (#6424)
- change: Introspection: use `SupportsGetItem`/`SupportsLenAndGetItem` instead of `Sequence` (#6413)
- change: Introspection: use `SupportsIndex` and `SupportsFloat` for `int` and `float` input (#6396)
- change: Make datetime `Access` traits available on abi3 (#6452)
- change: Record successful attach only after attaching in SuspendAttach (#6404)
- change: add pypy3.12 dll to pyo3-ffi list (#6429)
- change: add slice-ptr accessors to PyBuffer (#6382)
- change: bump GraalPy versions tested in CI, test graalpy on windows (#6406)
- change: bump MSRV to 1.85 (#6459)
- …and 17 more
