# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 43 → 35 (-8.8)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 67 → 100 (+32.9)
- Maturity 60 → 79 (+18.9)
- Readiness 32 → 17 (-15.0)
- Security 39 → 22 (-16.7)

## Resolved (364)

- AO3Bridge.collectList (cognitive 25) (bridges/AO3Bridge.php)
- AO3Bridge.collectList (cyclomatic 16) (bridges/AO3Bridge.php)
- AnidexBridge.collectData (cognitive 53) (bridges/AnidexBridge.php)
- AnidexBridge.collectData (cyclomatic 27) (bridges/AnidexBridge.php)
- AnimeUltimeBridge.collectData (cognitive 21) (bridges/AnimeUltimeBridge.php)
- AnnasArchiveBridge.collectData (cognitive 18) (bridges/AnnasArchiveBridge.php)
- ArsTechnicaBridge.parseItem (cognitive 25) (bridges/ArsTechnicaBridge.php)
- AssociatedPressNewsBridge.collectData (cognitive 47) (bridges/AssociatedPressNewsBridge.php)
- AssociatedPressNewsBridge.collectData (cyclomatic 24) (bridges/AssociatedPressNewsBridge.php)
- AssociatedPressNewsBridge.collectPageData (cognitive 27) (bridges/AssociatedPressNewsBridge.php)
- AtomFormat.render (cognitive 44) (formats/AtomFormat.php)
- AtomFormat.render (cyclomatic 25) (formats/AtomFormat.php)
- BAEBridge.collectData (cognitive 16) (bridges/BAEBridge.php)
- BMDSystemhausBlogBridge.collectData (cognitive 17) (bridges/BMDSystemhausBlogBridge.php)
- BMDSystemhausBlogBridge.detectParameters (cognitive 32) (bridges/BMDSystemhausBlogBridge.php)
- BadDragonBridge.collectData (cognitive 66) (bridges/BadDragonBridge.php)
- BadDragonBridge.collectData (cyclomatic 27) (bridges/BadDragonBridge.php)
- BadDragonBridge.detectParameters (cognitive 22) (bridges/BadDragonBridge.php)
- BadDragonBridge.detectParameters (cyclomatic 17) (bridges/BadDragonBridge.php)
- BadDragonBridge.inputToURL (cognitive 34) (bridges/BadDragonBridge.php)
- …and 344 more

## New (32)

- Context/problem and consequences/trade-offs are absent (only four-steps process description with no problem framing) (docs/05_Bridge_API/02_BridgeAbstract.md)
- Coverage not measured — test suite did not build
- Decision is a one-line removal with no context (why caching was removed) and no consequences/trade-offs (docs/04_For_Developers/05_Debug_mode.md)
- Dimension evaluation failed
- High IaC: DS-0002 (.devcontainer/Dockerfile)
- High IaC: DS-0029 (.devcontainer/Dockerfile)
- High: security finding (details withheld)
- Low IaC: DS-0026 (.devcontainer/Dockerfile)
- Medium IaC: DS-0001 (.devcontainer/Dockerfile)
- No consequences/trade-offs section describing the cost of running a bridge ecosystem (e.g. maintenance burden, API integration effort) and what happens if bridges break (docs/01_General/01_Project-goals.md)
- No context/problem (why a development environment setup) and no consequences/trade-offs (docs/04_For_Developers/07_Development_Environment_Setup.md)
- No context/problem and no consequences/trade-offs; only a bare listing of folders with links are present (docs/04_For_Developers/03_Folder_structure.md)
- No context/problem and no consequences/trade-offs; only a one-line file-creation instruction with an example (docs/07_Cache_API/01_How_to_create_a_new_cache.md)
- No context/problem and no consequences/trade-offs; only the interface declaration is shown (docs/07_Cache_API/02_CacheInterface.md)
- No context/problem and no consequences/trade-offs; only the title "02_Updating" is informative (docs/03_For_Hosts/02_Updating.md)
- No context/problem and no consequences/trade-offs; the body is a bare configuration dump with only enable/disable examples (docs/03_For_Hosts/05_Whitelisting.md)
- No context/problem and no consequences/trade-offs; the body is a boilerplate code example with only one line of rationale (docs/05_Bridge_API/01_How_to_create_a_new_bridge.md)
- No context/problem and no consequences; only a bare list of auth types with a documentation link (docs/03_For_Hosts/06_Authentication.md)
- No real context/problem and no explicit decision (which feed types to support, what data to extract) are stated; only boilerplate template present (docs/05_Bridge_API/03_FeedExpander.md)
- No tests found
- …and 12 more

## Changes since last survey

- 5 commits — 4 feature/other, 1 fixes

## By area

- bridges/BlueskyBridge.php — 2 commits
- (root) — 1 commit
- bridges/CaschyBridge.php — 1 commit
- docs/01_General — 1 commit

## Notable commits

- fix: [bluesky] fix #5063 reposts not being excluded (#5065)
- change: Update CaschyBridge.php (#5064)
- change: [docs] Switching domain for em92's instance (#5062)
- change: docs: add Caddy installation instructions (#5052)
- change: incl app.bsky.embed.gallery origin issue #5009 (#5060)
