# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 64 (+3.7)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 83 → 84 (+0.0)
- Architecture 94 → 94 (+0.1)
- Maturity 78 → 75 (-3.2)
- Readiness 65 → 65 (+0.8)
- Security 56 → 79 (+22.5)
- Domain Modelling 74 → 74 (+0.0)
- Performance 55 → 55 (+0.0)

## Resolved (3)

- High: security finding (details withheld)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1

## New (4)

- Duplicated block (16 lines × 2) (src/WebApi/Features/Heroes/CreateHero/CreateHeroRequestValidator.cs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1

## Changes since last survey

- 9 commits — 8 feature/other, 1 fixes

## By area

- (root) — 5 commits
- .claude/skills — 1 commit
- docs/agents — 1 commit
- src/WebApi — 1 commit
- tests/WebApi.ArchitectureTests — 1 commit

## Notable commits

- fix: fix(validation): enforce domain max lengths in request validators (#292)
- change: Bump AwesomeAssertions from 9.3.0 to 9.5.0 (#274)
- change: Bump EntityFrameworkCore.Exceptions.SqlServer from 8.1.3 to 10.0.1 (#266)
- change: Bump Microsoft.AspNetCore.OpenApi from 10.0.0 to 10.0.10 (#275)
- change: Bump Microsoft.EntityFrameworkCore.Design and Microsoft.EntityFrameworkCore.Relational (#276)
- change: Bump Microsoft.EntityFrameworkCore.Relational from 10.0.9 to 10.0.10 (#277)
- change: docs: add agent config and domain glossary (#294)
- change: feat(skills): ship /add-entity and /add-slice scaffolding skills (#296)
- change: test(arch): replace vacuously passing architecture tests (#295)
