# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 57 → 58 (+1.2)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 84 → 86 (+1.6)
- Architecture 81 → 81 (+0.0)
- Maturity 63 → 63 (+0.0)
- Readiness 42 → 42 (+0.0)
- Security 70 → 78 (+8.0)

## Resolved (4)

- High: security finding (details withheld)
- High: security finding (details withheld)
- The 'Get started' section describes only how to run the application (docker compose up) without explaining what each of the three services does or where to find the API endpoints. (README.md)
- redundant comment (src/WebApi/Program.cs)

## New (5)

- High: security finding (details withheld)
- High: security finding (details withheld)
- redundant comment (src/WebApi/Program.cs)
- redundant comment (src/WebApi/Program.cs)
- redundant comment (tests/Application.Tests/EducationServiceTests.cs)

## API surface

- Unchanged — 5 HTTP endpoints
