# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 72 → 77 (+5.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 82 → 81 (-0.0)
- Architecture 100 → 98 (-2.1)
- Maturity 75 → 75 (+0.1)
- Readiness 80 → 77 (-3.7)
- Security 62 → 74 (+12.1)
- Domain Modelling 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (18)

- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (examples/basic/Readme.md)
- Documentation: no licence statement
- Documentation: no usage examples (examples/basic/Readme.md)
- Duplicated block (24 lines × 2) (sea-orm-sync/src/entity/link.rs)
- Duplicated block (9 lines × 2) (sea-orm-sync/src/entity/column.rs)
- Duplicated block (9 lines × 2) (sea-orm-sync/src/entity/column.rs)
- Edited copy of a member (21 corresponding lines) (sea-orm-sync/src/schema/builder.rs)
- High: security finding (details withheld)
- Hotspot: sea-orm-codegen/src/entity/column.rs (sea-orm-codegen/src/entity/column.rs)
- Hotspot: sea-orm-codegen/src/entity/writer/dense.rs (sea-orm-codegen/src/entity/writer/dense.rs)
- Hotspot: sea-orm-macros/src/derives/active_enum.rs (sea-orm-macros/src/derives/active_enum.rs)
- Hotspot: sea-orm-macros/src/derives/util.rs (sea-orm-macros/src/derives/util.rs)
- Hotspot: sea-orm-sync/src/entity/active_model.rs (sea-orm-sync/src/entity/active_model.rs)
- Hotspot: src/entity/active_model.rs (src/entity/active_model.rs)
- Hotspot: src/error.rs (src/error.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (sea-orm-sync/src/entity/column.rs)
- Off-boarding risk: anonymized user #1

## New (17)

- Confusingly named operations: `from_json` and `set_from_json` likely perform similar JSON deserialization into the model. The distinction is unclear from the signature alone.
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate intent: `execute` and `exec_stmt` appear to be synonyms for executing a SQL statement. Having two methods with different names for the same action is confusing.
- Duplicated block (28 lines × 2) (sea-orm-sync/src/entity/link.rs)
- Duplicated block (5 lines × 2) (sea-orm-sync/src/entity/column.rs)
- Duplicated block (5 lines × 2) (sea-orm-sync/src/entity/column.rs)
- Duplicated block (8 lines × 2) (sea-orm-sync/src/query/select.rs)
- Edited copy of a member (21 corresponding lines) (sea-orm-sync/src/schema/builder.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (sea-orm-sync/src/entity/column.rs)
- Off the main sequence: entity (issues/1599/entity)
- Off the main sequence: sea-orm-codegen
- Off-boarding risk: anonymized user #1
- Redundant/Confusingly named operations: `arrow_array_to_value` and `arrow_array_to_value_alt` have identical signatures and likely perform the same core conversion, with `alt` being a fallback or variant. This creates ambiguity for users on which to use.
- Split sea-orm-sync
- Type duplication: `MigratorTraitSelf` and `MigratorTrait` expose identical method signatures for querying migration status (`get_migration_with_status`, `get_pending_migrations`, `get_applied_migrations`). This suggests one trait is redundant or they are meant to be implemented together but are exposed as separate public types causing confusion.

## Changes since last survey

- 28 commits — 23 feature/other, 5 fixes

## By area

- (root) — 5 commits
- sea-orm-sync/src — 5 commits
- changelog/2.0.4.md — 3 commits
- (repo) — 2 commits
- .github/workflows — 2 commits
- examples/actix_example — 2 commits
- sea-orm-macros/src — 2 commits
- build-tools/RELEASE.md — 1 commit
- changelog/2.0.3.md — 1 commit
- examples/seaography_example — 1 commit
- sea-orm-cli/README.md — 1 commit
- sea-orm-cli/src — 1 commit
- sea-orm-migration/Cargo.toml — 1 commit
- sea-orm-sync/tests — 1 commit

## Notable commits

- fix: Fix 2.0.4 changelog index after #3200 revert
- fix: Fix bump.sh taplo no-op, and document it in RELEASE.md
- fix: Fix left_join_linked joining multi-hop links onto the wrong alias (#3199)
- fix: Fix schema sync failing to drop a stale index on MySQL (#3202)
- fix: Revert "sea-orm-migration: don't depend on stream feature (#3200)"
- change: 2.0.3
- change: 2.0.4
- change: Add `select_except` to select all columns except the given ones (#3211)
- change: Add changelog for 2.0.4
- change: Apply `save_as` cast to `eq_any` / `ne_all` arrays (#3208)
- change: Build the 3 slowest examples as one workspace
- change: Merge pull request #3210 from SeaQL/split-test-common
- change: Merge remote-tracking branch 'origin/master' into split-test-common
- change: Refine SeaORM 2.0.3 release notes
- change: Regenerate sea-orm-sync (`eq_any` / `ne_all` save_as cast)
- change: Respect `condition_type` in linked joins (#3203)
- change: Restore taplo comment alignment after 2.0.3 bump
- change: Restore the #3208 example in the 2.0.4 changelog
- change: Split tests/common so each test binary compiles only the modules it uses
- change: Support `postgres:db_name` URLs in sea-orm-cli entity generation (#3197)
- …and 8 more
