# Changelog

## Score

- CAI 54 → 57 (+3.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 69 → 98 (+29.1)
- Maturity 64 → 63 (-0.7)
- Readiness 35 → 35 (+0.0)
- Security 90 → 98 (+7.9)
- Accessibility 70 → 70 (+0.0)
- Performance 100 (new)

## Resolved (7)

- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)

## New (3)

- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Low vulnerability: [GHSA redacted] (pnpm-lock.yaml)
- Medium vulnerability: [GHSA redacted] (pnpm-lock.yaml)

## Changes since last survey

- 10 commits — 9 feature/other, 1 fixes

## By area

- (repo) — 3 commits
- docs/java — 2 commits
- (root) — 1 commit
- docs/database — 1 commit
- docs/distributed-system — 1 commit
- docs/system-design — 1 commit
- docs/zhuanlan — 1 commit

## Notable commits

- fix: fix(deps): patch dependency security vulnerabilities
- change: Correct method signature spacing in MethodInterceptor
- change: Merge pull request #2915 from dajiaohuang/docs/2914-mcp-2026-07-28
- change: Merge pull request #2917 from Snailclimb/codex/dependency-security-20260919
- change: Merge pull request #2920 from qcsmallblack/patch-1
- change: docs(distributed-system): rework distributed lock motivation with multi-instance scenario
- change: docs(mysql): add missing exclusive-lock comment for SELECT ... FOR UPDATE
- change: docs(system-design): add state machine/workflow guide and Spring Boot executable JAR article
- change: docs(zhuanlan): update Spring AI interview project overview
- change: docs: strengthen cache consistency, ZGC, Java 17/21 and data migration content
