# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 53 → 56 (+2.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 99 → 99 (+0.1)
- Architecture 100 → 100 (+0.0)
- Maturity 67 → 69 (+2.9)
- Readiness 68 → 68 (+0.0)
- Security 27 → 34 (+6.7)

## Resolved (39)

- Change coupling: Base.kt ↔ ProtoTap.kt (buildSrc/src/main/kotlin/io/spine/dependency/local/Base.kt)
- Change coupling: Base.kt ↔ ToolBase.kt (buildSrc/src/main/kotlin/io/spine/dependency/local/Base.kt)
- Change coupling: DefaultSystemWriteSide.java ↔ NoOpSystemWriteSide.java (server/src/main/java/io/spine/system/server/DefaultSystemWriteSide.java)
- Change coupling: DefaultSystemWriteSide.java ↔ TenantAwareSystemWriteSide.java (server/src/main/java/io/spine/system/server/DefaultSystemWriteSide.java)
- Change coupling: NoOpSystemWriteSide.java ↔ TenantAwareSystemWriteSide.java (server/src/main/java/io/spine/system/server/NoOpSystemWriteSide.java)
- Change coupling: SubscriptionService.java ↔ SubscriptionRegistry.java (server/src/main/java/io/spine/server/SubscriptionService.java)
- Dependency hygiene not measured — no supported dependency manifest was read
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 19 more

## New (38)

- Change coupling: BaseTypes.kt ↔ CoreJvm.kt (buildSrc/src/main/kotlin/io/spine/dependency/local/BaseTypes.kt)
- Change coupling: BaseTypes.kt ↔ Time.kt (buildSrc/src/main/kotlin/io/spine/dependency/local/BaseTypes.kt)
- Change coupling: BaseTypes.kt ↔ Validation.kt (buildSrc/src/main/kotlin/io/spine/dependency/local/BaseTypes.kt)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 18 more

## Changes since last survey

- 98 commits — 95 feature/other, 3 fixes

## By area

- server/src — 56 commits
- (repo) — 12 commits
- docs/dependencies — 8 commits
- (root) — 7 commits
- .agents/memory — 3 commits
- client/src — 3 commits
- core/src — 3 commits
- .agents/tasks — 2 commits
- buildSrc/src — 2 commits
- .idea/inspectionProfiles — 1 commit
- server/build.gradle.kts — 1 commit

## Notable commits

- fix: Annotate fields and fix deprecation message
- fix: Fix the article in Javadoc
- fix: Remove reference to the fixed IDEA issue
- change: Add team-memory note: avoid Javadoc/KDoc-only imports
- change: Address ErrorProne warnings
- change: Address ErrorProne warnings
- change: Address ErrorProne warnings
- change: Address Kotlin compiler warning
- change: Address pre-PR review findings
- change: Address the PR review comments on visibility and docs
- change: Address the pre-PR review findings
- change: Apply the review feedback to the docs and the registration order
- change: Archive done task
- change: Assert the `deleted` flag in the aggregate lookup test
- change: Assert the exception message in `DefaultRepositorySpec`
- change: Auto-update of default inspections by IDEA
- change: Build complete messages with the Protobuf Kotlin DSL
- change: Bump version -> `2.0.0-SNAPSHOT.503`
- change: Bump version -> `2.0.0-SNAPSHOT.504`
- change: Bump version -> `2.0.0-SNAPSHOT.510`
- …and 78 more
