# Changelog

## Score

- CAI 40 → 43 (+3.4)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 63 → 65 (+1.3)
- Architecture 87 → 87 (+0.0)
- Maturity 43 → 43 (+0.0)
- Readiness 18 → 25 (+7.0)
- Security 75 → 75 (+0.0)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (13)

- Critical CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-server/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-react/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-react/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Medium vulnerability: [GHSA redacted] (time-writer-server/package-lock.json)
- No automated tests
- No tests found
- There is no architecture/design documentation for the system, so readers cannot tell whether event sourcing is implemented as a separate module or integrated into the UI.

## New (11)

- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Critical CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Critical CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-react/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-server/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-react/package-lock.json)
- High CVE: [GHSA redacted] (time-writer-client/package-lock.json)
- Medium CVE: [GHSA redacted] (time-writer-server/package-lock.json)
