# Changelog

## Score

- CAI 45 → 50 (+5.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 73 → 73 (+0.2)
- Architecture 52 → 48 (-3.4)
- Maturity 69 → 69 (-0.1)
- Readiness 52 → 48 (-4.2)
- Security 63 → 67 (+4.1)
- Accessibility 31 → 45 (+14.1)
- Performance 100 (new)

## Resolved (198)

- Critical CVE: [CVE redacted] (designer/submodules/package-lock.json)
- Critical CVE: [GHSA redacted] (designer/client/package-lock.json)
- Critical CVE: [GHSA redacted] (designer/client/package-lock.json)
- Documentation: no installation or build instructions (README.md)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/submodules/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/submodules/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/submodules/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/submodules/package-lock.json)
- High CVE: [CVE redacted] (designer/client/package-lock.json)
- High CVE: [CVE redacted] (designer/submodules/package-lock.json)
- …and 178 more

## New (86)

- Critical CVE: [GHSA redacted] (designer/client/package-lock.json)
- Critical CVE: [GHSA redacted] (designer/client/package-lock.json)
- Documentation: no project overview (README.md)
- Documentation: no project overview (docs/integrations/openAPI.md)
- Duplicated block (5 lines × 2) (scenario-compiler/src/main/java/pl/touk/nussknacker/engine/spel/SpelReflectionHelper.java)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/client/package-lock.json)
- High CVE: [GHSA redacted] (designer/submodules/package-lock.json)
- …and 66 more

## Changes since last survey

- 3 commits — 1 feature/other, 2 fixes

## By area

- designer/submodules — 1 commit
- engine/flink — 1 commit
- scenario-compiler/src — 1 commit

## Notable commits

- fix: Fix parsing of SpEL template expressions in Variable (#153)
- fix: Fix scenarios failing on a null aggregateBy (#124) (#9472)
- change: Show two component links as icons without a menu (#9467)
