# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 58 → 61 (+2.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 92 → 95 (+2.8)
- Architecture 100 → 100 (+0.0)
- Maturity 50 → 39 (-11.3)
- Readiness 47 → 64 (+17.4)
- Security 80 → 100 (+20.3)

## Resolved (12)

- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No automated tests
- No exposed public API
- No tests found
- Test reliability not included
- TooManyMethods: wa_raft_log (src/wa_raft_log.erl)
- TooManyMethods: wa_raft_server (src/wa_raft_server.erl)
- TooManyMethods: wa_raft_transport (src/wa_raft_transport.erl)
- complexity unreadable for .erl, .hrl — churn × complexity hotspots could not be measured

## New (19)

- Coverage not measured — no coverage collector is wired up
- Dependency hygiene PARTLY measured — rebar3 pinning read, dependency currency not (no rebar.lock-pinned Hex declaration to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (5 lines × 7) (src/wa_raft_acceptor.erl)
- Duplicated block (8 lines × 2) (src/wa_raft_log.erl)
- Duplicated block (8 lines × 2) (src/wa_raft_snapshot_catchup.erl)
- Duplicated block (8 lines × 4) (src/wa_raft_acceptor.erl)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/wa_raft_server.erl (src/wa_raft_server.erl)
- TodoComment (src/wa_raft_server.erl)
- TodoComment (src/wa_raft_server.erl)
- TodoComment (test/wa_raft_server_SUITE.erl)
- TodoComment (test/wa_raft_server_SUITE.erl)
- Workflow token permissions not restricted
- wa_raft_server.leader_adjust_config (cognitive 30) (src/wa_raft_server.erl)
- wa_raft_server.leader_adjust_config (cyclomatic 36) (src/wa_raft_server.erl)

## Changes since last survey

- 15 commits — 15 feature/other, 0 fixes

## By area

- (root) — 4 commits
- include/wa_raft.hrl — 3 commits
- src/wa_raft_server.erl — 3 commits
- src/wa_raft.erl — 1 commit
- src/wa_raft_dist_transport.erl — 1 commit
- src/wa_raft_label.erl — 1 commit
- src/wa_raft_log.erl — 1 commit
- src/wa_raft_log_ets.erl — 1 commit

## Notable commits

- change: Cap witness log replication at the max match index
- change: Clean up label type documentation
- change: Compute witness replication cap over full members only
- change: Fix README typo
- change: Include non-member participants in log trim index
- change: Make tests publishable to WhatsApp/waraft
- change: Make the durably-applied trim limit a storage provider callback
- change: Normalize Erlang module headers
- change: Precheck follower capacity before creating a snapshot
- change: Raise overloaded snapshot catchup backoff to 10s
- change: Re-sync with internal repository (#12)
- change: Refresh README for current architecture
- change: Simplify ETS reads
- change: Split last_quorum_ts into leader-quorum and commit-index timestamps
- change: Track transport/file progress with atomics instead of ETS read-modify-write
