# Changelog

## Score

- CAI 35 → 36 (+0.3)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 82 → 82 (+0.2)
- Architecture 69 → 69 (+0.0)
- Maturity 49 → 49 (+0.0)
- Readiness 25 → 26 (+0.7)
- Security 29 → 29 (+0.0)
- Domain Modelling 60 → 60 (+0.0)

## Resolved (11)

- High CVE: Microsoft.AspNetCore.Identity 2.0.2
- High CVE: Microsoft.AspNetCore.Identity 2.0.2
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- LLM evaluation failed
- Medium CVE: Microsoft.AspNetCore.All 2.0.7
- Medium CVE: Microsoft.AspNetCore.All 2.0.7
- Medium CVE: System.Net.Security 4.3.0
- Medium CVE: System.Net.Security 4.3.0

## New (12)

- High CVE: Microsoft.AspNetCore.Identity 2.0.2
- High CVE: Microsoft.AspNetCore.Identity 2.0.2
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- Medium CVE: Microsoft.AspNetCore.All 2.0.7
- Medium CVE: Microsoft.AspNetCore.All 2.0.7
- Medium CVE: System.Net.Security 4.3.0
- Medium CVE: System.Net.Security 4.3.0
- The Getting Started section describes registration options but does not explain how to register command/event handlers with the hosted-command/event-handler abstraction. (README.md)
- redundant comment (Samples/AspNetCore/Startup/StartupWithAttributeRegistration.cs)

## API surface

- Unchanged — 4 HTTP endpoints

## Architecture

- Unchanged — 0 containers · 1 contexts · 0 edges
