# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 48 → 52 (+4.4)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 99 → 95 (-3.6)
- Architecture 100 → 69 (-31.0)
- Maturity 35 → 47 (+12.2)
- Readiness 26 → 37 (+11.7)
- Security 93 → 91 (-1.7)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (10)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (10 lines × 2) (pkg/infrastructure/persistence/entdb/term_ent_repository.go)
- Duplicated block (12 lines × 2) (pkg/infrastructure/searcher/searcher.go)
- Duplicated block (13 lines × 2) (cmd/seeds/eng/seed.go)
- No exposed public API
- Test reliability not included
- The README begins an 'Start Application' section and ends in a demo/Demo block but does not yet describe how to run the engine locally or access the API. (README.md)
- complexity unreadable for .go — churn × complexity hotspots could not be measured
- dormant codebase — no living knowledge left to concentrate

## New (29)

- Dependency pinned to a stale untagged commit: golang.org/x/sync
- Duplicated block (25 lines × 2) (pkg/infrastructure/searcher/searcher.go)
- Duplicated block (28 lines × 2) (cmd/seeds/eng/seed.go)
- Duplicated block (9 lines × 2) (pkg/infrastructure/persistence/entdb/term_ent_repository.go)
- High CVE: [GHSA redacted] (go.mod)
- Hotspot: pkg/infrastructure/searcher/searcher.go (pkg/infrastructure/searcher/searcher.go)
- Indexer.IndexingDocument (cognitive 19) (pkg/infrastructure/indexer/indexer.go)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2023-1568 (go.mod)
- Medium CVE: GO-2026-6179 (go.mod)
- Medium IaC: CKV_DOCKER_9 (docker/db/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (docker/api/Dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No ADRs found
- Outdated: entgo.io/ent
- Outdated: github.com/go-chi/chi/v5
- Outdated: github.com/go-sql-driver/mysql
- Outdated: github.com/google/uuid
- Outdated: github.com/ikawaha/kagome-dict/ipa
- …and 9 more
