# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 67 → 68 (+1.0)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 71 → 71 (+0.6)
- Architecture 97 → 95 (-2.0)
- Maturity 76 → 78 (+2.5)
- Readiness 60 → 60 (+0.0)
- Security 68 → 71 (+3.1)
- Domain Modelling 100 → 100 (+0.0)
- Event-Driven 80 → 80 (+0.0)
- Event Sourcing 100 → 100 (+0.0)

## Resolved (39)

- BenchmarkReporter.print_summary (cognitive 16) (src/application/benchmarking/reporting.rs)
- Change coupling: analyst.rs ↔ sector_exposure_validator.rs (src/application/agents/analyst.rs)
- Change coupling: analyst.rs ↔ strategy_factory.rs (src/application/agents/analyst.rs)
- Change coupling: analyst.rs ↔ validator_trait.rs (src/application/agents/analyst.rs)
- Change coupling: circuit_breaker_validator.rs ↔ sector_exposure_validator.rs (src/domain/risk/filters/circuit_breaker_validator.rs)
- Change coupling: repositories.rs ↔ database.rs (src/domain/repositories.rs)
- Change coupling: sentinel.rs ↔ ui.rs (src/application/agents/sentinel.rs)
- Dependency hygiene not measured — no supported dependency manifest was read
- Executor.handle_order (cyclomatic 17) (src/application/agents/executor.rs)
- Further orphaned files (smaller)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 19 more

## New (35)

- Change coupling: analyst.rs ↔ websocket.rs (src/application/agents/analyst.rs)
- Change coupling: database.rs ↔ mod.rs (src/infrastructure/persistence/database.rs)
- Change coupling: metrics.rs ↔ portfolio.rs (src/domain/performance/metrics.rs)
- Change coupling: mod.rs ↔ database.rs (src/application/system/mod.rs)
- Change coupling: risk_manager.rs ↔ database.rs (src/application/risk_management/core/risk_manager.rs)
- Change coupling: scanner.rs ↔ mod.rs (src/application/agents/scanner.rs)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: dashboard_components/architecture_view.rs (src/interfaces/dashboard_components/architecture_view.rs)
- High CVE: [GHSA redacted] (Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 15 more
