# Changelog

## Score

- CAI 67 → 70 (+2.8)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 99 → 99 (+0.3)
- Maturity 66 → 66 (+0.0)
- Readiness 58 → 61 (+3.4)
- Security 70 → 79 (+8.4)

## Resolved (6)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no project overview (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)

## New (9)

- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): debug
- Outdated (npm): deep-assign
- Outdated (npm): stats-gl
- Outdated (npm): three
- Outdated (npm): three-bmfont-text
