# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 55 → 59 (+3.8)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

## Lenses

- Code Health 89 → 92 (+2.6)
- Architecture 88 → 92 (+3.9)
- Maturity 54 → 54 (+0.2)
- Readiness 69 → 77 (+7.1)
- Security 75 → 84 (+8.7)
- Accessibility 43 → 48 (+4.1)

## Resolved (28)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (18 lines × 5) (server/lib/schema_web/views/page_view.ex)
- Duplicated block (31 lines × 4) (server/lib/schema_web/views/page_view.ex)
- Duplicated block (6 lines × 2) (server/lib/schema/json_schema.ex)
- High CVE: [GHSA redacted] (server/mix.lock)
- High CVE: [GHSA redacted] (server/mix.lock)
- High CVE: [GHSA redacted] (server/mix.lock)
- High CVE: [GHSA redacted] (server/mix.lock)
- High CVE: [GHSA redacted] (server/mix.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: EEF-[CVE redacted] (server/mix.lock)
- Medium IaC: WD-DOCKER-0003 (server/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (server/Dockerfile)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (server/lib/schema_web/views/page_view.ex)
- No artifact signing
- No build provenance
- …and 8 more

## New (22)

- Duplicated block (19 lines × 5) (server/lib/schema_web/views/page_view.ex)
- Duplicated block (31 lines × 4) (server/lib/schema_web/views/page_view.ex)
- Duplicated block (6 lines × 2) (server/lib/schema/profiles.ex)
- Duplicated block (8 lines × 2) (server/lib/schema/json_schema.ex)
- Medium CVE: EEF-[CVE redacted] (server/mix.lock)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (server/lib/schema_web/views/page_view.ex)
- …and 2 more

## Changes since last survey

- 17 commits — 12 feature/other, 5 fixes

## By area

- .github/workflows — 6 commits
- server/lib — 6 commits
- (root) — 2 commits
- proto/test — 1 commit
- server/Dockerfile — 1 commit
- server/config — 1 commit

## Notable commits

- fix: fix(ci): scope image cleanup packages token to the job (#499)
- fix: fix(server): bump alpine runtime image for openssl CVEs (#523)
- fix: fix(server): escape the name echoed in 404 responses (#527)
- fix: fix(server): escape the swagger document embedded in the UI page (#525)
- fix: fix(server): stop converting request-supplied names to new atoms (#508)
- change: chore(server): record why the sobelow findings are safe (#535)
- change: chore(server): remove the unused splunk config (#533)
- change: ci(ci): pin remaining unpinned dependencies by hash (#503)
- change: ci(ci): point the latest tag at the image built from main (#531)
- change: ci(ci): publish an image from main and scan it instead of the release (#529)
- change: ci(ci): scan elixir with sobelow and workflows with codeql (#514)
- change: ci(ci): sign the server image and attest build provenance (#521)
- change: deps(ci): update go test module dependencies for security advisories (#504)
- change: deps(server): update elixir dependencies for security advisories (#506)
- change: docs(ci): add a CHANGELOG to the repository root (#520)
- change: docs(ci): add openssf best practices badge (#515)
- change: test(server): add property-based tests for the validator and translator (#511)
