# Changelog

## Score

- CAI 45 → 47 (+2.2)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 55 → 55 (+0.0)
- Readiness 18 → 25 (+6.9)
- Security 95 → 82 (-14.0)

## Resolved (6)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- High IaC: DS-0029 (Dockerfile)
- No exposed public API
- Test reliability not included
- single-maintainer — knowledge-concentration (bus factor) risk

## New (25)

- Critical CVE: [GHSA redacted] (poetry.lock)
- Critical CVE: [GHSA redacted] (poetry.lock)
- Critical CVE: [GHSA redacted] (poetry.lock)
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High CVE: [GHSA redacted] (poetry.lock)
- High IaC: DS-0029 (Dockerfile)
- High IaC: DS-0029 (Dockerfile)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: [GHSA redacted] (poetry.lock)
- Medium CVE: PYSEC-2024-230 (poetry.lock)
- Medium CVE: PYSEC-2026-2132 (poetry.lock)
- …and 5 more
