# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 71 → 78 (+7.3)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 99 → 100 (+1.0)
- Architecture 100 → 97 (-3.3)
- Maturity 57 → 64 (+6.5)
- Readiness 84 → 86 (+2.8)
- Security 73 → 88 (+15.8)
- Domain Modelling 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (14)

- Documentation: no project overview (data/README.md)
- Documentation: no usage examples (data/api/README.md)
- Duplicated block (9 lines × 2) (ci/pr-check/src/main.rs)
- Duplicated block (9 lines × 2) (ci/render/src/lib.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- pr_check::check_tool (cognitive 20) (ci/pr-check/src/main.rs)

## New (5)

- Duplicate types with near-identical structure. ApiEntry and Entry share the exact same set of properties. ApiEntry adds 'languages', 'other', and 'licenses' as PathBuf, while Entry has 'categories' and 'types' as BTreeSet. The core data model is duplicated, leading to maintenance overhead and potential inconsistency between the two types.
- Duplicate types with near-identical structure. ParsedEntry and Entry share the exact same set of properties (name, categories, tags, license, types, homepage, source, pricing, plans, description, discussion, deprecated, resources, reviews, demos, wrapper). Entry adds methods and a constructor from ParsedEntry, suggesting ParsedEntry is an intermediate state, but the duplication of the entire data model is redundant and confusing.
- High: security finding (details withheld)
- Inconsistent parameter types for similar operations. create_catalog takes a slice of Entry (&[Entry]), while create_api takes a single Entry (Entry). This suggests a potential API design flaw where create_api might be intended for a single entry but is named similarly to create_catalog which handles collections.
- Off the main sequence: github-repo

## Changes since last survey

- 27 commits — 27 feature/other, 0 fixes

## By area

- (root) — 10 commits
- ci/crates — 4 commits
- data/tools — 4 commits
- ci/pr-check — 3 commits
- .github/workflows — 2 commits
- ci/Cargo.lock — 1 commit
- ci/render — 1 commit
- data/api — 1 commit
- data/collections — 1 commit

## Notable commits

- change: Add DepWarden (#1848)
- change: Add LintLang (#1898)
- change: Add skillsaw (#1904)
- change: Bump dtolnay/rust-toolchain (#1908)
- change: Bump reqwest from 0.13.4 to 0.13.5 in /ci (#1893)
- change: Check homepage domain age for hosted tool submissions
- change: Close tool submissions that do not meet contribution criteria (#1897)
- change: Collapse deprecated tools in README sections (#1901)
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Commit list
- change: Deprecate unavailable tools and repair moved links (#1900)
- change: Exclude automation accounts from contributor eligibility counts (#1899)
- change: Flag generated README changes in contribution checks
- change: Keep contribution guidance focused on eligibility
- …and 7 more
