# Changelog

## Score

- CAI 55 → 43 (-12.6)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 53 → 53 (-0.2)
- Maturity 39 → 40 (+1.2)
- Readiness 79 → 37 (-42.4)
- Security 82 → 72 (-10.3)

## Resolved (8)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1

## New (51)

- Change coupling: gist.js ↔ index.js (api/gist.js)
- Change coupling: gist.js ↔ pin.js (api/gist.js)
- Change coupling: gist.js ↔ top-langs.js (api/gist.js)
- Change coupling: gist.js ↔ wakatime.js (api/gist.js)
- Change coupling: index.js ↔ pin.js (api/index.js)
- Change coupling: index.js ↔ top-langs.js (api/index.js)
- Change coupling: index.js ↔ wakatime.js (api/index.js)
- Change coupling: pin.js ↔ top-langs.js (api/pin.js)
- Change coupling: pin.js ↔ wakatime.js (api/pin.js)
- Change coupling: top-langs.js ↔ wakatime.js (api/top-langs.js)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 31 more
