# Changelog

## Score

- CAI 53 → 58 (+5.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 50 → 50 (+0.0)
- Readiness 53 → 55 (+1.9)
- Security 48 → 69 (+20.9)
- Performance 85 (new)

## Resolved (7)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1

## New (18)

- Documentation: no installation or build instructions (docs/download.md)
- Documentation: no installation or build instructions (docs/index.md)
- Documentation: no licence statement (docs/index.md)
- Documentation: no usage examples (docs/index.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Medium vulnerability: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
- Outdated (npm): execa
- Outdated (npm): fetch-cookie
- Outdated (npm): level
- Outdated (npm): level-codec
- Outdated (npm): levelup
- Outdated (npm): memdown
- Outdated (npm): node-fetch
- Outdated (npm): readable-stream
- Outdated (npm): through2
- Outdated (npm): uuid
