# Changelog

## Score

- CAI 68 → 69 (+1.0)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 93 → 93 (+0.0)
- Architecture 100 → 97 (-2.8)
- Maturity 65 → 66 (+0.3)
- Readiness 64 → 63 (-1.4)
- Security 61 → 71 (+9.7)

## Resolved (1)

- Hotspot: astrid-sdk-macros/src/lib.rs (astrid-sdk-macros/src/lib.rs)

## New (6)

- Ambiguous return type for `fs.read`. It is unclear if `fs.read` returns bytes or a string. Given `fs.read_to_string` exists, `fs.read` likely returns bytes, but the naming convention is inconsistent with standard libraries (e.g., Rust's `std::fs::read` returns bytes, but `read_to_string` is explicit). If `fs.read` returns bytes, it should be named `read_bytes` or similar to match `read_to_string`'s explicitness, or `read_to_string` should be `read_string`.
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Duplicate spawning mechanisms. There are two ways to spawn processes: the builder pattern via `Command` and the direct module-level functions `process.spawn` and `process.spawn_background`. This creates confusion about which API to use. The module-level functions are essentially thin wrappers around `Command`, adding unnecessary complexity.
- Inconsistent optional handling. Some getters have an `_opt` suffix (e.g., `get_bytes_opt`), while others do not (e.g., `get_borsh`, `get_versioned`). It is unclear if `get_borsh` returns an `Option` or a `Result` with a specific error type for 'not found'. This inconsistency makes it difficult to predict how to handle missing keys.
- Misuse of SystemTime for non-time fields. `ResolvedUser.display_name` is a string, not a time. `ExitInfo.exit_code` and `signal` are integers. `ResourceLimits` fields are numeric limits. `ProcessInfo.os_pid` is an integer. `KeyPage.next_cursor` is likely a string or opaque cursor. Using `SystemTime` for these fields is a severe type error and indicates a copy-paste error or misunderstanding of types.
- Redundant existence check. `fs.exists` is a common convenience method, but `fs.metadata` and `fs.symlink_metadata` already provide the necessary information to determine existence (by checking for errors). Having a dedicated `exists` method duplicates the intent of checking if a path is valid, leading to API bloat.

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- (root) — 2 commits
- astrid-sdk/src — 1 commit

## Notable commits

- change: chore(release): prepare SDK 0.7.2 (#69)
- change: feat(net): expose authenticated connection ownership (#68)
- change: feat(net): expose authenticated connection principals (#70)
