# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 56 → 46 (-10.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 96 → 100 (+4.2)
- Architecture 69 → 69 (+0.0)
- Maturity 57 → 66 (+8.6)
- Readiness 74 → 35 (-39.6)
- Security 45 → 40 (-4.8)

## Resolved (5)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- TooManyMethods: Core (lib/colorls/core.rb)

## New (7)

- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- No tests found
- The Usage section begins with a man page link but does not show any actual usage text or examples for flags like `-1`, `--all`, or `--tree`. The screenshot of one entry per line is cut off mid-sentence. (README.md)
- The body is a garbled mix of ASCII art and code (e.g. 'Y�����ʔ�', 'P%|Dbi') interspersed with random symbols ('#Ĉ', '��'), containing no context/problem statement, no explicit decision, and no consequences section (spec/fixtures/20kb-more-than-1mb.txt)
- Title '20kb-less-than-2mb' gives no context and decision is buried in base64/encoded garbage; consequences are not present (spec/fixtures/20kb-less-than-2mb.txt)
