# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 37 → 39 (+1.3)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 32 → 31 (-0.4)
- Architecture 91 → 79 (-11.9)
- Maturity 59 → 59 (-0.4)
- Readiness 40 → 35 (-4.5)
- Security 39 → 63 (+23.9)
- Accessibility 37 → 37 (+0.0)
- Performance 100 (new)

## Resolved (59)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Hotspot: bin/api.js (bin/api.js)
- Hotspot: bin/util.js (bin/util.js)
- Hotspot: biz/webui/htdocs/src/js/cgi.js (biz/webui/htdocs/src/js/cgi.js)
- Hotspot: biz/webui/htdocs/src/js/req-data.js (biz/webui/htdocs/src/js/req-data.js)
- Hotspot: biz/webui/htdocs/src/js/request-rule.js (biz/webui/htdocs/src/js/request-rule.js)
- Hotspot: biz/webui/htdocs/src/js/response-rule.js (biz/webui/htdocs/src/js/response-rule.js)
- Hotspot: lib/inspectors/req.js (lib/inspectors/req.js)
- Hotspot: lib/rules/rules.js (lib/rules/rules.js)
- Hotspot: lib/socket-mgr.js (lib/socket-mgr.js)
- Hotspot: lib/tunnel.js (lib/tunnel.js)
- Hotspot: lib/upgrade.js (lib/upgrade.js)
- Hotspot: lib/util/index.js (lib/util/index.js)
- Medium CVE: [GHSA redacted] (package-lock.json)
- _transform (cyclomatic 17) (lib/util/whistle-transform.js)
- addPluginMenus (cyclomatic 17) (biz/webui/htdocs/src/js/util.js)
- addRules (cognitive 54) (lib/rules/util.js)
- addRules (cyclomatic 25) (lib/rules/util.js)
- compareVersion (cognitive 16) (biz/webui/htdocs/src/js/util.js)
- compareVersion (cognitive 17) (lib/util/common.js)
- …and 39 more

## New (113)

- FunctionTooLong: log.patchJSON (assets/js/log.js)
- FunctionTooLong: rules-hint.CodeMirror.registerHelper("hint","rulesHint") (biz/webui/htdocs/src/js/rules-hint.js)
- FunctionTooLong: rules-mode.CodeMirror.defineMode("rules") (biz/webui/htdocs/src/js/rules-mode.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Hotspot: biz/webui/htdocs/src/js/rules-mode.js (biz/webui/htdocs/src/js/rules-mode.js)
- Hotspot: lib/inspectors/res.js (lib/inspectors/res.js)
- Medium: security finding (details withheld)
- Outdated (npm): body-parser
- Outdated (npm): colors
- Outdated (npm): express
- Outdated (npm): iconv-lite
- Outdated (npm): lru-cache
- Outdated (npm): mime
- Outdated (npm): xml2js
- Projects may be oversized for their cohesion
- add.default (cognitive 16) (biz/webui/cgi-bin/values/add.js)
- add.default (cognitive 18) (biz/webui/cgi-bin/rules/add.js)
- cli.default (cognitive 27) (bin/ca/cli.js)
- cli.default (cyclomatic 22) (bin/ca/cli.js)
- …and 93 more

## Changes since last survey

- 1 commits — 1 feature/other, 0 fixes

## By area

- (root) — 1 commit

## Notable commits

- change: chore(deps): bump adm-zip from 0.6.0 to 0.6.1
