# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 55 → 56 (+1.2)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 72 → 59 (-13.5)
- Architecture 82 → 56 (-26.4)
- Maturity 62 → 60 (-2.0)
- Readiness 56 → 55 (-1.5)
- Security 45 → 60 (+15.5)

## Resolved (23)

- Duplicated block (11 lines × 2) (modules/llrt_fetch/src/body_helpers.rs)
- Duplicated block (12 lines × 2) (modules/llrt_crypto/src/subtle/key_algorithm.rs)
- Duplicated block (5 lines × 11) (modules/llrt_buffer/src/array_buffer_view.rs)
- Duplicated block (7 lines × 2) (modules/llrt_stream_web/src/transform/stream.rs)
- Duplicated block (7 lines × 2) (modules/llrt_stream_web/src/transform/stream.rs)
- Hotspot: build.mjs (build.mjs)
- Hotspot: libs/llrt_encoding/src/lib.rs (libs/llrt_encoding/src/lib.rs)
- Hotspot: modules/llrt_crypto/src/provider/mod.rs (modules/llrt_crypto/src/provider/mod.rs)
- Hotspot: modules/llrt_crypto/src/provider/rust/mod.rs (modules/llrt_crypto/src/provider/rust/mod.rs)
- Hotspot: modules/llrt_crypto/src/subtle/supports.rs (modules/llrt_crypto/src/subtle/supports.rs)
- Hotspot: modules/llrt_fetch/src/headers.rs (modules/llrt_fetch/src/headers.rs)
- Hotspot: modules/llrt_stream_web/src/readable/byob_reader.rs (modules/llrt_stream_web/src/readable/byob_reader.rs)
- Hotspot: modules/llrt_util/src/text_decoder.rs (modules/llrt_util/src/text_decoder.rs)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (modules/llrt_fetch/src/request.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- Orphaned knowledge (modules/llrt_stream_web/src/readable/default_controller.rs)
- Orphaned knowledge (modules/llrt_stream_web/src/readable/iterator.rs)
- Orphaned knowledge (modules/llrt_stream_web/src/readable/stream/mod.rs)
- Orphaned knowledge (modules/llrt_stream_web/src/readable/stream/tee.rs)
- …and 3 more

## New (72)

- Ambiguous naming and signature overlap in Encoder. `encode` and `encode_to_string` appear to perform similar encoding operations, but `encode_to_string` explicitly includes a `lossy` parameter while `encode` does not. It is unclear if `encode` defaults to lossy or lossless, or if it returns a different type (e.g., Vec<u8> vs String).
- ClassTooLong: WritableStreamDefaultController (modules/llrt_stream_web/src/writable/default_controller.rs)
- Duplicate Console implementation. There are two distinct `Console` types in different modules (`llrt_core.modules.console` and `llrt_console`) with identical method signatures. This suggests redundant code or a namespace collision that could confuse users about which console instance is active.
- Duplicated block (10 lines × 2) (modules/llrt_crypto/src/subtle/key_algorithm.rs)
- Duplicated block (11 lines × 2) (modules/llrt_fetch/src/body_helpers.rs)
- Duplicated block (14 lines × 2) (modules/llrt_stream_web/src/readable/stream/tee.rs)
- Duplicated block (5 lines × 11) (modules/llrt_buffer/src/array_buffer_view.rs)
- Duplicated block (6 lines × 2) (modules/llrt_util/src/text_encoder_stream.rs)
- Duplicated block (8 lines × 2) (modules/llrt_util/src/text_decoder_stream.rs)
- Fragmented error throwing methods. There are four distinct methods for throwing errors from a Result, differentiated only by the type of error or message handling. This forces users to choose the correct method based on subtle distinctions rather than a single, flexible API.
- Hotspot: modules/llrt_fetch/src/fetch.rs (modules/llrt_fetch/src/fetch.rs)
- Inconsistent return types for decoder constructors across compression modules. Most return specific typed decoders (GzDecoder, DeflateDecoder, etc.), while zstd and brotli return a generic Result, and the streaming module uses a constructor pattern with a string encoding argument instead of a generic reader. This forces consumers to handle different initialization patterns and return types depending on the algorithm.
- Inconsistent return types for hex and base64 encoding. `bytes_to_hex` and `bytes_to_b64` return `u8` (likely a bug or internal representation), while `bytes_to_hex_string` and `bytes_to_b64_string` return `String`. This creates confusion about which function to use for actual string output.
- Inconsistent return types for string extraction. `get_coerced_string_bytes` returns `u8` (likely a pointer or handle), while `get_string_bytes` returns a `Result`. This inconsistency makes it difficult to handle errors uniformly when extracting string data from values.
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (modules/llrt_fetch/src/request.rs)
- …and 52 more

## Changes since last survey

- 49 commits — 38 feature/other, 11 fixes

## By area

- (root) — 20 commits
- (repo) — 19 commits
- modules/llrt_fetch — 3 commits
- modules/llrt_buffer — 2 commits
- libs/llrt_utils — 1 commit
- llrt_core/src — 1 commit
- modules/llrt_stream_web — 1 commit
- modules/llrt_util — 1 commit
- tests/wpt — 1 commit

## Notable commits

- fix: Merge pull request #1778 from nabetti1720/fix/web-streams
- fix: Merge pull request #1787 from nabetti1720/fix/improve-wpt
- fix: Merge pull request #1788 from nabetti1720/fix/encoding-streams
- fix: Run cargo fmt on the rquickjs 0.14 API fixes
- fix: chore: Revert the exclusion conditions for the fetch WPT
- fix: fix(encoding,util): Fix encoding streams behavior and share WTF-8 encoding logic
- fix: fix(encoding,util): use primordials and atomics in TextEncoderStream
- fix: fix(webstreams): Fix Web Streams conformance and structuredClone transfer handling
- fix: fix(wpt): improve harness compatibility and narrow Fetch skips
- fix: fix: correct wpt_errors.txt baseline for pqc-enabled WPT run
- fix: fix: update wpt_errors.txt for intl402's effect on 5 unrelated tests
- change: Avoid extra copy in lossy UTF-8 conversion via Cow-based bytes_to_utf8_string_lossy
- change: Bump rquickjs to 0.14.0 and adapt to its breaking API changes
- change: Enable pqc by default in make test and check-wpt
- change: Make Intl/Temporal opt-in via a new intl402 feature
- change: Make pqc default-on again, keep it toggleable
- change: Merge pull request #1771 from awslabs/chore/reduce-binary-size
- change: Merge pull request #1775 from nabetti1720/chore/skip-historical-test
- change: Merge pull request #1776 from nabetti1720/feat/impl-teststream
- change: Merge pull request #1777 from nabetti1720/chore/skip-invalid-url-cases
- …and 29 more

## Architecture

- Containers 1 added · 0 removed · contexts 0 added · 0 removed · edges 0 added · 0 removed

## Added containers (1)

- cli:%name.PascalCased%.template
