# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 61 → 65 (+4.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 75 → 100 (+25.5)
- Architecture 100 → 69 (-31.0)
- Maturity 64 → 57 (-7.7)
- Readiness 70 → 67 (-2.4)
- Security 51 → 80 (+29.0)

## Resolved (269)

- AGUIAdapter.load_messages (cognitive 63) (calfkit/_vendor/pydantic_ai/ui/ag_ui/_adapter.py)
- AGUIAdapter.load_messages (cyclomatic 23) (calfkit/_vendor/pydantic_ai/ui/ag_ui/_adapter.py)
- AbstractAgent._infer_name (cognitive 22) (calfkit/_vendor/pydantic_ai/agent/abstract.py)
- AbstractAgent.run_stream (cognitive 30) (calfkit/_vendor/pydantic_ai/agent/abstract.py)
- AbstractAgent.run_stream (cyclomatic 17) (calfkit/_vendor/pydantic_ai/agent/abstract.py)
- Agent.iter (cognitive 26) (calfkit/_vendor/pydantic_ai/agent/__init__.py)
- Agent.iter (cyclomatic 23) (calfkit/_vendor/pydantic_ai/agent/__init__.py)
- Agent.override (cognitive 21) (calfkit/_vendor/pydantic_ai/agent/__init__.py)
- AgentStream.validate_response_output (cognitive 18) (calfkit/_vendor/pydantic_ai/result.py)
- AgentWorker._request_parts_from_a2a (cognitive 17) (calfkit/_vendor/pydantic_ai/_a2a.py)
- AnthropicModel._add_builtin_tools (cognitive 23) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- AnthropicModel._limit_cache_points (cognitive 19) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- AnthropicModel._map_message (cognitive 100) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- AnthropicModel._map_message (cyclomatic 49) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- AnthropicModel._map_user_prompt (cognitive 30) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- AnthropicStreamedResponse._get_event_iterator (cognitive 62) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- AnthropicStreamedResponse._get_event_iterator (cyclomatic 40) (calfkit/_vendor/pydantic_ai/models/anthropic.py)
- BaseAgentNodeDef.__init__ (cognitive 21) (calfkit/nodes/agent.py)
- BaseAgentNodeDef.__init__ (cyclomatic 19) (calfkit/nodes/agent.py)
- BaseAgentNodeDef.run (cognitive 69) (calfkit/nodes/agent.py)
- …and 249 more

## New (25)

- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 5 more

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- (root) — 2 commits
- calfkit/_vendor — 1 commit

## Notable commits

- change: chore: retire the 0.13 docs and clean up after the cutover (#373)
- change: feat!: born-new cutover to durable agent, delete legacy implementation, and seed src/calfkit (#371)
- change: test: seed the tests layout and adopt pytest 9 conventions (#372)
