# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 50 → 50 (+0.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 33 → 37 (+3.8)
- Architecture 89 → 84 (-5.2)
- Maturity 72 → 72 (-0.3)
- Readiness 74 → 62 (-11.9)
- Security 71 → 81 (+9.8)
- Accessibility 55 → 57 (+2.2)
- Performance 62 (new)

## Resolved (117)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FunctionTooLong: scan.runDiscovery (web/src/lib/core/scan.ts)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: assessment-log.mjs (assessment-log.mjs)
- Hotspot: batch/aggregate-tokens.mjs (batch/aggregate-tokens.mjs)
- Hotspot: check-liveness.mjs (check-liveness.mjs)
- Hotspot: check-table-freshness.mjs (check-table-freshness.mjs)
- Hotspot: company-funded.mjs (company-funded.mjs)
- Hotspot: contacts.mjs (contacts.mjs)
- Hotspot: fingerprint-core.mjs (fingerprint-core.mjs)
- Hotspot: fix-slugs.mjs (fix-slugs.mjs)
- Hotspot: intake.mjs (intake.mjs)
- Hotspot: lib/cv-payload-schema.mjs (lib/cv-payload-schema.mjs)
- …and 97 more

## New (251)

- Critical vulnerability: [GHSA redacted] (web/package-lock.json)
- Documentation: no licence statement (README.md)
- Documentation: no project overview (README.md)
- Duplicated block (10 lines × 2) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (12 lines × 2) (dashboard/internal/data/pdf.go)
- Duplicated block (12–14 lines × 2) (dashboard/internal/data/career.go)
- Duplicated block (16 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (16 lines × 2) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (17–18 lines × 2) (dashboard/internal/data/pdf.go)
- Duplicated block (19–20 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (24–28 lines × 2) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (26–27 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (30–31 lines × 2) (dashboard/internal/data/career.go)
- Duplicated block (5 lines × 3) (dashboard/internal/ui/screens/stats.go)
- Duplicated block (6 lines × 3) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (7 lines × 2) (dashboard/internal/data/career.go)
- Duplicated block (7 lines × 3) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (8 lines × 4) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (8–10 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (9 lines × 2) (dashboard/internal/data/pdf.go)
- …and 231 more

## Changes since last survey

- 300 commits — 157 feature/other, 143 fixes

## By area

- (root) — 179 commits
- web/src — 30 commits
- tests/providers — 9 commits
- .github/scripts — 8 commits
- docs/SUPPORTED_JOB_BOARDS.md — 8 commits
- .github/workflows — 5 commits
- dashboard/internal — 5 commits
- docs/avatar-santifer.png — 3 commits
- docs/manifesto-wall.svg — 3 commits
- modes/ko — 3 commits
- (repo) — 2 commits
- batch/README.md — 2 commits
- batch/batch-prompt.md — 2 commits
- modes/_shared.md — 2 commits
- modes/apply.md — 2 commits
- modes/zh — 2 commits
- tests/fixtures — 2 commits
- web/package-lock.json — 2 commits
- batch/batch-runner.sh — 1 commit
- config/profile.example.yml — 1 commit

## Notable commits

- fix: Fix web status filters for external data roots (#4410)
- fix: fix(agents): scope onboarding and keep diagnostics read-only (#4428)
- fix: fix(analyze-patterns): validate threshold and vendor flags (#4007)
- fix: fix(application-answers): find the draft block by a trailing (draft) marker (#4432)
- fix: fix(application-answers): parse Block H when its heading is localized (#4400)
- fix: fix(apply): hand off Ashby submission to system browser (#4443)
- fix: fix(apply): the code-fence strip reached inside JSON string values (#3302)
- fix: fix(apply): validate answers against live field limits (#4442)
- fix: fix(ashby): read the salary range from compensationTiers[].components[] (#4331)
- fix: fix(avature): read article--jobs cards, titled from the h3 anchor (#4559)
- fix: fix(batch): add adaptive rate-limit backoff (#4370)
- fix: fix(batch): fail closed on no-op workers and archive the verbatim JD (#4422)
- fix: fix(batch): reject explicit zero offer limits (#4308)
- fix: fix(batch): require parent confirmation for delegated agency postings (#4371)
- fix: fix(batch): resolve batch-prompt.md placeholders to stable labels (#4517)
- fix: fix(batch-evaluate): _profile.md and tracker-additions resolve to the code root (#4347) (#4348)
- fix: fix(build-cv-html): render each project bullets item as its own block (#4300)
- fix: fix(ci): pin the upgrade gate to the main channel so it stays hermetic (#4470)
- fix: fix(ci): pr-triage workflow_run finds fork PRs by head owner:branch, skips main (#4407)
- fix: fix(cli): scan-hn.mjs delegates --help and unknown flags to lib/cli-flags.mjs (#4627)
- …and 280 more
