# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 51 → 58 (+6.3)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 94 → 96 (+2.1)
- Architecture 99 → 98 (-0.5)
- Maturity 65 → 66 (+0.9)
- Readiness 32 → 46 (+13.1)
- Security 52 → 52 (+0.0)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (34)

- Boundary-crossing change coupling: ClientCodeSamples.kt ↔ DeploymentCodeSamples.kt (carp.clients.core/src/commonTest/kotlin/dk/cachet/carp/clients/ClientCodeSamples.kt)
- Boundary-crossing change coupling: DeploymentCodeSamples.kt ↔ StudiesCodeSamples.kt (carp.deployments.core/src/commonTest/kotlin/dk/cachet/carp/deployments/DeploymentCodeSamples.kt)
- Change coupling: Serialization.kt ↔ TestInstances.kt (carp.common/src/commonMain/kotlin/dk/cachet/carp/common/infrastructure/serialization/Serialization.kt)
- Change coupling: StudyService.kt ↔ InMemoryStudyRepository.kt (carp.studies.core/src/commonMain/kotlin/dk/cachet/carp/studies/application/StudyService.kt)
- Change coupling: StudyService.kt ↔ StudyRepository.kt (carp.studies.core/src/commonMain/kotlin/dk/cachet/carp/studies/application/StudyService.kt)
- Change coupling: StudyServiceHost.kt ↔ InMemoryStudyRepository.kt (carp.studies.core/src/commonMain/kotlin/dk/cachet/carp/studies/application/StudyServiceHost.kt)
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- Low CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- Low CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- Low CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- Medium CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- …and 14 more

## New (13)

- Change coupling clique: index.ts, index.ts, index.ts, index.ts (typescript-declarations/carp-data-core/index.ts)
- Change coupling: KotlinExport.kt ↔ kotlin-kotlin-stdlib.d.ts (publish-npm-packages/src/commonMain/kotlin/KotlinExport.kt)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High CVE: [GHSA redacted] (kotlin-js-store/yarn.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- The README states the project is 'the result of a collaboration between iMotions and CACHET' but does not link to either platform's CARP documentation or its own GitHub repository. (README.md)
- Workflow token permissions not restricted

## Changes since last survey

- 3 commits — 2 feature/other, 1 fixes

## By area

- carp.studies.core/src — 2 commits
- (root) — 1 commit

## Notable commits

- fix: Fix: `stopParticipantGroup` verifies study membership using the wrong ID
- change: Build: next version for SNAPSHOT 1.3.1
- change: Share one `TestUUIDFactory` across services in `RecruitmentServiceHostTest`

## Architecture

- Unchanged — 0 containers · 1 contexts · 0 edges
