# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 67 (+6.7)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 87 → 87 (-0.0)
- Architecture 99 → 99 (-0.5)
- Maturity 52 → 55 (+3.4)
- Readiness 71 → 71 (+0.1)
- Security 52 → 77 (+25.4)

## Resolved (72)

- Documentation: no installation or build instructions (README.md)
- Duplicated block (7 lines × 2) (clap_derive/src/item.rs)
- Duplicated block (8 lines × 2) (clap_derive/src/item.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 52 more

## New (16)

- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Duplicated block (10 lines × 2) (clap_derive/src/item.rs)
- Duplicated block (5 lines × 2) (clap_derive/src/item.rs)
- Duplicated block (8 lines × 2) (clap_derive/src/item.rs)
- High: security finding (details withheld)
- Highly redundant and confusing getter methods for aliases. There are multiple methods to retrieve aliases with overlapping semantics (visible vs all, short vs long, combined). The return types are inconsistent (`char` vs `str` vs `impl Iterator`), suggesting internal implementation details are leaking or the API is unstable. Specifically, `get_visible_short_aliases` and `get_all_short_aliases` returning `char` (singular) is suspicious for a list of aliases.
- Hotspot: clap_derive/src/attr.rs (clap_derive/src/attr.rs)
- Inconsistent naming and return types for parsing operations. `get_matches` returns `ArgMatches` directly (panicking on error), while `try_get_matches` returns `ClapResult`. Furthermore, `get_matches` has no `from` variant for custom iterators, forcing users to use `try_get_matches_from` or convert iterators manually. The naming convention mixes 'get' (blocking/panicking) and 'try' (result-returning) inconsistently across input sources.
- Inconsistent naming for subcommand lookup. `Command` uses `find_subcommand`, whereas `Arg` uses `get_id`, `get_help`, etc. More importantly, `find_subcommand` returns `Self` (the subcommand itself), which is inconsistent with `get_arguments` which returns an iterator. If it returns `Self`, it should likely be `get_subcommand` to match the `get_*` pattern for retrieval, or `find_*` should return an `Option<Self>` to indicate failure, which is the standard Rust pattern for 'find' operations.
- Inverted test pyramid
- Members sharing a duplicated core (4 members, 50+ identical tokens) (clap_derive/src/derives/args.rs)
- No ADRs found
- Off the main sequence: clap_lex
- Off-boarding risk: anonymized user #1
- Redundant `_os` suffixed methods for default values. `default_value` and `default_value_os` appear to do the same thing, as do their plural variants. Since `OsStr` is the native OS string type in Rust, and `Into<OsStr>` is accepted by both, the distinction is unclear and likely unnecessary, adding API surface without clear benefit.
- Redundant/Confusing naming for argument count configuration. `number_of_values` takes a single `usize` (count), while `num_args` takes a `ValueRange` (min/max). In clap, these often map to the same underlying CLI flag (`--num-args`), but the API exposes two distinct methods with different semantics and input types, leading to confusion about which to use for simple fixed counts vs ranges.

## Changes since last survey

- 23 commits — 21 feature/other, 2 fixes

## By area

- (root) — 6 commits
- (repo) — 5 commits
- .github/workflows — 3 commits
- clap_builder/src — 2 commits
- clap_complete/tests — 2 commits
- tests/derive_ui — 2 commits
- clap_complete/CHANGELOG.md — 1 commit
- clap_complete/Cargo.toml — 1 commit
- clap_complete/src — 1 commit

## Notable commits

- fix: Merge pull request #6526 from bonnefoa/fix-completion-escape
- fix: fix(clap_complete): Fix value escape in zsh completion
- change: Merge pull request #6521 from r-near/feat/derive-deferred-initialization
- change: Merge pull request #6528 from epage/template
- change: Merge pull request #6535 from epage/action
- change: chore(ci): Pin actions
- change: chore(ci): Remove unused bench job
- change: chore(ci): Resolve conflict
- change: chore(deps): Update Rust crate trybuild to v1.0.120 (#6509)
- change: chore(release): Simplify replacements
- change: chore: Release
- change: chore: Release
- change: chore: Rename master to main
- change: chore: Update from _rust template
- change: docs(ai): Explicitly exclude shell script logic
- change: docs: Update changelog
- change: docs: Update changelog
- change: feat(derive): Defer enum subcommand initialization
- change: style: Make clippy happy
- change: style: Make rustfmt happy
- …and 3 more
