# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 57 → 50 (-7.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 90 → 86 (-4.7)
- Maturity 58 → 54 (-3.9)
- Readiness 69 → 35 (-34.5)
- Security 65 → 74 (+9.1)

## Resolved (14)

- Change coupling: domainProxy.ts ↔ pathProxy.ts (src/node/routes/domainProxy.ts)
- Change coupling: errors.ts ↔ vscode.ts (src/node/routes/errors.ts)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: node/cli.ts (src/node/cli.ts)
- Further orphaned files (smaller)
- High CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- No AppArmor/SELinux confinement
- No network policy
- No seccomp profile
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- The requirements section is cut off mid-sentence ('You can use any Linux distribution, but [our docs](https://coder.com/docs/code-server/latest/guide) assume that you're using Debian hosted by Google Cloud (see the following section for instructions on setting this up).') before stating the minimum RAM and CPU cores. (docs/requirements.md)

## New (23)

- Dimension evaluation failed
- High CVE: [GHSA redacted] (test/package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (test/package-lock.json)
- Low CVE: [GHSA redacted] (test/package-lock.json)
- Low CVE: [GHSA redacted] (test/package-lock.json)
- Low IaC: KSV-0004 (ci/helm-chart/templates/deployment.yaml)
- Low IaC: KSV-0020 (ci/helm-chart/templates/deployment.yaml)
- Low IaC: KSV-0021 (ci/helm-chart/templates/deployment.yaml)
- Low IaC: KSV-0030 (ci/helm-chart/templates/deployment.yaml)
- Low IaC: KSV-0106 (ci/helm-chart/templates/deployment.yaml)
- Medium CVE: [GHSA redacted] (test/package-lock.json)
- Medium CVE: [GHSA redacted] (test/package-lock.json)
- Medium CVE: [GHSA redacted] (test/package-lock.json)
- No automated tests
- No tests found
- The Getting started section lists five ways to get started but only four items appear in the visible text; the fifth is cut off mid-sentence ('Using our one-click buttons...') before being confirmed. (README.md)
- …and 3 more
