# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 58 → 42 (-15.6)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 60 → 63 (+3.0)
- Architecture 74 → 69 (-4.6)
- Maturity 70 → 67 (-2.7)
- Readiness 53 → 24 (-29.0)
- Security 54 → 51 (-3.1)

## Resolved (22)

- Boundary-crossing change coupling: tree-sitter.ts ↔ name-matcher.ts (src/extraction/tree-sitter.ts)
- Change coupling: langs.rs ↔ grammars.ts (codegraph-kernel/src/langs.rs)
- Change coupling: langs.rs ↔ index.ts (codegraph-kernel/src/langs.rs)
- Change coupling: lib.rs ↔ grammars.ts (codegraph-kernel/src/lib.rs)
- Change coupling: lib.rs ↔ index.ts (codegraph-kernel/src/lib.rs)
- Change coupling: migrations.ts ↔ queries.ts (src/db/migrations.ts)
- Change coupling: server-instructions.ts ↔ tools.ts (src/mcp/server-instructions.ts)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further sole-owners (lower concentration)
- High CVE: [GHSA redacted] (site/package-lock.json)
- High vulnerability: [GHSA redacted] (site/package-lock.json)
- High vulnerability: [GHSA redacted] (site/package-lock.json)
- High vulnerability: [GHSA redacted] (site/package-lock.json)
- Hotspot: src/resolution/c-fnptr-synthesizer.ts (src/resolution/c-fnptr-synthesizer.ts)
- Hotspot: src/resolution/callback-synthesizer.ts (src/resolution/callback-synthesizer.ts)
- Hotspot: src/resolution/import-resolver.ts (src/resolution/import-resolver.ts)
- Hotspot: src/resolution/name-matcher.ts (src/resolution/name-matcher.ts)
- Low vulnerability: [GHSA redacted] (site/package-lock.json)
- Low vulnerability: [GHSA redacted] (telemetry-worker/package-lock.json)
- …and 2 more

## New (59)

- Boundary-crossing change coupling: extraction-version.ts ↔ index.ts (src/extraction/extraction-version.ts)
- Boundary-crossing change coupling: extraction-version.ts ↔ name-matcher.ts (src/extraction/extraction-version.ts)
- Boundary-crossing change coupling: index.ts ↔ tools.ts (src/context/index.ts)
- Boundary-crossing change coupling: kernel-parity.mjs ↔ grammars.ts (scripts/kernel-parity.mjs)
- Boundary-crossing change coupling: kernel-parity.mjs ↔ index.ts (scripts/kernel-parity.mjs)
- Boundary-crossing change coupling: migrations.ts ↔ index.ts (src/db/migrations.ts)
- Boundary-crossing change coupling: tree-sitter.ts ↔ index.ts (src/extraction/tree-sitter.ts)
- Change coupling: index.ts ↔ parse-worker.ts (src/extraction/index.ts)
- Dimension evaluation failed
- FileTooLong: public/panels.js (telemetry-dashboard/public/panels.js)
- High CVE: [GHSA redacted] (site/package-lock.json)
- High CVE: [GHSA redacted] (telemetry-dashboard/package-lock.json)
- High CVE: [GHSA redacted] (site/package-lock.json)
- High CVE: [GHSA redacted] (site/package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (telemetry-worker/package-lock.json)
- High CVE: [GHSA redacted] (telemetry-worker/package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: __tests__/fixtures/tail-render-ts/src/lib/session-store.ts (__tests__/fixtures/tail-render-ts/src/lib/session-store.ts)
- …and 39 more

## Changes since last survey

- 81 commits — 59 feature/other, 22 fixes

## By area

- scripts/agent-eval — 17 commits
- __tests__/fixtures — 16 commits
- (root) — 13 commits
- docs/benchmarks — 13 commits
- src/mcp — 11 commits
- docs/design — 4 commits
- __tests__/explore-allocation-1500.test.ts — 1 commit
- __tests__/explore-allocation-e2e.test.ts — 1 commit
- __tests__/explore-factory-closure.test.ts — 1 commit
- __tests__/sync-rebuild-convergence.test.ts — 1 commit
- src/db — 1 commit
- src/installer — 1 commit
- telemetry-dashboard/scripts — 1 commit

## Notable commits

- fix: Merge pull request #1498 from colbymchenry/bugfix/CG-16
- fix: Merge pull request #1527 from colbymchenry/bugfix/CG-38
- fix: docs(benchmarks): re-derive the token figures the result.usage bug touched
- fix: docs(benchmarks): record CG-38 as open, and correct the regression claim
- fix: docs(benchmarks): record the CG-30 A/B — deterministic win, no behavioural regression
- fix: docs(benchmarks): record the CG-31 A/B — no regression, four repos stop truncating
- fix: fix(explore): a funded whole-file buy must also fit the render ceiling (CG-21)
- fix: fix(explore): bound how far an oversize cluster member may overshoot (CG-30)
- fix: fix(explore): damp ambient declaration files on flow queries (CG-28)
- fix: fix(explore): fund the guard from room that exists, and cut the epilogue first (CG-31)
- fix: fix(explore): guarantee an agent-named symbol renders, wherever it sits (CG-38)
- fix: fix(explore): hold back what is still owed below a clustered render (CG-31)
- fix: fix(explore): keep the drift warning out of the cuttable epilogue (CG-31)
- fix: fix(explore): pay every admitted file on every render path (CG-26)
- fix: fix(explore): recognize Wrangler-style "generated by … by running" banners (CG-25)
- fix: fix(explore): restore the CG-30 bound d652c14 reverted
- fix: fix(explore): shrink a later cluster into the remainder instead of dropping it (CG-36)
- fix: fix(explore): spend the reservation instead of dropping it (CG-21, #1500)
- fix: test(agent-eval): drop the duplicated fixed-overhead line (CG-7)
- fix: test(agent-eval): price codegraph's fixed context cost alongside its residual (CG-7)
- …and 61 more

## Architecture

- Containers 0 added · 0 removed · contexts 0 added · 2 removed · edges 0 added · 0 removed

## Removed bounded contexts (2)

- .
- php
