# Changelog

## Score

- CAI 47 → 51 (+3.2)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 68 → 68 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 49 → 49 (+0.0)
- Readiness 59 → 45 (-14.5)
- Security 38 → 58 (+20.8)

## Resolved (4)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)

## New (10)

- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): dedent
- Outdated (npm): detect-indent
- Outdated (npm): fs-extra
- Outdated (npm): glob
- Outdated (npm): inquirer
- Outdated (npm): strip-bom
- Outdated (npm): strip-json-comments
