# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 71 → 73 (+2.7)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 94 → 94 (+0.3)
- Architecture 100 → 98 (-2.2)
- Maturity 67 → 67 (+0.0)
- Readiness 76 → 70 (-6.0)
- Security 63 → 80 (+16.8)
- Performance 91 (new)

## Resolved (80)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 60 more

## New (10)

- Inconsistent naming for factory methods. 'from_dir', 'from_file', 'from_toml' suggest source-based construction, while 'from_defaults' suggests a state-based construction. While distinct, the pattern 'from_*' is used for both source and default state, which can be slightly confusing. More importantly, 'update(source: Self)' is used for merging, but there is no 'merge' or 'combine' alias, which is fine, but 'from_defaults' is an outlier in the 'from_*' naming convention if it doesn't take a source.
- Inconsistent parameter naming for the input buffer. One uses 'buffer' and the other uses 'content' (in Tokenizer methods), but within the check module itself, the distinction is clear (str vs &[u8]). However, looking at Tokenizer, we see 'parse_str(content: str)' and 'parse_bytes(content: &[u8])'. The naming 'content' vs 'buffer' is inconsistent across the API surface for the same conceptual input.
- Inconsistent parameter naming for the same logical argument. The core trait uses 'ident' and 'word', while the implementation 'BuiltIn' uses 'ident_token' and 'word_token'. This creates confusion about whether the argument is the raw token or a processed identifier/word object.
- Off the main sequence: dictgen
- Off the main sequence: typos
- Off the main sequence: varcon-core
- Outdated: clap
- Outdated: encoding_rs
- Outdated: toml
- Outdated: unicode-ident

## Changes since last survey

- 16 commits — 12 feature/other, 4 fixes

## By area

- (repo) — 6 commits
- (root) — 4 commits
- .github/workflows — 4 commits
- crates/typos-cli — 2 commits

## Notable commits

- fix: Fix merge conflict in rust-next workflow
- fix: Merge pull request #1619 from szepeviktor/fix-wf
- fix: Merge pull request #1621 from antonkesy/fix-case-correct-panic
- fix: fix(cli): Don't panic on non-ASCII corrections
- change: Merge pull request #1618 from epage/template
- change: Merge pull request #1620 from epage/test
- change: Merge pull request #1625 from epage/maturin
- change: chore(ci): Clean up test action
- change: chore(ci): Update maturin
- change: chore: Release
- change: chore: Release
- change: chore: Rename master to main
- change: chore: Update from _rust template
- change: docs: Update changelog
- change: docs: Update changelog
- change: style: Make clippy happy
