# Changelog

## Score

- CAI 38 → 44 (+5.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 71 → 81 (+9.5)
- Architecture 58 (new)
- Maturity 61 → 71 (+10.4)
- Readiness 22 → 33 (+11.4)
- Security 46 → 65 (+18.8)
- Accessibility 42 (new)
- Performance 60 (new)

## Resolved (114)

- Boundary-crossing change coupling: SpecRunnerOpenMode.vue ↔ StudioPanel.vue (packages/app/src/runner/SpecRunnerOpenMode.vue)
- Boundary-crossing change coupling: SpecRunnerOpenMode.vue ↔ index.ts (packages/app/src/runner/SpecRunnerOpenMode.vue)
- Boundary-crossing change coupling: StudioPanel.vue ↔ index.ts (packages/app/src/studio/StudioPanel.vue)
- Boundary-crossing change coupling: errors.ts ↔ upload_artifacts.ts (packages/errors/src/errors.ts)
- Boundary-crossing change coupling: firefox.ts ↔ pluginUtils.js (packages/server/lib/browsers/firefox.ts)
- Boundary-crossing change coupling: key_press.ts ↔ bidi_automation.ts (packages/server/lib/automation/commands/key_press.ts)
- Boundary-crossing change coupling: privileged_channel.ts ↔ privileged-commands-manager.ts (packages/driver/src/util/privileged_channel.ts)
- Change coupling: ask.js ↔ index.js (scripts/binary/ask.js)
- Change coupling: cloud_request.ts ↔ index.ts (packages/server/lib/cloud/api/cloud_request.ts)
- Critical CVE: [GHSA redacted] (system-tests/projects/angular-18/yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/angular-21/yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/plugin-code-coverage/yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/webpack4_wds4-react/yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/plugin-code-coverage/yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/qwik-app/yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/plugin-code-coverage/yarn.lock)
- Critical CVE: [GHSA redacted] (system-tests/projects/config-cjs-and-esm/config-with-ts-module-no-tsconfig/yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- …and 94 more

## New (3429)

- $Cypress.action (cognitive 35) (packages/driver/src/cypress.ts)
- $Cypress.action (cyclomatic 85) (packages/driver/src/cypress.ts)
- (anonymous) (cognitive 26) (packages/server/lib/privileged-commands/privileged-channel.js)
- (anonymous) (cyclomatic 28) (packages/server/lib/privileged-commands/privileged-channel.js)
- Assertions commented out: can target new element after mouseup sequence (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: click when mouseup el is child of mousedown el (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: events when element moved on click (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: events when element moved on mousedown (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: events when element moved on mouseup (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: no click when mouseUpPhase targetEl is detached (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: no click when new element at coords is not ancestor (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- Assertions commented out: responds to changes in move handlers (packages/driver/cypress/e2e/commands/actions/click.cy.ts)
- AutIframe.highlightEl (cognitive 31) (packages/app/src/runner/aut-iframe.ts)
- AutIframe.highlightEl (cyclomatic 18) (packages/app/src/runner/aut-iframe.ts)
- Boundary-crossing change coupling: AuthActions.ts ↔ auth.ts (packages/data-context/src/actions/AuthActions.ts)
- Boundary-crossing change coupling: BrowserDataSource.ts ↔ OpenBrowserList.vue (packages/data-context/src/sources/BrowserDataSource.ts)
- Boundary-crossing change coupling: event-manager.ts ↔ events.ts (packages/app/src/runner/event-manager.ts)
- Boundary-crossing change coupling: remote-states.ts ↔ response-middleware.ts (packages/network-tools/lib/remote-states.ts)
- Boundary-crossing change coupling: selectFile.ts ↔ privileged-commands-manager.ts (packages/driver/src/cy/commands/actions/selectFile.ts)
- Boundary-crossing change coupling: studio-app-types.ts ↔ studio-server-types.ts (packages/app/src/studio/studio-app-types.ts)
- …and 3409 more

## Changes since last survey

- 300 commits — 272 feature/other, 28 fixes

## By area

- (repo) — 51 commits
- packages/driver — 47 commits
- packages/server — 43 commits
- (root) — 21 commits
- tooling/v8-snapshot — 19 commits
- .circleci/src — 13 commits
- cli/CHANGELOG.md — 8 commits
- cli/types — 6 commits
- packages/app — 6 commits
- system-tests/projects — 6 commits
- packages/data-context — 5 commits
- packages/proxy — 5 commits
- packages/electron — 4 commits
- packages/errors — 4 commits
- packages/launchpad — 4 commits
- cli/lib — 3 commits
- cli/test — 3 commits
- npm/puppeteer — 3 commits
- packages/config — 3 commits
- .circleci/config.yml — 2 commits

## Notable commits

- fix: chore: consolidate AI guidance into guides/ and fix two changelog validation bugs (#34833)
- fix: chore: fix flaky test isolation system tests by dropping 20s timeout (#34698)
- fix: chore: fix verify-release-readiness OOM after the v16 merge (#34695)
- fix: fix changelog incorrect merge
- fix: fix(puppeteer): always disconnect, report falsy rejections, and fix retry timeout (#34907)
- fix: fix: apply blockHosts test config overrides at runtime (#34200)
- fix: fix: bound the teardown work that waits on another process (#34699)
- fix: fix: describe cy.contains() subject by its content in assertions (#34588)
- fix: fix: do not offer to translate the application under test (#34664)
- fix: fix: don't mutate the DOM when have.attr/css/prop is given an object (#34544)
- fix: fix: enforce blockHosts on the browser network path in Chrome (#34788)
- fix: fix: fake cancelIdleCallback alongside requestIdleCallback in cy.clock() (#34926)
- fix: fix: fire after:run when a project is closed in global open mode (#34700)
- fix: fix: have tap run acknowledge a running spec instead of dumping it (#34777)
- fix: fix: honor a zero weight in weightedChoice and deflake its distribution test (#34815)
- fix: fix: keep app service workers off the Cypress runner document (#34762)
- fix: fix: keep the run's exit code when graceful-exit teardown fails (#34686)
- fix: fix: label the `cy.env()` console output (#34615)
- fix: fix: merge user --disable-features args instead of letting them clobber (#34787)
- fix: fix: never hand a Cypress internal route to the site under test (#34801)
- …and 280 more
