# Changelog

## Score

- CAI 34 → 36 (+1.4)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 49 → 51 (+2.4)
- Architecture 65 → 65 (+0.0)
- Maturity 53 → 63 (+9.9)
- Readiness 19 → 20 (+0.7)
- Security 78 → 80 (+2.3)
- Domain Modelling 100 → 100 (+0.0)
- Event-Driven 100 → 100 (+0.0)
- Accessibility 35 → 35 (+0.0)

## Resolved (127)

- BarePragmaDisable (Src/APIServer/Aplication/Graphql/Types/ObjectTypes/WebHook/WebHookRecordType.cs)
- BarePragmaDisable (Src/IdentityServer/Aplication/Interfaces/IAppDbContext.cs)
- CommentedOutCode (Src/APIServer/API/Configuration/AddScheduler.cs)
- CommentedOutCode (Src/APIServer/Persistence/Extensions/AddApiDbContext.cs)
- CommentedOutCode (Src/BFF/API/Configuration/AddIdentity.cs)
- CommentedOutCode (Src/BFF/API/Configuration/Bff/CustomProxyHttpMessageInvokerFactory.cs)
- CommentedOutCode (Src/IdentityServer/API/Configuration/AddDbContext.cs)
- CommentedOutCode (Src/Shared/API/Configuration/AddTelemerty.cs)
- Coverage not measured — analyzer environment
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- Critical CVE: [GHSA redacted] (Src/BFF/API/ClientApp/package-lock.json)
- …and 107 more

## New (4)

- Coverage not measured — analyzer environment
- Inconsistent spelling of 'Activate' as 'Activ' in command, handler, and input model names.
- Inconsistent spelling of 'Internal' as 'Internall' (double 'l') and 'Notification' as 'Notifi' (truncated/typo) in namespace and class names.
- Multiple typos in naming: 'Middleware' as 'Middelware', 'Environment' as 'Enviroment', 'Parent' as 'Parrent'.

## API surface

- Unchanged — 2 HTTP endpoints
