# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 61 (+1.5)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 59 → 59 (+0.1)
- Architecture 65 → 59 (-6.0)
- Maturity 68 → 68 (+0.2)
- Readiness 62 → 60 (-1.7)
- Security 58 → 67 (+9.6)
- Performance 100 (new)

## Resolved (16)

- ETagPollingManager.checkCurrentIssue (cognitive 17) (packages/decap-cms-backend-github/src/polling.ts)
- EditorInterface.render (cyclomatic 17) (packages/decap-cms-core/src/components/Editor/EditorInterface.js)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Hotspot: packages/decap-cms-backend-forgejo/src/API.ts (packages/decap-cms-backend-forgejo/src/API.ts)
- Hotspot: packages/decap-cms-backend-forgejo/src/implementation.tsx (packages/decap-cms-backend-forgejo/src/implementation.tsx)
- Hotspot: packages/decap-cms-backend-github/src/implementation.tsx (packages/decap-cms-backend-github/src/implementation.tsx)
- Hotspot: packages/decap-cms-core/src/actions/config.ts (packages/decap-cms-core/src/actions/config.ts)
- Hotspot: packages/decap-cms-core/src/backend.ts (packages/decap-cms-core/src/backend.ts)
- Hotspot: packages/decap-cms-core/src/components/Editor/EditorInterface.js (packages/decap-cms-core/src/components/Editor/EditorInterface.js)
- Hotspot: packages/decap-cms-core/src/reducers/entries.ts (packages/decap-cms-core/src/reducers/entries.ts)
- Hotspot: packages/decap-cms-core/src/reducers/entryDraft.js (packages/decap-cms-core/src/reducers/entryDraft.js)
- Hotspot: packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js (packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1

## New (28)

- ClassTooLong: GitLab (packages/decap-cms-backend-gitlab/src/implementation.ts)
- Documentation: no installation or build instructions (packages/decap-cms-widget-code/README.md)
- FileTooLong: src/implementation.ts (packages/decap-cms-backend-gitlab/src/implementation.ts)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Low cohesion: API (LCOM4 5) (packages/decap-cms-backend-git-gateway/src/GitHubAPI.ts)
- Low cohesion: ControlPane (LCOM4 4) (packages/decap-cms-core/src/components/Editor/EditorControlPane/EditorControlPane.js)
- Low cohesion: TestBackend (LCOM4 15) (packages/decap-cms-backend-test/src/implementation.ts)
- Low vulnerability: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- MethodTooLong: Widget.render (packages/decap-cms-core/src/components/Editor/EditorControlPane/Widget.js)
- NotesPollingManager.checkCurrentIssue (cognitive 23) (packages/decap-cms-lib-util/src/notesPolling.ts)
- …and 8 more

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- packages/decap-cms-core — 2 commits
- packages/decap-cms — 1 commit

## Notable commits

- change: Feature/optimize editor performance (#7793)
- change: Notes pane improvements, GitLab support (#7994)
- change: chore(release): publish
