# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 62 → 42 (-19.6)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 95 → 100 (+5.0)
- Maturity 56 → 59 (+3.6)
- Readiness 59 → 30 (-29.2)
- Security 55 → 38 (-17.0)

## Resolved (17)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FinderChoice::call (cognitive 28) (src/finder/mod.rs)
- FinderChoice::call (cyclomatic 26) (src/finder/mod.rs)
- Further orphaned files (smaller)
- Hotspot: src/commands/core/actor.rs (src/commands/core/actor.rs)
- Hotspot: src/finder/mod.rs (src/finder/mod.rs)
- Hotspot: src/parser.rs (src/parser.rs)
- Input::run (cognitive 17) (src/commands/preview/var.rs)
- Medium CVE: RUSTSEC-2025-0055 (Cargo.lock)
- Medium advisory (unsound): RUSTSEC-2026-0190 (Cargo.lock)
- Off-boarding risk: anonymized user #1
- Parser::read_lines (cognitive 25) (src/parser.rs)
- Parser::read_lines (cyclomatic 17) (src/parser.rs)
- Parser::write_cmd (cognitive 20) (src/parser.rs)
- Workflow token permissions not restricted
- actor::prompt_finder (cognitive 21) (src/commands/core/actor.rs)

## New (4)

- Dimension evaluation failed
- High: security finding (details withheld)
- No automated tests
- No tests found
