# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 68 → 68 (+0.6)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 89 → 89 (+0.0)
- Architecture 99 → 94 (-5.2)
- Maturity 59 → 59 (+0.1)
- Readiness 59 → 59 (-0.2)
- Security 84 → 87 (+3.5)
- Domain Modelling 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (14)

- Documentation: no architecture or design documentation (README.md)
- Documentation: written for insiders (README.md)
- High: security finding (details withheld)
- Hotspot: diesel/src/mysql_like/connection/bind.rs (diesel/src/mysql_like/connection/bind.rs)
- Hotspot: diesel/src/mysql_like/connection/url.rs (diesel/src/mysql_like/connection/url.rs)
- Hotspot: diesel_cli/src/config.rs (diesel_cli/src/config.rs)
- Hotspot: diesel_cli/src/infer_schema_internals/data_structures.rs (diesel_cli/src/infer_schema_internals/data_structures.rs)
- Hotspot: diesel_cli/src/infer_schema_internals/sqlite.rs (diesel_cli/src/infer_schema_internals/sqlite.rs)
- Hotspot: diesel_derives/src/field.rs (diesel_derives/src/field.rs)
- Hotspot: diesel_derives/src/model.rs (diesel_derives/src/model.rs)
- Hotspot: diesel_derives/src/sql_function.rs (diesel_derives/src/sql_function.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- Off-boarding risk: anonymized user #3

## New (18)

- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Inconsistent naming for similar database operations across different contexts. `execute_returning_id` is specific to insert statements, while `execute_returning_count` is on the generic Connection trait. While domains differ, the naming convention `execute_returning_*` is not unified (e.g., `execute_and_return_id` vs `execute_returning_count`). More critically, `execute_returning_id` is only available on `InsertStatement` for MySQL-like connections, whereas generic connections use `execute_returning_count`. This creates a fragmented API for 'execute and get result' operations.
- Medium IaC: DS-0001 (.clusterfuzzlite/Dockerfile)
- Off the main sequence: diesel_attribute_parser
- Off the main sequence: diesel_infer_query
- Off the main sequence: diesel_table_macro_syntax
- Off the main sequence: dsl_auto_type
- Off the main sequence: migrations_internals
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- Off-boarding risk: anonymized user #3
- Redundant methods with identical return types and likely identical implementation logic. `cast` and `fallible_cast` appear to be aliases for the same operation, creating confusion about when to use which.
- Repeated repair: diesel/src/doctest_setup.rs (diesel/src/doctest_setup.rs)
- Repeated repair: diesel/src/query_dsl/mod.rs (diesel/src/query_dsl/mod.rs)
- Repeated repair: diesel/src/sqlite/connection/sqlite_blob.rs (diesel/src/sqlite/connection/sqlite_blob.rs)
- Repetitive pattern across multiple statement types (`Insert`, `Update`, `Delete`) for boxing queries. While this is a common Rust pattern for trait object safety, the existence of both `into_boxed` and `into_boxed_clone` on every statement type suggests a potential duplication of intent if the clone variant is not strictly necessary for all use cases, or if the API could be unified via a single `into_boxed` that handles cloning internally if needed. However, the more glaring issue is the duplication of `internal_into_boxed` and `internal_into_boxed_clone` in the DSL traits (`BoxedDsl` and `BoxedCloneDsl`) which wrap these methods.
- Split diesel
- Two methods on the same trait (`IntoSql`) with identical signatures and return types. This suggests one is a legacy alias or a mistake in trait design.

## Changes since last survey

- 51 commits — 38 feature/other, 13 fixes

## By area

- (repo) — 23 commits
- diesel/src — 12 commits
- fuzz/src — 4 commits
- (root) — 3 commits
- .github/workflows — 2 commits
- diesel_migrations/migrations_macros — 2 commits
- .github/codecov.yml — 1 commit
- .github/dependabot.yml — 1 commit
- diesel_compile_tests/tests — 1 commit
- examples/sqlite — 1 commit
- fuzz/corpus — 1 commit

## Notable commits

- fix: Cleanup and minor fixes
- fix: Fix jsonb doctests and gate them on SQLite 3.45
- fix: Fix the invalid dependabot config and add a 7 day cooldown
- fix: Merge pull request #5213 from LucaCappelletti94/fix/sqlite-jsonb-group-array-doctests
- fix: Merge pull request #5215 from LucaCappelletti94/fix/unchecked-bind-sql-doc
- fix: Merge pull request #5218 from zommiommy/fix/sqlite-blob-state
- fix: Merge pull request #5234 from LucaCappelletti94/dependabot-config-fix
- fix: Merge pull request #5247 from mgeisler/fix-embed-migrations-not-reproducible
- fix: fix(migrations): make `embed_migrations!` reproducible
- fix: fix(sqlite): close blob handles exactly once
- fix: fix(sqlite): reject before-start blob seeks
- fix: fix(sqlite): track closed blob handles with Option
- fix: fixed nullable + cleanups
- change: Add a fuzz harness for the sqlite deserialization code
- change: Add code coverage reporting to CI
- change: Apply batched suggestions from code review
- change: Bump `sqlite-wasm-rs` to 0.6.1
- change: Document the raw SQL appenders and their injection risk
- change: Drop the test-only cfg on set_requires_rollback_maybe_up_to_top_level
- change: Enable serde_json's float_roundtrip for json float round trip tests
- …and 31 more
