# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 62 → 64 (+2.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 (new)
- Architecture 91 → 93 (+2.3)
- Maturity 55 → 49 (-5.8)
- Readiness 74 → 70 (-4.6)
- Security 59 → 75 (+15.9)

## Resolved (42)

- Boundary-crossing change coupling: SqlServerStructuralJsonTypeMapping.cs ↔ SqliteJsonTypeMapping.cs (src/EFCore.SqlServer/Storage/Internal/SqlServerStructuralJsonTypeMapping.cs)
- Change coupling: CosmosAnnotationNames.cs ↔ CosmosClientWrapper.cs (src/EFCore.Cosmos/Metadata/Internal/CosmosAnnotationNames.cs)
- Change coupling: CosmosDbOptionExtension.cs ↔ ICosmosSingletonOptions.cs (src/EFCore.Cosmos/Infrastructure/Internal/CosmosDbOptionExtension.cs)
- Change coupling: CosmosEventId.cs ↔ CosmosLoggingDefinitions.cs (src/EFCore.Cosmos/Diagnostics/CosmosEventId.cs)
- Change coupling: CosmosLoggerExtensions.cs ↔ CosmosLoggingDefinitions.cs (src/EFCore.Cosmos/Diagnostics/Internal/CosmosLoggerExtensions.cs)
- Change coupling: CosmosLoggingDefinitions.cs ↔ CosmosClientWrapper.cs (src/EFCore.Cosmos/Diagnostics/Internal/CosmosLoggingDefinitions.cs)
- Change coupling: DbContextOptimizeCommand.cs ↔ IOperationExecutor.cs (src/ef/Commands/DbContextOptimizeCommand.cs)
- Change coupling: SqlServerCSharpRuntimeAnnotationCodeGenerator.cs ↔ SqlServerMigrationsSqlGenerator.cs (src/EFCore.SqlServer/Design/Internal/SqlServerCSharpRuntimeAnnotationCodeGenerator.cs)
- Change coupling: SqlServerLoggingDefinitions.cs ↔ SqlServerLoggerExtensions.cs (src/EFCore.SqlServer/Diagnostics/Internal/SqlServerLoggingDefinitions.cs)
- Code Coverage not included (time budget)
- Dependency Hygiene not included (time budget)
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 22 more

## New (219)

- Boundary-crossing change coupling: CosmosValueConverterCompensatingExpressionVisitor.cs ↔ RelationalValueConverterCompensatingExpressionVisitor.cs (src/EFCore.Cosmos/Query/Internal/CosmosValueConverterCompensatingExpressionVisitor.cs)
- Change coupling: CSharpSnapshotGenerator.cs ↔ MigrationsCodeGenerator.cs (src/EFCore.Design/Migrations/Design/CSharpSnapshotGenerator.cs)
- Change coupling: CosmosDbOptionExtension.cs ↔ SingletonCosmosClientWrapper.cs (src/EFCore.Cosmos/Infrastructure/Internal/CosmosDbOptionExtension.cs)
- Change coupling: CosmosSingletonOptions.cs ↔ SingletonCosmosClientWrapper.cs (src/EFCore.Cosmos/Infrastructure/Internal/CosmosSingletonOptions.cs)
- Change coupling: SqlServerAnnotationCodeGenerator.cs ↔ SqlServerAnnotationProvider.cs (src/EFCore.SqlServer/Design/Internal/SqlServerAnnotationCodeGenerator.cs)
- Change coupling: SqlServerAnnotationProvider.cs ↔ SqlServerMigrationsSqlGenerator.cs (src/EFCore.SqlServer/Metadata/Internal/SqlServerAnnotationProvider.cs)
- Change coupling: SqlServerLoggingDefinitions.cs ↔ SqlServerDatabaseModelFactory.cs (src/EFCore.SqlServer/Diagnostics/Internal/SqlServerLoggingDefinitions.cs)
- Coverage not measured — no coverage collector is wired up
- Dependency advisory scan runs only on code events
- Documentation: no architecture or design documentation (src/EFCore.SqlServer.Abstractions/README.md)
- Documentation: no architecture or design documentation (src/EFCore.SqlServer.HierarchyId/README.md)
- High secret: WD-SECRET-0003 (build/Key.snk)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 199 more

## Changes since last survey

- 265 commits — 249 feature/other, 16 fixes

## By area

- (repo) — 73 commits
- (root) — 54 commits
- eng/Versions.props — 28 commits
- eng/common — 13 commits
- src/EFCore.Relational — 12 commits
- test/Directory.Packages.props — 10 commits
- src/EFCore — 9 commits
- src/EFCore.SqlServer — 8 commits
- src/EFCore.Design — 7 commits
- src/Microsoft.Data.Sqlite.Core — 7 commits
- test/EFCore.Specification.Tests — 5 commits
- test/EFCore.SqlServer.FunctionalTests — 5 commits
- .github/workflows — 4 commits
- eng/harness-evaluation — 3 commits
- src/EFCore.Sqlite.Core — 3 commits
- test/EFCore.AspNet.Specification.Tests — 3 commits
- test/EFCore.Sqlite.FunctionalTests — 3 commits
- test/EFCore.Cosmos.FunctionalTests — 2 commits
- test/EFCore.Design.Tests — 2 commits
- test/EFCore.Relational.Specification.Tests — 2 commits

## Notable commits

- fix: Add servicing switch for GroupBy navigation fix
- fix: Fix ArgumentNullException when a foreign key references a key declared on a complex type property (#38764)
- fix: Fix AspNetCore.Identity tests on Helix (#39013)
- fix: Fix IsTableExcludedFromMigrations default for entity splitting. (#38802)
- fix: Fix UUID suffix handling in scaffolded navigation names (#38929)
- fix: Fix ValuesExpression pruning dropping outer columns referenced from VALUES cells (#38779)
- fix: Fix escaping of UNC project paths containing spaces (#38719)
- fix: Fix handling decimal for EF_DECIMAL collate. (#38891)
- fix: Fix null dereference build errors in the scaffolding tests (#38949)
- fix: Fix projecting JSON complex collection together with collection navigation (#38932)
- fix: Fix seed data diffing when primary key column count changes (#38824)
- fix: Revert OneLoc template changes
- fix: Revert some stuff
- fix: [release/11.0-rc1] Fix query shaping for native primitive collections (#38810)
- fix: [release/11.0] Fix UPDATE ordering regression for unique-index reassignment (#38924)
- fix: [release/11.0] Fix projecting JSON complex collection together with collection navigation (#38948)
- change: Abort API review baseline workflow for unmerged PRs (#38818)
- change: Add Dependabot schedule for release/11.0 on Friday (#38862)
- change: Add SQLite synchronous connection string option (#38812)
- change: Add `static` to the lambdas for functions/aggregates/collations (and explicit names). (#38892)
- …and 245 more
