# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 61 → 63 (+1.5)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 100 → 98 (-1.7)
- Maturity 52 → 52 (+0.0)
- Readiness 73 → 73 (+0.0)
- Security 53 → 59 (+6.1)

## Resolved (15)

- Dependency hygiene not measured — no supported dependency manifest was read
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Scanner failed to run — not a clean result

## New (19)

- Change coupling: address.ex ↔ avatar.ex (lib/faker/address.ex)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium vulnerability: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1

## Changes since last survey

- 16 commits — 15 feature/other, 1 fixes

## By area

- (root) — 10 commits
- .github/workflows — 6 commits

## Notable commits

- fix: fix(deps): remove makeup dependency (#683)
- change: chore(deps): lock file maintenance (#686)
- change: chore(deps): lock file maintenance (#690)
- change: chore(deps): update actions/checkout action to v7.0.1 (#680)
- change: chore(deps): update dependency @semantic-release/git to v11.0.1 (#685)
- change: chore(deps): update dependency elixir to v1.20.3 (#694)
- change: chore(deps): update dependency erlang to v29.0.4 (#687)
- change: chore(deps): update dependency erlang to v29.0.5 (#692)
- change: chore(deps): update github/codeql-action action to v4.37.2 (#682)
- change: chore(deps): update github/codeql-action action to v4.37.3 (#684)
- change: chore(deps): update github/codeql-action action to v4.37.4 (#689)
- change: chore(deps): update github/codeql-action action to v4.37.5 (#691)
- change: chore(deps): update github/codeql-action action to v4.37.6 (#693)
- change: chore(deps): update node.js to v24.19.0 (#688)
- change: chore(deps): update semantic-release monorepo (major) (#681)
- change: chore(release): v0.19.0-alpha.5 [skip ci]
