# Changelog

## Score

- CAI 35 → 36 (+0.9)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 83 → 85 (+2.6)
- Architecture 100 → 100 (+0.0)
- Maturity 48 → 54 (+6.6)
- Readiness 12 → 12 (+0.0)
- Security 48 → 58 (+9.8)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 47 → 44 (-3.5)

## Resolved (57)

- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (12 lines × 2) (internals/order/controller/http/handler.go)
- Duplicated block (12 lines × 2) (internals/order/controller/http/handler.go)
- Duplicated block (16 lines × 2) (internals/product/repository/product.go)
- Duplicated block (8 lines × 2) (pkgs/validation/option.go)
- Duplicated block (9–10 lines × 2) (internals/product/controller/http/handler.go)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- …and 37 more

## New (27)

- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (12 lines × 2) (internals/order/controller/http/handler.go)
- Duplicated block (12 lines × 2) (internals/order/controller/http/handler.go)
- Duplicated block (16 lines × 2) (internals/product/repository/product.go)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- High CVE: [GHSA redacted] (frontend/package-lock.json)
- Low IaC: KSV-0003 (k8s/frontend.yaml)
- Low IaC: KSV-0003 (k8s/minio.yaml)
- Low IaC: KSV-0011 (k8s/frontend.yaml)
- Low IaC: KSV-0011 (k8s/minio.yaml)
- Low IaC: KSV-0015 (k8s/frontend.yaml)
- Low IaC: KSV-0015 (k8s/minio.yaml)
- Low IaC: KSV-0016 (k8s/app.yaml)
- Low IaC: KSV-0016 (k8s/frontend.yaml)
- Low IaC: KSV-0016 (k8s/minio.yaml)
- Low IaC: KSV-0018 (k8s/app.yaml)
- Low IaC: KSV-0018 (k8s/frontend.yaml)
- Low IaC: KSV-0018 (k8s/minio.yaml)
- Low vulnerability: [GHSA redacted] (frontend/package-lock.json)
- …and 7 more
