# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 62 (+2.1)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 88 → 89 (+0.5)
- Architecture 68 → 68 (-0.1)
- Maturity 71 → 69 (-1.8)
- Readiness 57 → 57 (+0.0)
- Security 54 → 61 (+6.4)
- Event-Driven 72 → 72 (+0.0)

## Resolved (80)

- Change coupling: SignContractEndpoint.cs ↔ MarkPassAsExpiredEndpoint.cs (Chapter-1-initial-architecture/Src/Fitnet/Contracts/SignContract/SignContractEndpoint.cs)
- Decision is generic ('We decided to use Docker') with no context (why not a different container tool) or trade-offs beyond the listed consequences (Chapter-1-initial-architecture/Docs/ArchitectureDecisionLog/0006-use-docker.adoc)
- Decision is generic ('We decided to use Docker') with no context (why not a different container tool) or trade-offs beyond the listed consequences (Chapter-2-modules-separation/Docs/ArchitectureDecisionLog/0006-use-docker.adoc)
- Decision is generic ('We decided to use Docker') with no context (why not a different container tool) or trade-offs beyond the listed consequences (Chapter-3-microservice-extraction/Docs/ArchitectureDecisionLog/0006-use-docker.adoc)
- Decision is generic ('We decided to use Docker') with no context (why not a different container tool) or trade-offs beyond the listed consequences (Chapter-4-applying-tactical-domain-driven-design/Docs/ArchitectureDecisionLog/0006-use-docker.adoc)
- High IaC: DS-0002 (Chapter-3-microservice-extraction/Fitnet.Contracts/Src/Dockerfile)
- High IaC: DS-0002 (Chapter-3-microservice-extraction/Fitnet/Src/Dockerfile)
- High IaC: DS-0002 (Chapter-4-applying-tactical-domain-driven-design/Fitnet.Contracts/Src/Dockerfile)
- High IaC: DS-0002 (Chapter-4-applying-tactical-domain-driven-design/Fitnet/Src/Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 60 more

## New (4)

- Build action pinned to a mutable branch
- Secret passed as a command-line argument
- Test runner surfaced no tests
- Workflow token permissions not restricted

## API surface

- Unchanged — 1 HTTP endpoints
