# Changelog

## Score

- CAI 30 → 36 (+6.6)
- Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 81 → 80 (-0.4)
- Architecture 70 → 74 (+3.7)
- Maturity 79 → 78 (-0.0)
- Readiness 31 → 26 (-4.3)
- Security 8 → 26 (+18.5)
- Accessibility 50 → 50 (-0.0)
- Performance 66 (new)

## Resolved (589)

- Change-coupling hub: index.ts → resources_injector.rs, index.d.ts, binding.ts, share.ts (packages/core/src/config/index.ts)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [CVE redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Documentation: no architecture or design documentation (website/README.md)
- Documentation: no installation or build instructions (rust-plugins/icons/README.md)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- …and 569 more

## New (121)

- Change coupling: index.ts ↔ binding.ts (packages/core/src/config/index.ts)
- Change coupling: index.ts ↔ share.ts (packages/core/src/config/index.ts)
- Confusing Constructor Naming: `new_without_internal_plugins` is a verbose and awkward name for a constructor variant. It suggests a special case rather than a standard builder pattern or factory method.
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [CVE redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 101 more
