# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 52 → 53 (+1.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 48 → 47 (-1.2)
- Architecture 93 → 94 (+1.1)
- Maturity 54 → 56 (+1.4)
- Readiness 46 → 48 (+1.8)
- Security 71 → 77 (+5.9)
- Accessibility 72 → 72 (+0.0)
- Performance 100 (new)

## Resolved (23)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Request (cognitive 17) (src/client.js)
- _end (cognitive 116) (src/node/index.js)
- _end (cyclomatic 35) (src/client.js)
- _end (cyclomatic 74) (src/node/index.js)
- _shouldRetry (cognitive 20) (src/request-base.js)
- _shouldRetry (cyclomatic 16) (src/request-base.js)
- callback (cognitive 23) (src/node/index.js)
- callback (cyclomatic 16) (src/node/index.js)
- field (cognitive 20) (src/request-base.js)
- request (cognitive 43) (src/node/index.js)
- …and 3 more

## New (34)

- Documentation: no architecture or design documentation (docs/index.md)
- Documentation: no usage examples (docs/index.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Hotspot: src/client.js (src/client.js)
- Hotspot: src/node/index.js (src/node/index.js)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Outdated (npm): component-emitter
- Outdated (npm): form-data
- Outdated (npm): mime
- Outdated (npm): qs
- Repeated repair: src/node/http2wrapper.js (src/node/http2wrapper.js)
- Skipped (documented): should follow a relative redirect within the same Unix domain socket (test/node/security.js)
- Skipped (documented): should not follow a redirect from one Unix domain socket to another (test/node/security.js)
- Skipped (documented): should not follow a redirect into a Unix domain socket (test/node/security.js)
- Skipped (documented): should reject the promise for a redirect into a Unix domain socket (test/node/security.js)
- …and 14 more

## Changes since last survey

- 9 commits — 2 feature/other, 7 fixes

## By area

- (root) — 3 commits
- (repo) — 2 commits
- src/node — 2 commits
- test/node — 2 commits

## Notable commits

- fix: Merge pull request #1852 from official-burak/fix/max-response-size-double-callback
- fix: Merge pull request #1859 from dyk1454683243-sudo/cursor/fix-request-dispose-error-efa5
- fix: fix(ci): restore matrix installs and stabilize HTTP2 pipe test
- fix: fix(node): handle early streamed responses and multipart length errors
- fix: fix: consolidate safe request, redirect, and CI regressions
- fix: fix: dispose request on header and request-path errors
- fix: fix: harden redirects, response handling and cookie scoping against hostile servers
- change: 10.4.0
- change: 10.4.1
