# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 31 → 32 (+1.5)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 27 → 27 (+0.0)
- Architecture 97 → 87 (-10.0)
- Maturity 60 → 60 (+0.0)
- Readiness 23 → 25 (+2.2)
- Security 55 → 72 (+17.1)
- Accessibility 31 → 31 (+0.0)
- Performance 60 (new)

## Resolved (5)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)

## New (7)

- Medium: security finding (details withheld)
- Outdated (npm): path-to-regexp
- Outdated (npm): swiper
- Projects may be oversized for their cohesion
- find-common-css-vars.fs.readdirSync("./src/core/components").forEach() (cognitive 22) (scripts/find-common-css-vars.js)
- find-common-css-vars.fs.readdirSync("./src/core/components").forEach() (cyclomatic 20) (scripts/find-common-css-vars.js)
- link.Link (cognitive 18) (src/react/components/link.jsx)

## Changes since last survey

- 6 commits — 3 feature/other, 3 fixes

## By area

- src/core — 4 commits
- (root) — 1 commit
- src/react — 1 commit

## Notable commits

- fix: fix(input): reset outlined input bottom margin in iOS theme
- fix: fix(login-screen): match outlined label backgrounds to login screen
- fix: fix(sheet): reserve toolbar space in default bottom sheets
- change: 9.2.0
- change: Prevent chip delete event from bubbling (#4367)
- change: feat(link): support disabled links across component frameworks
