# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 57 → 71 (+13.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 99 → 99 (+0.5)
- Architecture 69 → 69 (+0.0)
- Maturity 76 → 79 (+3.1)
- Readiness 81 → 80 (-0.7)
- Security 37 → 65 (+28.0)

## Resolved (19)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (24 lines × 5) (src/Commands/Makes/MakeControllerCommand.php)
- Duplicated block (47 lines × 2) (src/Application.php)
- Duplicated block (5 lines × 2) (src/Commands/InstallCommand.php)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included

## New (21)

- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (13 lines × 2) (src/Application.php)
- Duplicated block (29 lines × 5) (src/Commands/Makes/MakeControllerCommand.php)
- Duplicated block (5 lines × 2) (src/Commands/InstallCommand.php)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (src/Commands/Makes/MakeControllerCommand.php)
- …and 1 more

## Changes since last survey

- 3 commits — 2 feature/other, 1 fixes

## By area

- (root) — 2 commits
- (repo) — 1 commit

## Notable commits

- fix: fix: Reviewed the dependabot deptrac bump and fixed two issues: removed committed merge-conflict markers from the auto-merge workflow, and loosened deptrac's exact pin to ^4.6 in composer.json
- change: Merge pull request #16 from giacomomasseron/dependabot/composer/deptrac/deptrac-4.7.1
- change: build(deps): update deptrac/deptrac requirement from 4.6.2 to 4.7.1
