# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 65 → 68 (+3.2)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 99 → 99 (+0.0)
- Architecture 100 → 92 (-7.8)
- Maturity 52 → 55 (+2.8)
- Readiness 70 → 72 (+1.5)
- Security 70 → 84 (+14.0)

## Resolved (8)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Unpinned build actions

## New (5)

- Inconsistent arity and parameter naming for CSP directive manipulation. The methods exist in two forms: one taking a `request` object and a `target` argument, and another taking only `additions`. The `target` argument in the 3-arg version is ambiguous (is it the config name? the request object again?), while the 2-arg version implies a global or default context. This creates confusion about how to target specific named configurations versus the default.
- Inconsistent arity for applying named overrides. One version requires a `request` object, the other does not. It is unclear when the `request` is necessary (e.g., for dynamic config resolution) versus when it is optional or redundant.
- Inconsistent arity for nonce generation. Methods exist with and without a `request` argument. This suggests that nonce generation might depend on request-specific state in some cases but not others, leading to confusion about which method to call in different contexts (e.g., background jobs vs. request handling).
- Inconsistent arity for opting out of headers. One version requires a `request`, the other does not. This inconsistency mirrors the nonce generation issue and suggests unclear scoping rules for opt-out operations.
- Inconsistent naming for append operations. `named_append` takes a block, while `named_appends` (plural) takes only a name. It is unclear if `named_appends` retrieves existing appends or if it's a typo/inconsistency in naming convention (singular vs plural) for similar operations.

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- (repo) — 2 commits
- .github/workflows — 1 commit

## Notable commits

- change: Bump ruby/setup-ruby from 1.321.0 to 1.323.0
- change: Bump ruby/setup-ruby from 1.321.0 to 1.323.0 (#601)
- change: Pin GitHub Actions to commit SHAs (#600)
