# Changelog

## Score

- CAI 38 → 51 (+12.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 77 → 68 (-9.3)
- Architecture 21 → 62 (+40.7)
- Maturity 76 → 76 (-0.4)
- Readiness 56 → 64 (+8.2)
- Security 60 → 55 (-5.6)
- Accessibility 39 → 40 (+0.8)

## Resolved (78)

- Change coupling clique: ansi-dark.ts, atom-one-dark.ts, dracula-dark.ts, github-light.ts, googlecode-light.ts, xcode-light.ts (packages/cli/src/ui/themes/builtin/dark/ansi-dark.ts)
- Change coupling: GeminiMessage.tsx ↔ GeminiMessageContent.tsx (packages/cli/src/ui/components/messages/GeminiMessage.tsx)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 58 more

## New (1447)

- A2AAuthProviderFactory.findMatchingScheme (cognitive 22) (packages/core/src/agents/auth-provider/factory.ts)
- A2AResultReassembler.update (cognitive 31) (packages/core/src/agents/a2aUtils.ts)
- A2AResultReassembler.update (cyclomatic 20) (packages/core/src/agents/a2aUtils.ts)
- ActivityLogger.patchNodeHttp (cognitive 39) (packages/cli/src/utils/activityLogger.ts)
- ActivityLogger.patchNodeHttp (cyclomatic 46) (packages/cli/src/utils/activityLogger.ts)
- ActivityLogger.sanitizeNetworkLog (cognitive 16) (packages/cli/src/utils/activityLogger.ts)
- AgentConfigDialog.AgentConfigDialog (cognitive 27) (packages/cli/src/ui/components/AgentConfigDialog.tsx)
- AgentConfigDialog.AgentConfigDialog (cyclomatic 24) (packages/cli/src/ui/components/AgentConfigDialog.tsx)
- AgentRegistry.loadAgents (cognitive 38) (packages/core/src/agents/registry.ts)
- AgentRegistry.loadAgents (cyclomatic 20) (packages/core/src/agents/registry.ts)
- AgentRegistry.registerRemoteAgent (cognitive 27) (packages/core/src/agents/registry.ts)
- AgentRegistry.registerRemoteAgent (cyclomatic 24) (packages/core/src/agents/registry.ts)
- AgentRunner.run_agent (cognitive 31) (tools/caretaker-agent/cloudrun/pr-generator/workflow/agent_runner.py)
- AgentRunner.run_agent (cyclomatic 18) (tools/caretaker-agent/cloudrun/pr-generator/workflow/agent_runner.py)
- AgentSession.stream (cognitive 48) (packages/core/src/agent/agent-session.ts)
- AgentSession.stream (cyclomatic 32) (packages/core/src/agent/agent-session.ts)
- AllowedPathChecker.check (cognitive 30) (packages/core/src/safety/built-in.ts)
- AnalyzeScreenshotInvocation.execute (cognitive 20) (packages/core/src/agents/browser/analyzeScreenshot.ts)
- AnalyzeScreenshotInvocation.execute (cyclomatic 18) (packages/core/src/agents/browser/analyzeScreenshot.ts)
- App.App (cognitive 48) (packages/devtools/client/src/App.tsx)
- …and 1427 more

## Changes since last survey

- 97 commits — 37 feature/other, 60 fixes

## By area

- packages/core — 33 commits
- packages/cli — 20 commits
- tools/caretaker-agent — 13 commits
- docs/changelogs — 11 commits
- (root) — 7 commits
- packages/a2a-server — 4 commits
- integration-tests/file-system-interactive.test.ts — 2 commits
- .github/actions — 1 commit
- docs/get-started — 1 commit
- docs/reference — 1 commit
- evals/test-helper.test.ts — 1 commit
- integration-tests/concurrency-limit.test.ts — 1 commit
- packages/vscode-ide-companion — 1 commit
- scripts/utils — 1 commit

## Notable commits

- fix: (FIX) history rollback and retry nudge optimizations (#28934)
- fix: [SSR Agent] Issue Fix (19239): Update /clear command docs to include context reset (#28847)
- fix: [SSR Agent] Issue Fix (19463): Format cli_help subagent output as markdown (#28864)
- fix: [SSR Agent] Issue Fix (19826): Migrate process.env to vi.stubEnv in a2a-server tests (#28811)
- fix: [SSR Agent] Issue Fix (21477): Prevent indefinite TUI hang by adding execution timeouts (#28812)
- fix: [SSR Agent] Issue Fix (21911): Add composite flag to packages/cli tsconfig (#28813)
- fix: [SSR Agent] Issue Fix (21919): Fix TypeScript strict-null errors in integration tests (#28814)
- fix: [SSR Agent] Issue Fix (22093): Prevent subagents from running when agents mode is disabled (#28867)
- fix: [SSR Agent] Issue Fix (23954): Add trailing space to autocomplete suggestions (#28868)
- fix: [SSR Agent] Issue Fix (24587): Fix misleading admin error for personal accounts (#28819)
- fix: [SSR Agent] Issue Fix (24935): Force terminal buffer rerender after exiting external editors (#28880)
- fix: [SSR Agent] Issue Fix (26120): Clarify privacy notice wording and selection options (#28820)
- fix: [SSR Agent] Issue Fix (28050): Add Vertex AI locations documentation link (#28865)
- fix: [SSR Agent] Issue Fix (28518): Fix sub-agent handoff token regression on startup (#28882)
- fix: fix(a2a-server): add early return on unsupported store in tasks metadata endpoint (#29334)
- fix: fix(a2a-server): clear stale cancellation error on new message turns (#28940)
- fix: fix(caretaker): clear lock on NEEDS_HUMAN transition (#28601)
- fix: fix(cli): emit tool_call update prior to request_permission in ACP mode (#29439)
- fix: fix(cli): isolate settings directory in sandbox containers (#29216)
- fix: fix(cli): isolate temporary directory for macOS Seatbelt sandbox (#29171)
- …and 77 more
