# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 57 → 62 (+4.9)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 65 → 93 (+27.8)
- Architecture 93 → 92 (-0.4)
- Maturity 60 → 61 (+1.1)
- Readiness 69 → 61 (-7.8)
- Security 48 → 57 (+9.0)
- Accessibility 64 → 64 (+0.0)
- Performance 100 (new)

## Resolved (87)

- Critical CVE: [CVE redacted] (js/yarn.lock)
- Critical CVE: [CVE redacted] (website-ng/package-lock.json)
- Critical CVE: [CVE redacted] (website-ng/package-lock.json)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Documentation: written for insiders (rust/gen/README.md)
- Duplicated block (5 lines × 2) (rust/tract-bench/src/bin/convert_model.rs)
- Further sole-owners (lower concentration)
- HackComment (python/tests/test_features_extraction_vs_reference.py)
- HackComment (python/tests/test_inference_vs_reference.py)
- High CVE: [CVE redacted] (js/yarn.lock)
- High CVE: [CVE redacted] (js/yarn.lock)
- High CVE: [CVE redacted] (website-ng/package-lock.json)
- High CVE: [CVE redacted] (js/yarn.lock)
- High CVE: [CVE redacted] (website-ng/package-lock.json)
- High CVE: [CVE redacted] (js/yarn.lock)
- High CVE: [CVE redacted] (website-ng/package-lock.json)
- High CVE: [CVE redacted] (website-ng/package-lock.json)
- High CVE: [CVE redacted] (js/yarn.lock)
- High CVE: [CVE redacted] (website-ng/package-lock.json)
- …and 67 more

## New (32)

- Coverage not measured — JavaScript/TypeScript suite
- Duplicated block (11 lines × 2) (python/scripts/sync.py)
- FixmeComment (python/src/magika/magika.py)
- FixmeComment (python/src/magika/magika.py)
- FixmeComment (python/src/magika/magika.py)
- FixmeComment (python/src/magika/magika.py)
- FixmeComment (python/src/magika/magika.py)
- FixmeComment (rust/pyo3/src/lib.rs)
- FixmeComment (rust/pyo3/src/lib.rs)
- FixmeComment (rust/pyo3/src/lib.rs)
- High CVE: [GHSA redacted] (js/yarn.lock)
- High CVE: [GHSA redacted] (js/yarn.lock)
- High CVE: [GHSA redacted] (js/yarn.lock)
- High CVE: [GHSA redacted] (js/yarn.lock)
- High CVE: [GHSA redacted] (js/yarn.lock)
- High CVE: [GHSA redacted] (website-ng/package-lock.json)
- High vulnerability: [GHSA redacted] (rust/pyo3/Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- InferredType exposes both a public property `content_type` of type String and a method `content_type()` returning ContentType. This is a direct signature conflict where the same name refers to two different types and access patterns (field vs method).
- …and 12 more

## Changes since last survey

- 36 commits — 33 feature/other, 3 fixes

## By area

- .github/workflows — 8 commits
- rust/pyo3 — 4 commits
- python/scripts — 3 commits
- python/src — 3 commits
- rust/lib — 3 commits
- (repo) — 2 commits
- rust/cli — 2 commits
- rust/rules — 2 commits
- rust/tract-runtime — 2 commits
- .github/CODEOWNERS — 1 commit
- js/src — 1 commit
- python/CHANGELOG.md — 1 commit
- python/pyproject.toml — 1 commit
- rust/color.sh — 1 commit
- rust/ffi — 1 commit
- rust/sync.sh — 1 commit

## Notable commits

- fix: Fix before-script-linux path in poc-pyo3-wheels workflow
- fix: Fix tract convolution padding and check every GPU batch plan at startup (#1466)
- fix: workflow: fix CLI binary staging path for Linux targets and comment out upstream tract-linalg limitations
- change: Add 62 content types to the knowledge base (#1471)
- change: Add multi-platform test matrix and unify CLI binary staging in workflow
- change: Add the magika-rules crate (#1462)
- change: Comment out retired macos-13 (x86_64-apple-darwin) runner from workflow
- change: Compile the bundled rules when the crate is built (#1492)
- change: Detect recursive directory cycles in the CLI (#1463)
- change: Harden the CLI against bad limits, special files and pipeline errors (#1464)
- change: Implement PyO3 wrapper for Magika Python library POC
- change: Link the C library on macOS (#1470)
- change: Look up content types by label (#1484)
- change: Make ia0 code owner of anything below rust (#1498)
- change: Merge pull request #1478 from google/less-coverall-tests
- change: Merge pull request #1483 from google/pyo3
- change: Port PyO3 wrapper to embedded tract inference runtime and update workflow
- change: Read small files once during feature extraction (#1465)
- change: Remove legacy CLI, Click dependency, models dir, and expose model name via PyO3
- change: Remove legacy Python fallback code, implementation data models, and non-critical tests
- …and 16 more
