# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 71 → 49 (-22.3)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 80 → 76 (-4.1)
- Maturity 63 → 64 (+0.5)
- Readiness 73 → 30 (-42.4)
- Security 75 → 67 (-8.0)

## Resolved (5)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1

## New (23)

- Change coupling: cli.ts ↔ deps.ts (src/cli.ts)
- Change coupling: cli.ts ↔ repl.ts (src/cli.ts)
- Change coupling: core.ts ↔ vendor-core.ts (src/core.ts)
- Change coupling: goods.ts ↔ index.ts (src/goods.ts)
- Change coupling: goods.ts ↔ repl.ts (src/goods.ts)
- Change coupling: util.ts ↔ vendor-core.ts (src/util.ts)
- Dimension evaluation failed
- FileTooLong: test/core.test.js (test/core.test.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- Hotspot: build/vendor-extra.cjs (build/vendor-extra.cjs)
- Hotspot: src/core.ts (src/core.ts)
- Low IaC: DS-0026 (dcr/Dockerfile)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- …and 3 more
