# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 59 → 64 (+5.0)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 77 → 86 (+9.6)
- Architecture 100 → 100 (+0.0)
- Maturity 51 → 50 (-1.5)
- Readiness 49 → 65 (+15.3)
- Security 87 → 86 (-0.7)

## Resolved (17)

- Client.writePump (cognitive 18) (examples/chat/client.go)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (11 lines × 2) (conn.go)
- Duplicated block (9 lines × 2) (conn.go)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2024-2598 (go.mod)
- Medium: security finding (details withheld)
- No exposed public API
- Test reliability not included
- main.echoCopy (cognitive 23) (examples/autobahn/server.go)
- main.echoReadAll (cognitive 40) (examples/autobahn/server.go)
- main.writer (cognitive 21) (examples/filewatch/main.go)

## New (20)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (12 lines × 2) (conn.go)
- Duplicated block (12 lines × 2) (conn.go)
- Flaky test: .::github.com/gorilla/websocket.TestHTTPSProxyHTTPBackend
- Flaky test: .::github.com/gorilla/websocket.TestTLSValidationErrors
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2024-2598 (go.mod)
- MethodTooLong: Conn.advanceFrame (conn.go)
- MethodTooLong: Dialer.DialContext (client.go)
- No dependency advisory monitoring
- Outdated: golang.org/x/net
- TodoComment (prepared.go)
- TooManyFields: Conn (conn.go)
