# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 58 → 62 (+4.1)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 94 → 93 (-0.4)
- Architecture 96 → 94 (-1.8)
- Maturity 65 → 65 (-0.1)
- Readiness 46 → 51 (+4.9)
- Security 52 → 60 (+8.0)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (19)

- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (examples/src/gcp/README.md)
- Documentation: no installation or build instructions (examples/src/health/README.md)
- Documentation: no project overview (examples/src/health/README.md)
- Duplicated block (12–13 lines × 2) (grpc/src/client/load_balancing/child_manager.rs)
- Duplicated block (25 lines × 2) (interop/src/server_prost.rs)
- Duplicated block (8 lines × 2) (interop/src/server_protobuf.rs)
- Duplicated block (8 lines × 2) (tonic-build/src/client.rs)
- Hotspot: grpc-protobuf-build/src/lib.rs (grpc-protobuf-build/src/lib.rs)
- Hotspot: grpc-protobuf/src/status.rs (grpc-protobuf/src/status.rs)
- Hotspot: tonic-prost-build/src/lib.rs (tonic-prost-build/src/lib.rs)
- Hotspot: tonic/src/codec/decode.rs (tonic/src/codec/decode.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- Off-boarding risk: anonymized user #3
- OutlierStatsRegistry::run_housekeeping (cognitive 31) (tonic-xds/src/client/loadbalance/outlier_detection.rs)
- TodoComment (grpc/src/client/load_balancing/child_manager.rs)
- TodoComment (grpc/src/server/mod.rs)
- TodoComment (tonic-protobuf/src/lib.rs)

## New (36)

- AdsWorker::add_watcher (cognitive 40) (xds-client/src/client/worker.rs)
- AdsWorker::add_watcher (cyclomatic 16) (xds-client/src/client/worker.rs)
- AdsWorker::run_stream_task (cognitive 19) (xds-client/src/client/worker.rs)
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Documentation: no project overview (tonic/benches-disabled/README.md)
- Duplicate WorkScheduler types in different modules. Both `grpc.client.name_resolution.WorkScheduler` and `grpc.client.load_balancing.WorkScheduler` have the same signature `schedule_work(data: WorkData)`. It is unclear if these are distinct interfaces or if one is a duplicate/refactor artifact.
- Duplicated block (10 lines × 2) (xds-client/src/client/worker.rs)
- Duplicated block (11–12 lines × 2) (grpc/src/client/load_balancing/child_manager.rs)
- Duplicated block (11–15 lines × 2) (grpc-protobuf/src/server/client_streaming.rs)
- Duplicated block (31 lines × 2) (grpc-protobuf/src/server/server_streaming.rs)
- Duplicated block (8–10 lines × 2) (tonic-build/src/client.rs)
- Edited copy of a member (35 corresponding lines) (grpc-protobuf/src/server/server_streaming.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: xds-client/src/client/worker.rs (xds-client/src/client/worker.rs)
- Inconsistent API surface for CallOptions between client and server. The client-side CallOptions exposes mutable setters and getters for properties like deadline, whereas the server-side CallOptions only exposes a constructor with no visible property accessors or setters. This suggests a divergence in how call configuration is handled or exposed.
- Inconsistent interceptor signatures. Client interceptors return streams `(SendStream, RecvStream)`, while server interceptors return `Trailers` and take explicit `tx`/`rx` streams. This makes it difficult to write shared interceptor logic or understand the flow.
- Inconsistent method naming and signatures for ChannelController. The name resolution controller uses `update` with a `ResolverUpdate`, while the load balancing controller uses `update_picker` with an `LbState`. These are likely part of the same controller interface but are split or named inconsistently.
- Inconsistent method naming for receiving messages. Client uses `recv`, while server uses `next`. These perform the same logical operation (advancing the stream and retrieving the next message) but have different names and return types (`ResponseStreamItem` vs `Result`).
- …and 16 more

## Changes since last survey

- 28 commits — 25 feature/other, 3 fixes

## By area

- grpc/src — 11 commits
- tonic-xds/src — 7 commits
- xds-client/src — 4 commits
- .github/workflows — 1 commit
- examples/generated — 1 commit
- grpc-xds/Cargo.toml — 1 commit
- tonic-prost/src — 1 commit
- tonic-types/src — 1 commit
- tonic/src — 1 commit

## Notable commits

- fix: Fix Code-QL breakage with CI configuration. (#2870)
- fix: fix(types): Serialize `BadRequest::FieldViolation` `reason` and `localized_message` (#2461)
- fix: grpc/service_config: fix flaky service_config tests caused by a test LB policy name collision (#2892)
- change: Make ParsedLbConfig available to load balancers, include child selection mechanism. (#2887)
- change: chore(xds): bump crates to 0.1.0-alpha.4 (#2886)
- change: feat(tonic-xds): expose ADS message size limit knobs in config (#2879)
- change: feat(tonic-xds): implement gRFC A50 outlier detection success-rate algorithm (#2673)
- change: feat(tonic-xds): make outlier detection transport-agnostic (#2849)
- change: feat(tonic-xds): support A65 ADS TLS credentials (#2869)
- change: grpc-protobuf: add server codegen utils (#2818)
- change: grpc/attributes: add remove API and inline persistent list (#2891)
- change: grpc/client/load_balancing: add endpoint filtering utils (#2850)
- change: grpc/client: avoid unnecessary CallOptions clone (#2872)
- change: grpc/lb: add SubchannelUpdate and remove LbPolicy::subchannel_update (#2873)
- change: grpc/lb: require LbConfig in resolver_update (#2880)
- change: grpc/service_config: memoize default_lb_policy via LazyLock (#2862)
- change: grpc: allow external TLS implementations with __unstable (#2842)
- change: grpc: ignore large enum variant clippy in Lazy (#2874)
- change: prost: relax codec Default bounds (#2681)
- change: protoc-gen-rust-grpc: add gRPC server support (#2867)
- …and 8 more
