# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 64 (+4.0)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 87 → 88 (+1.0)
- Architecture 87 → 87 (-0.1)
- Maturity 68 → 70 (+2.7)
- Readiness 54 → 59 (+5.1)
- Security 63 → 68 (+4.9)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 57 → 60 (+2.9)

## Resolved (46)

- Boundary-crossing change coupling: page.tsx ↔ ConceptEvaluationSubscriber.ts (src/app/concepts/[id]/page.tsx)
- Boundary-crossing change coupling: page.tsx ↔ ConceptRepositorySQLite.ts (src/app/concepts/[id]/page.tsx)
- Consequences/trade-offs (e.g. AI feedback quality, PDF download option) are not visible in the visible text (Documentation/ADRs/001-introduce-draft-stage-before-concept-stage/diagram.md)
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 26 more

## New (12)

- Change coupling clique: page.tsx, ConceptRepositorySQLite.ts, ConceptEvaluationSubscriber.ts (src/app/concepts/[id]/page.tsx)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (package-lock.json)
