# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 62 → 65 (+3.1)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 73 → 70 (-2.6)
- Architecture 67 → 73 (+6.0)
- Maturity 59 → 55 (-3.7)
- Readiness 78 → 85 (+7.0)
- Security 60 → 82 (+21.2)
- Performance 85 (new)

## Resolved (66)

- Documentation: contradicts the code (docs/index.html)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 46 more

## New (63)

- Documentation: no architecture or design documentation (docs/index.html)
- Documentation: no project overview (docs/index.html)
- FileTooLong: animation-glitch/app.js (docs/animation-glitch/app.js)
- FileTooLong: src/animations.ts (packages/inferno-animation/src/animations.ts)
- FileTooLong: uibench/custom-uibench.js (docs/uibench/custom-uibench.js)
- FunctionTooLong: animations.runMove (packages/inferno-animation/src/animations.ts)
- FunctionTooLong: custom-uibench.initTests (docs/uibench/custom-uibench.js)
- FunctionTooLong: patching.patchElement (packages/inferno/src/DOM/patching.ts)
- FunctionTooLong: props.patchProp (packages/inferno/src/DOM/props.ts)
- FunctionTooLong: renderToString.renderVNodeToString (packages/inferno-server/src/renderToString.ts)
- High: security finding (details withheld)
- Hotspot: packages/inferno-create-element/src/index.ts (packages/inferno-create-element/src/index.ts)
- Hotspot: packages/inferno-server/src/renderToString.queuestream.ts (packages/inferno-server/src/renderToString.queuestream.ts)
- Hotspot: packages/inferno-server/src/renderToString.stream.ts (packages/inferno-server/src/renderToString.stream.ts)
- Hotspot: packages/inferno-server/src/renderToString.ts (packages/inferno-server/src/renderToString.ts)
- Hotspot: packages/inferno/src/DOM/mounting.ts (packages/inferno/src/DOM/mounting.ts)
- Hotspot: packages/inferno/src/DOM/patching.ts (packages/inferno/src/DOM/patching.ts)
- Hotspot: packages/inferno/src/DOM/props.ts (packages/inferno/src/DOM/props.ts)
- Hotspot: packages/inferno/src/DOM/unmounting.ts (packages/inferno/src/DOM/unmounting.ts)
- Hotspot: packages/inferno/src/core/implementation.ts (packages/inferno/src/core/implementation.ts)
- …and 43 more

## Changes since last survey

- 73 commits — 11 feature/other, 62 fixes

## By area

- packages/inferno — 25 commits
- packages/inferno-server — 17 commits
- packages/inferno-router — 5 commits
- (root) — 3 commits
- packages/inferno-compat — 3 commits
- packages/inferno-hydrate — 3 commits
- packages/inferno-mobx — 3 commits
- packages/inferno-animation — 2 commits
- packages/inferno-create-element — 2 commits
- scripts/rollup — 2 commits
- .github/workflows — 1 commit
- demo/inferno-router-demo — 1 commit
- docs/animation-glitch — 1 commit
- docs/autofocus_bug — 1 commit
- packages/inferno-clone-vnode — 1 commit
- packages/inferno-hyperscript — 1 commit
- packages/inferno-redux — 1 commit
- scripts/babel — 1 commit

## Notable commits

- fix: Fix an issue where hydration uses a vNode that is already mounted in another position of the same tree or in another container, it uses the same vNode object for the server rendered DOM node. After the next render one of the positions is not updated.
- fix: fix an issue where CI never runs the tests that need a DOM-free environment
- fix: fix an issue where Prompt stops blocking after the first confirmed transition
- fix: fix an issue where Redirect drops the state of a location object
- fix: fix an issue where Redirect in a Switch goes to its to path without the params
- fix: fix an issue where RenderQueueStream never ends as a readable stream
- fix: fix an issue where Switch crashes on false, null and undefined children
- fix: fix an issue where Switch drops the key of the matched Route
- fix: fix an issue where TypeScript finds the types of every package only through a fallback
- fix: fix an issue where a Fragment created with an empty children array and explicit child flags renders nothing on the server, while in the browser it renders an empty text node. Server rendered HTML then does not match the browser. When the server renders the placeholder that other empty Fragments get, hydration keeps the Fragment with the empty array and the next render throws "Cannot read properties of null (reading 'nextSibling')".
- fix: fix an issue where a Fragment with exactly one child is removed, the child is not unmounted. Class components inside it never get componentWillUnmount, refs are not cleared, and the content of a Portal inside it stays in the portal container.
- fix: fix an issue where a Portal is re-rendered with a different container and its child is a component or a Fragment, rendering throws "Failed to execute 'removeChild' on 'Node': parameter 1 is not of type 'Node'". The content is not moved to the new container.
- fix: fix an issue where a component is unmounted and mounted again, losing its state, when the element rendered in its place is equal but was normalized as the child of some other element earlier.
- fix: fix an issue where a hoisted vNode with multiple children renders the children of some other vNode after an element of the same type has been patched in its place. This is trade-off between performance and correctness. Modern  browsers handle try catch - performance really well. Optimize later.
- fix: fix an issue where a ref passed through spread props to a forwardRef component is lost
- fix: fix an issue where a vNode referenced outside of render and placed in two positions shares its DOM node and state between them. After the next render one of the positions is not updated, or rendering throws NotFoundError.
- fix: fix an issue where a vNode referenced outside of render is cloned every time it is rendered again, even when it is rendered in the same position as before. Hoisted vNodes, the root passed to render() again and the root returned by a component allocate a new vNode on every render.
- fix: fix an issue where an element vNode with multiple children that is rendered in two places is updated only in one of them afterwards.
- fix: fix an issue where an option without a value prop gets the value "undefined"
- fix: fix an issue where cloneVNode writes children into the props passed to it
- …and 53 more
