# Changelog

## Score

- CAI 43 → 43 (+0.2)

## Lenses

- Code Health 58 → 58 (+0.2)
- Architecture 90 → 90 (+0.0)
- Maturity 46 → 46 (+0.0)
- Readiness 28 → 28 (+0.0)
- Security 66 → 66 (+0.0)
- Domain Modelling 66 → 68 (+2.9)

## Resolved (17)

- High CVE: Microsoft.AspNetCore.Identity 2.0.0
- High CVE: Microsoft.AspNetCore.Identity 2.0.0
- High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.0.0
- High CVE: System.Net.Security 4.0.0
- High CVE: System.Net.Security 4.0.0
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- Medium CVE: Microsoft.AspNetCore.All 2.0.0
- Medium CVE: Microsoft.AspNetCore.All 2.0.0
- Medium CVE: System.Net.Security 4.0.0
- Medium CVE: System.Net.Security 4.0.0
- Medium CVE: System.Net.Security 4.3.0
- Medium CVE: System.Net.Security 4.3.0
- The environment setup section is long but cut mid-sentence by the scanner: it describes running up-kafka-mongodb.sh and docker ps output, then clips before stating how to run the Bearer Auth API or Consumer API. (README.md)
- Thin analysable surface across projects

## New (15)

- High CVE: Microsoft.AspNetCore.Identity 2.0.0
- High CVE: Microsoft.AspNetCore.Identity 2.0.0
- High CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.0.0
- High CVE: System.Net.Security 4.0.0
- High CVE: System.Net.Security 4.0.0
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Net.Security 4.3.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- High CVE: System.Security.Cryptography.Xml 4.4.0
- Medium CVE: Microsoft.AspNetCore.All 2.0.0
- Medium CVE: Microsoft.AspNetCore.All 2.0.0
- Medium CVE: System.Net.Security 4.0.0
- Medium CVE: System.Net.Security 4.0.0
- Medium CVE: System.Net.Security 4.3.0
- Medium CVE: System.Net.Security 4.3.0

## API surface

- Unchanged — 16 HTTP endpoints
