# Changelog

## Score

- CAI 60 → 65 (+4.6)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 62 → 63 (+0.1)
- Architecture 94 → 95 (+0.9)
- Maturity 67 → 67 (+0.0)
- Readiness 69 → 70 (+0.9)
- Security 52 → 62 (+9.5)

## Resolved (5)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)

## New (6)

- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): @types/html-minifier-terser
- Outdated (npm): html-minifier-terser
- Outdated (npm): lodash
- Outdated (npm): tapable
