# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 57 → 62 (+4.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Architecture 100 → 100 (+0.0)
- Maturity 55 → 55 (+0.0)
- Readiness 48 → 56 (+7.9)
- Security 70 → 84 (+14.2)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 62 → 62 (+0.0)

## Resolved (42)

- Dependency hygiene not measured — no supported dependency manifest was read
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- …and 22 more

## New (3)

- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)

## Changes since last survey

- 28 commits — 25 feature/other, 3 fixes

## By area

- (root) — 16 commits
- test/pom.xml — 3 commits
- .github/workflows — 2 commits
- core/src — 2 commits
- test/src — 2 commits
- core/pom.xml — 1 commit
- src/checkstyle — 1 commit
- src/main — 1 commit

## Notable commits

- fix: Fix PackedMap.values() returning keys instead of values (#27110)
- fix: Fix missing shadow and blur on the global search results dropdown (#27113)
- fix: Fix self-referential Javadoc links in InMemorySecurityRealm test class (#27119)
- change: Add expression examples to "Restrict where builds can run" help (#27117)
- change: Align GenericWhitespace ws.illegalFollow message with Checkstyle default (#27120)
- change: Lock file maintenance (#27149)
- change: Remove comments from properties and jelly files in shipped war (#27100)
- change: Remove pre 2.0 detached plugins (#27098)
- change: Update actions/checkout action to v7.0.1 (#27123)
- change: Update dependency eslint to v10.8.0 (#27148)
- change: Update dependency io.jenkins.plugins:font-awesome-api to v7.3.1-1013.v0835a_879ec6d (#27124)
- change: Update dependency org.jenkins-ci.main:jenkins-test-harness to v2578 (#27125)
- change: Update dependency org.jenkins-ci.main:remoting to v3384 (#27114)
- change: Update dependency org.jenkins-ci.plugins:junit to v1416 (#27131)
- change: Update dependency postcss to v8.5.21 (#27130)
- change: Update dependency postcss to v8.5.22 (#27147)
- change: Update dependency prettier to v3.9.6 (#27137)
- change: Update dependency sass to v1.101.3 (#27138)
- change: Update dependency sass to v1.101.7 (#27144)
- change: Update dependency sass to v1.102.0 (#27150)
- …and 8 more

## Architecture

- Unchanged — 0 containers · 1 contexts · 0 edges
