# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 44 → 44 (-0.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 91 → 84 (-6.7)
- Architecture 94 → 98 (+3.4)
- Maturity 51 → 38 (-13.1)
- Readiness 17 → 22 (+5.4)
- Security 80 → 91 (+10.9)

## Resolved (5)

- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API

## New (97)

- Change coupling: train_grpo.py ↔ train_ppo.py (trainer/train_grpo.py)
- Critical CVE: [GHSA redacted] (requirements.txt)
- DPODataset.generate_loss_mask (cognitive 17) (dataset/lm_dataset.py)
- Duplicated block (10 lines × 2) (dataset/lm_dataset.py)
- Duplicated block (11 lines × 2) (trainer/train_grpo.py)
- Duplicated block (12–14 lines × 4) (trainer/train_distillation.py)
- Duplicated block (15 lines × 3) (trainer/train_full_sft.py)
- Duplicated block (2–11 lines × 5) (trainer/train_distillation.py)
- Duplicated block (5 lines × 2) (eval_llm.py)
- Duplicated block (5 lines × 2) (eval_llm.py)
- Duplicated block (5 lines × 2) (scripts/convert_model.py)
- Duplicated block (5 lines × 2) (trainer/train_agent.py)
- Duplicated block (5 lines × 2) (trainer/train_agent.py)
- Duplicated block (5 lines × 2) (trainer/train_grpo.py)
- Duplicated block (5 lines × 3) (trainer/train_full_sft.py)
- Duplicated block (5–7 lines × 2) (trainer/train_agent.py)
- Duplicated block (6 lines × 2) (dataset/lm_dataset.py)
- Duplicated block (6 lines × 2) (scripts/web_demo.py)
- Duplicated block (7 lines × 2) (scripts/web_demo.py)
- Duplicated block (7 lines × 2) (trainer/train_agent.py)
- …and 77 more

## Changes since last survey

- 46 commits — 19 feature/other, 27 fixes

## By area

- (repo) — 16 commits
- (root) — 13 commits
- trainer/train_agent.py — 5 commits
- model/model_minimind.py — 4 commits
- dataset/lm_dataset.py — 1 commit
- scripts/eval_toolcall.py — 1 commit
- scripts/serve_openai_api.py — 1 commit
- trainer/rollout_engine.py — 1 commit
- trainer/train_full_sft.py — 1 commit
- trainer/train_grpo.py — 1 commit
- trainer/train_tokenizer.py — 1 commit
- trainer/trainer_utils.py — 1 commit

## Notable commits

- fix: Merge pull request #769 from qizwiz/fix/llm-response-unguarded
- fix: Merge pull request #829 from DaoyuanLi2816/fix/dpo-paired-think-format
- fix: Merge pull request #847 from a0917-cell/fix/safe-math-eval
- fix: Merge pull request #854 from basil-k-aji-dev/fix/rl-ddp-grad-sync
- fix: Merge pull request #857 from wbbeyourself/fix-ctrl-c-exception
- fix: Merge pull request #859 from basil-k-aji-dev/fix/moe-router-gradient-topk1
- fix: Merge pull request #860 from Linxiushen/fix-tokenizer-pretrain-format
- fix: Merge pull request #863 from Linxiushen/fix-fp16-attention-mask-nan
- fix: Merge pull request #864 from Linxiushen/fix-nonstream-max-tokens
- fix: Merge pull request #865 from Linxiushen/fix-requirements-missing-fastapi
- fix: Merge pull request #867 from DaoyuanLi2816/fix/lora-inference-paths
- fix: Merge pull request #868 from DaoyuanLi2816/fix/final-accumulation-checkpoint
- fix: [fix] float16 下 attention mask 的 -1e9 溢出成 -inf，导致整条序列输出 NaN
- fix: [fix] keep DPO preference pair think formatting aligned
- fix: [fix] keep agent rollout token-aligned #850
- fix: [fix] keep the MoE router trainable at num_experts_per_tok=1
- fix: [fix] replace tool eval() with an AST math evaluator
- fix: [fix] requirements.txt 缺 fastapi/uvicorn，按 README 跑 serve_openai_api.py 直接崩
- fix: [fix] residual step order
- fix: [fix] restore top-1 router gradient #858
- …and 26 more
