# Changelog

## Score

- CAI 55 → 59 (+3.7)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 93 → 93 (+0.0)
- Architecture 100 → 86 (-13.8)
- Maturity 52 → 52 (-0.1)
- Readiness 57 → 58 (+1.4)
- Security 43 → 54 (+11.5)
- Event Sourcing 100 → 100 (+0.0)

## Resolved (3)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1

## New (26)

- Documentation: no contributor guidance (README.md)
- Inconsistent naming for factory methods creating the same type. One uses 'from_...' with descriptive parameters, the other uses 'from_...' but implies a different construction path. More critically, compare with ItemId which has multiple 'from_...' variants (from_base16, from_base62, from_raw, from_uri, from_local). While distinct, the lack of a unified 'parse' or 'try_from' pattern across ID types is a minor stylistic inconsistency, but the real issue is below.
- Medium advisory (unsound): RUSTSEC-2026-0306 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Off the main sequence: psst-core
- Off-boarding risk: anonymized user #1
- Outdated: crossbeam-channel
- Outdated: data-encoding
- Outdated: env_logger
- Outdated: image
- Outdated: log
- Outdated: open
- Outdated: parking_lot
- Outdated: rangemap
- Outdated: regex
- Outdated: serde
- Outdated: serde_json
- Outdated: souvlaki
- Outdated: tempfile
- Outdated: time
- …and 6 more
