# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 76 → 78 (+2.0)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 97 (-3.4)
- Architecture 100 → 94 (-5.8)
- Maturity 76 → 73 (-3.6)
- Readiness 71 → 79 (+8.3)
- Security 71 → 76 (+5.1)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (44)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Further sole-owners (lower concentration)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 24 more

## New (89)

- (anonymous) (cognitive 18) (.mcp/dart-server/server.js)
- AppButton.build (cognitive 17) (packages/app_ui/lib/src/widgets/app_button.dart)
- AppButton.build (cyclomatic 17) (packages/app_ui/lib/src/widgets/app_button.dart)
- Change coupling: auth_repository_impl.dart ↔ bookmarks_sync_service.dart (packages/features/auth/lib/src/data/repositories/auth_repository_impl.dart)
- Change coupling: bookmark_detail_widgets.dart ↔ bookmarks_list_widgets.dart (packages/features/bookmarks/lib/src/presentation/widgets/bookmark_detail_widgets.dart)
- Change coupling: bookmark_detail_widgets.dart ↔ profile_widgets.dart (packages/features/bookmarks/lib/src/presentation/widgets/bookmark_detail_widgets.dart)
- Change-coupling hub: bookmarks_list_bloc.dart → bookmark_form_bloc.dart, bookmark_detail_widgets.dart, profile_widgets.dart (packages/features/bookmarks/lib/src/presentation/bloc/bookmarks_list/bookmarks_list_bloc.dart)
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Duplicated block (10–11 lines × 3) (packages/features/auth/lib/src/presentation/screens/register_screen.dart)
- Duplicated block (12 lines × 2) (packages/app_ui/lib/src/widgets/app_empty_view.dart)
- Duplicated block (13 lines × 2) (packages/features/bookmarks/lib/src/presentation/widgets/bookmark_form_fields.dart)
- Duplicated block (14 lines × 2) (packages/features/bookmarks/lib/src/data/sync/bookmarks_sync_service.dart)
- Duplicated block (16 lines × 2) (packages/features/auth/lib/src/data/repositories/auth_repository_impl.dart)
- Duplicated block (16 lines × 2) (packages/features/bookmarks/lib/src/data/repositories/bookmarks_repository_impl.dart)
- Duplicated block (18 lines × 2) (packages/features/bookmarks/lib/src/data/repositories/bookmarks_repository_impl.dart)
- Duplicated block (18 lines × 2) (packages/features/bookmarks/lib/src/data/sync/bookmarks_sync_adapter.dart)
- Duplicated block (18 lines × 2) (packages/features/bookmarks/lib/src/presentation/widgets/bookmark_detail_widgets.dart)
- Duplicated block (19 lines × 2) (packages/features/bookmarks/lib/src/data/sync/bookmarks_sync_adapter.dart)
- Duplicated block (29 lines × 2) (packages/features/auth/lib/src/presentation/screens/login_screen.dart)
- …and 69 more

## Changes since last survey

- 15 commits — 9 feature/other, 6 fixes

## By area

- .github/workflows — 5 commits
- (repo) — 4 commits
- packages/features — 2 commits
- .githooks/pre-push — 1 commit
- .mcp/dart-server — 1 commit
- android/build.gradle.kts — 1 commit
- packages/database_drift — 1 commit

## Notable commits

- fix: fix(ci): mark the placeholder-credential steps as Firebase-only (#198)
- fix: fix(ci): mark the scaffolding that only this repository needs (#196)
- fix: fix: leave scaffolds formatted, and gate on it (#195)
- fix: fix: let the pre-push hook run under git's hook environment (#204)
- fix: fix: make every scaffold configuration compile, analyze and test clean (#194)
- fix: fix: regenerate stale di.module.dart across four packages (#202)
- change: Merge pull request #190 from kido-luci/dependabot/bundler/android/bundler-7931bf9ce8
- change: Merge pull request #191 from kido-luci/dependabot/gradle/android/gradle-minor-and-patch-2314945e7c
- change: Merge pull request #193 from kido-luci/dependabot/npm_and_yarn/dot-mcp/dart-server/npm_and_yarn-c3809050de
- change: Merge pull request #199 from kido-luci/dependabot/github_actions/github-actions-d2809b2831
- change: chore(deps): bump body-parser
- change: chore(deps): bump github/codeql-action in the github-actions group
- change: chore(deps): bump the gradle-minor-and-patch group across 1 directory with 2 updates
- change: chore(deps): bump the pub-minor-and-patch group, capping drift at 2.34.0 (#200)
- change: chore: gate di.module.dart against generator drift (#203)
