# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 54 → 41 (-13.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 97 (new)
- Maturity 52 → 50 (-1.3)
- Readiness 46 → 26 (-20.2)
- Security 50 → 48 (-2.0)

## Resolved (20)

- Concentrated knowledge decay
- Coverage not included — suite not readable by the collector
- Critical vulnerability: [GHSA redacted] (Gemfile.lock)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- Largest orphaned file (SourceryRuntime/Sources/Linux/AST/Method_Linux.swift)
- Largest orphaned file (SourceryRuntime/Sources/Linux/AST/Type_Linux.swift)
- Largest orphaned file (SourceryRuntime/Sources/macOS/AST/Type.swift)
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- Rotate the exposed credentials — git history can't be un-committed
- Secret: facebook-page-access-token (Pods/Pods.xcodeproj/project.pbxproj)
- The README mentions 'Sourcery Pro provides a powerful Stencil editor and extends Xcode with the ability to handle live AST templates' but does not describe how to install or configure Sourcery Pro, which is critical for readers who want to buy it. (README.md)
- complexity unreadable for .swift — churn × complexity hotspots could not be measured

## New (18)

- (anonymous) (cognitive 16) (SourceryJS/Resources/ejs.js)
- Dimension evaluation failed
- FileTooLong: Resources/ejs.js (SourceryJS/Resources/ejs.js)
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- Low IaC: DS-0026 (Dockerfile)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- No automated tests
- No tests found
- compile (cognitive 19) (SourceryJS/Resources/ejs.js)
- early-stage repository — too little history to judge knowledge freshness
- scanLine (cognitive 19) (SourceryJS/Resources/ejs.js)
- scanLine (cyclomatic 25) (SourceryJS/Resources/ejs.js)
- single-commit history — no usable git history window to measure hotspots
- single-maintainer — knowledge-concentration (bus factor) risk
