# Changelog

## Score

- CAI 63 → 66 (+3.3)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 84 → 84 (+0.0)
- Architecture 100 → 98 (-2.0)
- Maturity 56 → 55 (-0.3)
- Readiness 83 → 79 (-3.5)
- Security 51 → 63 (+12.0)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (3)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1

## New (44)

- Confusing method naming and intent. `resolve_audio` sounds like it performs the network resolution, while `try_get_url` sounds like it retrieves a cached or previously resolved URL. However, `try_get_url` likely also performs resolution if not cached. The prefix `try_` is misleading in Rust where `try_` often implies fallibility that is handled via `?` or `Result`, but here it's just a getter. `resolve_audio` is domain-specific, while `try_get_url` is generic.
- Documentation: no project overview (README.md)
- Inconsistent builder pattern return types. `with_password` and `with_access_token` return `Self` (allowing method chaining), while `with_blob` returns `Result`. This breaks the fluent builder pattern and forces the user to handle errors differently depending on which credential type they are setting.
- Inconsistent setter return types. Most setters return `()` (unit), but `set_user_attribute` returns `String`. This suggests `set_user_attribute` might be returning the previous value or a new key, which is an unexpected side effect for a setter and inconsistent with the rest of the API.
- Inconsistent volume control API. `set_volume` takes an absolute `u16`, while `volume_up` and `volume_down` take no arguments (implying a fixed step). This is acceptable, but `set_volume` returns `Result` while `volume_up/down` also return `Result`. If the volume steps are fixed, the step size is hidden. More importantly, `set_volume` is the only way to set an absolute value, but the lack of a `get_volume` method in the public surface (only `Cache.volume()` exists) makes the API asymmetric.
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Off the main sequence: librespot-core
- Off the main sequence: librespot-oauth
- Off-boarding risk: anonymized user #1
- Outdated: async-trait
- Outdated: bytes
- Outdated: data-encoding
- Outdated: env_logger
- Outdated: flate2
- Outdated: futures-core
- Outdated: futures-util
- Outdated: governor
- Outdated: http
- Outdated: http-body-util
- Outdated: hyper
- …and 24 more
