# Changelog

## Score

- CAI 49 → 50 (+0.9)

## Lenses

- Code Health 61 → 61 (+0.0)
- Architecture 81 → 81 (+0.0)
- Maturity 47 → 47 (+0.0)
- Readiness 39 → 39 (+0.0)
- Security 64 → 64 (+0.0)
- Domain Modelling 70 → 100 (+30.3)
- Event-Driven 100 → 100 (+0.0)
- Event Sourcing 100 → 100 (+0.0)

## Resolved (10)

- High CVE: System.Net.Security 4.3.0
- High CVE: System.Net.Security 4.3.0
- Medium CVE: SharpCompress 0.23.0
- Medium CVE: SharpCompress 0.23.0
- Medium CVE: System.Net.Security 4.3.0
- Medium CVE: System.Net.Security 4.3.0
- The architecture section describes a single public API gateway routing HTTP requests to microservices but does not explain how the event sourcing/Outbox pattern routes events between services or how the Outbox is persisted. (README.md)
- redundant comment (Infrastructure/Consul/ConsulExtensions.cs)
- redundant comment (Infrastructure/Consul/ConsulExtensions.cs)
- redundant comment (Infrastructure/Consul/ConsulExtensions.cs)

## New (10)

- High CVE: System.Net.Security 4.3.0
- High CVE: System.Net.Security 4.3.0
- Medium CVE: SharpCompress 0.23.0
- Medium CVE: SharpCompress 0.23.0
- Medium CVE: System.Net.Security 4.3.0
- Medium CVE: System.Net.Security 4.3.0
- redundant comment (Infrastructure/Consul/ConsulExtensions.cs)
- redundant comment (Infrastructure/Consul/ConsulExtensions.cs)
- redundant comment (Infrastructure/Consul/ConsulExtensions.cs)
- redundant comment (Infrastructure/Core/ExceptionFilter.cs)

## API surface

- Unchanged — 10 HTTP endpoints
