# Changelog

## Score

- CAI 31 → 44 (+13.3)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 48 (new)
- Architecture 82 (new)
- Maturity 21 → 40 (+19.4)
- Readiness 15 → 43 (+27.3)
- Security 100 → 57 (-42.9)
- Accessibility 47 (new)

## Resolved (6)

- Dependency hygiene not measured — no supported dependency manifest was read
- No tests found
- No tests — template/sample
- bus factor not measured — no commits were sampled
- early-stage repository — too little history to judge knowledge freshness
- single-commit history — no usable git history window to measure hotspots

## New (157)

- Analyzed solution does not cover the bulk of the repository
- Banned license: iTextSharp.LGPLv2.Core
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (micro-frontend/customer-frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (micro-frontend/customer-frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (micro-frontend/customer-frontend/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (token-based-auth-core-react/ecommerce.client/package-lock.json)
- Critical CVE: [GHSA redacted] (micro-frontend/customer-frontend/package-lock.json)
- …and 137 more

## API surface

- 163 added · 0 removed (a removed endpoint is potentially breaking)

## Added endpoints (163)

- DELETE /api/accounts/{id}
- DELETE /api/bookings/{id}
- DELETE /api/catalogitem/delete/{id}
- DELETE /api/catalogitems/{id}
- DELETE /api/categories/{id}
- DELETE /api/customer/delete/{id}
- DELETE /api/customer/deletebulkdata
- DELETE /api/customer/deletecustomer/{id}
- DELETE /api/customer/{id}
- DELETE /api/customers/{id}
- DELETE /api/departments/{id}
- DELETE /api/district/{id}
- DELETE /api/documents/{id}
- DELETE /api/employee/deletebulkdata
- DELETE /api/employees/deleteemployee/{id}
- DELETE /api/employees/{id}
- DELETE /api/order/{id}
- DELETE /api/orders/delete/{id}
- DELETE /api/product/{id}
- DELETE /api/products/delete/{id}
- …and 143 more
