# Changelog

## Score

- CAI 38 → 39 (+0.9)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 80 → 80 (-0.2)
- Architecture 65 → 70 (+5.5)
- Maturity 57 → 57 (-0.0)
- Readiness 49 → 44 (-4.2)
- Security 17 → 20 (+3.3)
- Domain Modelling 82 → 78 (-3.3)
- Performance 71 (new)

## Resolved (225)

- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [CVE redacted] (package-lock.json)
- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (infrastructure/exit-tool/perform_exodus/yarn.lock)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical vulnerability: [GHSA redacted] (infrastructure/exit-tool/perform_exodus/yarn.lock)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (docs/launch.md)
- Documentation: written for insiders (README.md)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- …and 205 more

## New (43)

- Ambiguous parameter naming and overlapping intent. `account_info` takes a generic `account_id_or_address` string and a `state_type` to filter, while `account_full_info` takes the same generic identifier but presumably returns all states. The naming convention `account_info` vs `account_full_info` is inconsistent with other methods like `block_by_position` vs `block_transactions`. Furthermore, `account_id_or_address` is a poor API design choice compared to using a dedicated enum or distinct methods for ID vs Address lookups.
- Critical vulnerability: [GHSA redacted] (infrastructure/exit-tool/perform_exodus/yarn.lock)
- End-of-life runtime: Rust 1.91
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- Inconsistent parameter structure for transaction submission. `submit_tx` takes a transaction and a signature separately. `submit_batch` takes a `TxWithSignature` (which already contains the signature) and a separate `EthBatchSignatures`. This implies `TxWithSignature` might be a list or a single item, but the naming and structure are confusing compared to the single tx case.
- Inconsistent parameter typing for token identification. `token_by_id` uses `TokenLike` (likely a struct/enum), while `token_price` uses `TokenLike` for the first arg but `str` for `token_id_or_usd`. This suggests `TokenLike` might not be fully utilized or that `token_price` should also accept a structured token identifier for consistency.
- …and 23 more
