# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 46 → 46 (+0.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 90 → 87 (-3.3)
- Architecture 43 → 45 (+1.1)
- Maturity 76 → 77 (+0.2)
- Readiness 53 → 55 (+1.3)
- Security 33 → 33 (-0.4)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (27)

- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (packages/cli/templates/package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: packages/core/src/commands/repository.ts (packages/core/src/commands/repository.ts)
- Hotspot: packages/core/src/data-store/dynamodb.service.ts (packages/core/src/data-store/dynamodb.service.ts)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- Low CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low vulnerability: [GHSA redacted] (packages/cli/templates/package-lock.json)
- Low vulnerability: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (packages/cli/templates/infra-local/appsync-simulator/package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- …and 7 more

## New (29)

- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (package-lock.json)
- Critical vulnerability: [GHSA redacted] (packages/cli/templates/package-lock.json)
- High CVE: [GHSA redacted] (packages/cli/templates/infra-local/appsync-simulator/package-lock.json)
- High CVE: [GHSA redacted] (packages/cli/templates/infra-local/appsync-simulator/package-lock.json)
- High CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- High CVE: [GHSA redacted] (packages/cli/templates/package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (packages/cli/templates/package-lock.json)
- High vulnerability: [GHSA redacted] (packages/cli/templates/package-lock.json)
- …and 9 more

## Changes since last survey

- 31 commits — 11 feature/other, 20 fixes

## By area

- (repo) — 11 commits
- packages/cli — 5 commits
- packages/core — 5 commits
- (root) — 3 commits
- packages/directory — 3 commits
- packages/master — 2 commits
- .github/workflows — 1 commit
- packages/mcp-server — 1 commit

## Notable commits

- fix: Merge pull request #337 from mbc-net/fix/configurable-port-improvements
- fix: Merge pull request #487 from mbc-net/fix/infra-template-ci-gap
- fix: Merge pull request #488 from mbc-net/ci/fix-dep-update-output-format
- fix: Merge pull request #496 from mbc-net/fix/v140-changelog
- fix: Merge remote-tracking branch 'origin/develop' into fix/configurable-port-improvements
- fix: Merge remote-tracking branch 'origin/develop' into fix/configurable-port-improvements
- fix: ci: fix "Invalid format" error in dependency-update-test output
- fix: fix(cli): harden Step Functions Local registration in trigger_ddb_stream
- fix: fix(cli): honor LOCAL_SFN_PORT and fail fast in local dev tooling
- fix: fix(cli): make cognito-local port configurable via LOCAL_COGNITO_PORT
- fix: fix(cli): restore serverless-offline startup wait timeout to 100s
- fix: fix(cli): treat StateMachineAlreadyExists as success in SFN registration
- fix: fix(core)+docs: non-empty tableName guard, shared-table & constant-coupling notes
- fix: fix(core): correct async PRISMA resolution + soften duplicate-alias guard to warn
- fix: fix(core): gate StateMachineDoesNotExist swallow on IS_OFFLINE, not SFN_ENDPOINT
- fix: fix(core): guard registerEventHandlerAlias misuse (orphan alias + dropped handlers)
- fix: fix(core): re-throw StateMachineDoesNotExist outside local Step Functions
- fix: fix(core): reject Prisma class in async factory + guard CommandModule.registerAsync
- fix: fix(core): resolve data-sync handler PRISMA across module boundary + guard duplicate table alias
- fix: fix(master): warn that renaming the central master table breaks TTL/sequence config
- …and 11 more
