# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 30 → 31 (+0.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 74 → 83 (+8.5)
- Architecture 62 → 83 (+20.5)
- Maturity 56 → 67 (+11.4)
- Readiness 30 → 30 (-0.2)
- Security 80 → 55 (-24.4)
- Domain Modelling 10 → 10 (+0.0)

## Resolved (15)

- Boundary-crossing change coupling: app.ts ↔ app.ts (src/booking/src/app.ts)
- Boundary-crossing change coupling: app.ts ↔ app.ts (src/booking/src/app.ts)
- Boundary-crossing change coupling: app.ts ↔ app.ts (src/booking/src/app.ts)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Dormant codebase
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Scanner failed to run — not a clean result
- Secret: jwt (booking.rest)
- Secret: jwt (booking.rest)
- Test reliability not included
- The Goals of This Project section lists vertical-slice architecture but does not explain what slice each service represents or how slices interrelate. (README.md)
- single-maintainer — knowledge-concentration (bus factor) risk

## New (338)

- Coverage not measured — JavaScript/TypeScript suite
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no committed lockfile, so no resolved version to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High IaC: KSV-0014 (deployments/kubernetes/booking-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/flight-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/identity-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/jaeger-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/otel-collector-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/passenger-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/postgres-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/rabbitmq-deployment.yaml)
- High IaC: KSV-0014 (deployments/kubernetes/zipkin-deployment.yaml)
- High IaC: KSV-0109 (deployments/kubernetes/configmap.yaml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0002 (docker-compose.yml)
- High IaC: WD-COMPOSE-0003 (docker-compose.yml)
- High IaC: WD-COMPOSE-0003 (docker-compose.yml)
- High IaC: WD-COMPOSE-0003 (docker-compose.yml)
- …and 318 more

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- (root) — 2 commits
- deployments/kubernetes — 1 commit

## Notable commits

- change: Merge pull request #18 from itachi5747/feature/add-dockerfile-docker-compose
- change: docs: update README for running docker-compose and kubernetes to up and running whole application (#20)
- change: feat: add kubernetes deployments for all services (#19)
