# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 61 → 61 (+0.1)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

## Lenses

- Code Health 56 → 56 (+0.2)
- Architecture 91 → 90 (-1.5)
- Maturity 62 → 62 (+0.0)
- Readiness 62 → 62 (-0.0)
- Security 69 → 70 (+0.4)

## Resolved (33)

- Critical CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.2.0
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (docs/2023-01-17--full-demo-with-managed-app.md)
- High CVE: Microsoft.Extensions.Caching.Memory 8.0.0
- High CVE: Newtonsoft.Json 11.0.2
- High CVE: System.Formats.Asn1 8.0.0
- High CVE: System.Security.Cryptography.Xml 8.0.0
- High CVE: System.Text.Json 6.0.5
- High CVE: System.Text.Json 6.0.6
- High CVE: System.Text.Json 8.0.0
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 13 more

## New (27)

- Deprecated: Azure.Identity
- Documentation: no project overview (README.md)
- Inconsistent casing convention for property names within the BillingDefinition type. 'id' uses lowercase while 'processStatus' uses camelCase. Given the presence of other camelCase properties (e.g., Access_token, Quantity), 'id' appears to be an outlier or a direct mapping to a wire-format key that breaks the local naming convention.
- Inconsistent casing style for compound property names. 'Access_token' uses an underscore separator while 'processStatus' uses camelCase. This indicates a lack of consistent naming convention for multi-word identifiers within the ManagedWebhook.Definitions namespace.
- Outdated: Apache.Avro
- Outdated: Azure.Identity
- Outdated: Azure.Messaging.EventHubs
- Outdated: Azure.Messaging.EventHubs.Processor
- Outdated: Azure.Storage.Blobs
- Outdated: FSharp.Control.AsyncSeq
- Outdated: FSharp.Core
- Outdated: Microsoft.Extensions.Configuration
- Outdated: Microsoft.Extensions.Configuration.EnvironmentVariables
- Outdated: Microsoft.Extensions.DependencyInjection.Abstractions
- Outdated: Microsoft.Extensions.Hosting
- Outdated: Microsoft.Extensions.Logging.Abstractions
- Outdated: Microsoft.NET.Test.Sdk
- Outdated: Microsoft.VisualStudio.Azure.Containers.Tools.Targets
- Outdated: NUnit
- Outdated: NUnit3TestAdapter
- …and 7 more

## API surface

- Unchanged — 2 HTTP endpoints
