# Changelog

## Score

- CAI 50 → 38 (-11.7)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 83 → 62 (-20.9)
- Maturity 59 → 59 (+0.3)
- Readiness 42 → 21 (-21.5)
- Security 60 → 52 (-7.9)

## Resolved (14)

- Change coupling: build-monaco-editor-core-pkg.ts ↔ build-monaco-editor-pkg.ts (scripts/ci/build-monaco-editor-core-pkg.ts)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: common/lspLanguageFeatures.ts (src/languages/features/common/lspLanguageFeatures.ts)
- FileTooLong: typescript/languageFeatures.ts (src/languages/features/typescript/languageFeatures.ts)
- High CVE: [GHSA redacted] (webpack-plugin/package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- LLM evaluation failed
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- TooManyMethods: TypeScriptWorker (src/languages/features/typescript/tsWorker.ts)
- knowledge concentrated in recent work — freshness signal contradicted by repo activity

## New (43)

- Dimension evaluation failed
- FileTooLong: sql/keywords.js (src/languages/definitions/sql/keywords.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (monaco-lsp-client/package-lock.json)
- Low CVE: [GHSA redacted] (monaco-lsp-client/package-lock.json)
- Low CVE: [GHSA redacted] (webpack-plugin/package-lock.json)
- Low CVE: [GHSA redacted] (monaco-lsp-client/package-lock.json)
- Low CVE: [GHSA redacted] (monaco-lsp-client/package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (monaco-lsp-client/package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (monaco-lsp-client/package-lock.json)
- …and 23 more
