# Changelog

## Score

- CAI 52 → 54 (+2.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 94 → 94 (+0.0)
- Architecture 71 → 74 (+3.0)
- Maturity 70 → 71 (+1.5)
- Readiness 45 → 51 (+6.5)
- Security 41 → 41 (+0.0)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (15)

- Critical CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (packages/server/package-lock.json)
- High CVE: [GHSA redacted] (packages/server/package-lock.json)
- High CVE: [GHSA redacted] (packages/server/package-lock.json)
- High CVE: [GHSA redacted] (packages/server/package-lock.json)
- High CVE: [GHSA redacted] (packages/server/package-lock.json)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High vulnerability: [GHSA redacted] (packages/server/package-lock.json)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- The running-it-yourself section is cut mid-sentence ('Then in another terminal y') by the scanner; no further instructions follow in the visible portion of the document. (README.md)

## New (16)

- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (packages/server/package-lock.json)
- High CVE: [GHSA redacted] (yarn.lock)
- The README does not mention how to run the demo locally beyond the initial install/yarn dev steps; a 'Run it yourself' section would be ideal for completeness. (README.md)
- The README links to an external site but does not explain how to access or modify the demo locally. (README.md)
