# Changelog

## Score

- CAI 55 → 55 (+0.1)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 78 → 78 (-0.0)
- Architecture 70 → 71 (+0.1)
- Maturity 64 → 64 (-0.0)
- Readiness 68 → 55 (-13.3)
- Security 39 → 56 (+17.5)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 51 (new)
- Performance 73 (new)

## Resolved (111)

- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [CVE redacted] (yarn.lock)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- …and 91 more

## New (56)

- Confusing naming convention: 'new' and 'new_full' suggest a constructor pattern, but 'new_full' implies 'new' is incomplete or defaulting. In Rust, 'new' is the standard constructor. Using 'new_full' for a second constructor is non-idiomatic and confusing.
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Documentation: contradicts the code (docs/CHANGELOG_V0.md)
- Duplicate intent: Both methods take a path and return a String, implying they perform the same normalization of path separators. The names 'normalize' and 'standardize' are semantically identical in this context.
- Duplicate intent: Two methods appear to check for the same CI environment condition. 'is_ci' is likely the standard accessor, while 'is_ci_env' is redundant or a legacy alias.
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High vulnerability: [GHSA redacted] (yarn.lock)
- Inconsistent return types and error handling: 'locate_root' returns a VirtualPath directly (implying it never fails or panics on failure), while 'locate_root_with_check' returns AnyResult. This inconsistency in error handling strategy for similar operations is confusing.
- Inconsistent return types and error handling: Same issue as 'locate_root' vs 'locate_root_with_check'. 'locate_root_many' returns VirtualPath directly, while the 'with_check' variant returns AnyResult.
- Inverted test pyramid
- Low cohesion: ExtensionRegistry (LCOM4 6) (crates/extension-plugin/src/extension_registry.rs)
- Low cohesion: MoonSandbox (LCOM4 4) (crates/test-utils/src/sandbox.rs)
- Low cohesion: MoonSession (LCOM4 5) (crates/app/src/session.rs)
- Low cohesion: ToolchainRegistry (LCOM4 17) (crates/toolchain-plugin/src/toolchain_registry.rs)
- …and 36 more

## Changes since last survey

- 11 commits — 7 feature/other, 4 fixes

## By area

- (root) — 5 commits
- crates/app — 2 commits
- crates/cache-storage — 1 commit
- crates/config-loader — 1 commit
- crates/task-runner — 1 commit
- crates/vcs — 1 commit

## Notable commits

- fix: fix(query): respect CI environment when tracking affected tasks and projects (#2707)
- fix: fix: Audit 09/26 (#2731)
- fix: fix: Restore numeric options (0-3) for MOON_COLOR (#2713)
- fix: fix: Wait for remote storage to connect before reading or writing the cache (#2715)
- change: chore: Bump packages
- change: chore: Bump packages
- change: chore: Release
- change: chore: Release
- change: docs: Update changelog.
- change: feat: Add MOON_BUILTIN_REGISTRY_HOST and MOON_BUILTIN_REGISTRY_NAMESPACE (#2709)
- change: perf: collect working tree status once per run (#2702)
