# Changelog

## Score

- CAI 66 → 71 (+5.3)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 82 → 82 (+0.4)
- Architecture 100 → 89 (-11.2)
- Maturity 74 → 73 (-0.3)
- Readiness 75 → 72 (-2.8)
- Security 51 → 65 (+13.7)
- Performance 100 (new)

## Resolved (9)

- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: src/bin/sccache-dist/main.rs (src/bin/sccache-dist/main.rs)
- Hotspot: src/cache/multilevel.rs (src/cache/multilevel.rs)
- Hotspot: src/compiler/compiler.rs (src/compiler/compiler.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/compiler/cicc.rs)
- Off-boarding risk: anonymized user #1
- sccache::compiler::gcc::preprocess_cmd (cognitive 16) (src/compiler/gcc.rs)

## New (43)

- Ambiguous and overlapping read operations. `get` and `get_with_raw` appear to serve similar purposes (retrieving data), but the distinction between 'raw' and non-raw is unclear. Furthermore, `get_raw` exists separately, creating a triad of read methods with unclear semantic boundaries. It is unclear if `get` returns deserialized objects while `get_raw` returns bytes, or if `get_with_raw` is an alias for one of them.
- Documentation: no project overview (README.md)
- Duplicate intent in `TcCache`. `get` and `get_file` have nearly identical signatures and likely return the same type (`LruResult`). It is unclear why there are two methods for retrieving a toolchain, unless one returns a file handle and the other returns a path or bytes, but the return type `LruResult` is opaque and suggests identical behavior.
- Flaky test: sccache::system.test_stats_no_server
- Further sole-owners (lower concentration)
- Inconsistent naming for write operations. `put` takes a structured `CacheWrite` object, while `put_raw` takes raw bytes. While the distinction is logical, the naming convention `put` vs `put_raw` is less standard than `put` vs `put_bytes` or `store` vs `store_raw`. More importantly, `get` vs `get_raw` inconsistency (see above) suggests a broader pattern of confusing 'raw' terminology.
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/compiler/cicc.rs)
- Off-boarding risk: anonymized user #1
- Outdated: anyhow
- Outdated: async-trait
- Outdated: blake3
- Outdated: bytes
- Outdated: chrono
- Outdated: clap
- Outdated: encoding_rs
- Outdated: env_logger
- Outdated: filetime
- Outdated: flate2
- Outdated: fs-err
- …and 23 more

## Changes since last survey

- 24 commits — 17 feature/other, 7 fixes

## By area

- src/compiler — 14 commits
- (root) — 2 commits
- src/cache — 2 commits
- src/server.rs — 2 commits
- tests/integration — 2 commits
- docs/Configuration.md — 1 commit
- tests/system.rs — 1 commit

## Notable commits

- fix: Fix preprocessor cache include validation
- fix: Revert "Add cache hit variant for direct mode"
- fix: Revert "Add primitive printing for direct cache hit"
- fix: Revert "Change match to if"
- fix: Revert "Rename to DirectCacheType"
- fix: Revert "Wire the variant into actual generate_hash_key"
- fix: fix(cache): avoid duplicate multilevel reads
- change: Add cache hit variant for direct mode
- change: Add primitive printing for direct cache hit
- change: Change match to if
- change: Don't hand the jobserver to children that can't use it
- change: Rename to DirectCacheType
- change: Strip basedirs from the compiler arguments too
- change: Wire the variant into actual generate_hash_key
- change: chore(deps): update rust crate tar to v0.4.45
- change: chore: Remove dependency status badge (#2856)
- change: dist: refuse to trim rlibs from crates that also emit a cdylib
- change: docs: SCCACHE_CACHE_MULTIARCH enables multi-arch caching
- change: gcc, clang: don't distribute multi-arch compilations
- change: gcc, clang: preprocess multi-arch compilations once per -arch
- …and 4 more
