# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 52 → 52 (+0.1)

## Lenses

- Code Health 90 → 90 (+0.6)
- Architecture 42 → 42 (+0.0)
- Maturity 67 → 68 (+0.6)
- Readiness 46 → 46 (+0.0)
- Security 66 → 66 (-0.0)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (9)

- Critical CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1

## New (23)

- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- …and 3 more

## Changes since last survey

- 21 commits — 13 feature/other, 8 fixes

## By area

- (repo) — 13 commits
- (root) — 3 commits
- packages/core — 2 commits
- packages/common — 1 commit
- packages/platform-fastify — 1 commit
- sample/08-webpack — 1 commit

## Notable commits

- fix: Merge branch 'nestjs:master' into fix/validation-pipe-validator-options
- fix: Merge pull request #17360 from kyu4583/fix/sse-retry-zero
- fix: Merge pull request #17394 from Se3do/fix/grpc-close-null-assignment
- fix: Merge pull request #17399 from coxxny/fix/validation-pipe-validator-options
- fix: Merge pull request #17400 from Se3do/fix/async-executor-anti-pattern
- fix: Merge pull request #17404 from beiifeng/fix-17382
- fix: fix(common): added test for #17398
- fix: fix(deps): remove duplicate version @fastify/static
- change: Merge pull request #17379 from nestjs/renovate/concurrently-10.x
- change: Merge pull request #17381 from nestjs/dependabot/npm_and_yarn/sample/17-mvc-fastify/fastify/static-10.1.2
- change: Merge pull request #17395 from nestjs/dependabot/github_actions/github/codeql-action-4.37.3
- change: Merge pull request #17396 from nestjs/renovate/webpack-cli-7.x
- change: Merge pull request #17401 from Se3do/test/module-ref-unit-tests
- change: Merge pull request #17403 from nestjs/dependabot/npm_and_yarn/nx-22.7.8
- change: Merge pull request #17408 from nestjs/dependabot/npm_and_yarn/globals-17.8.0
- change: chore(deps): update dependency concurrently to v10.0.4
- change: chore(deps): update dependency webpack-cli to v7.2.2
- change: chore(deps-dev): bump globals from 17.7.0 to 17.8.0
- change: chore(deps-dev): bump nx from 22.5.4 to 22.7.8
- change: refactor(core): remove async promise executor anti-patterns
- …and 1 more
