# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 49 → 53 (+3.5)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 86 → 86 (-0.1)
- Architecture 83 → 83 (+0.0)
- Maturity 73 → 73 (+0.0)
- Readiness 36 → 37 (+0.1)
- Security 50 → 65 (+14.2)
- Domain Modelling 57 → 60 (+2.7)
- Event-Driven 100 → 100 (+0.0)

## Resolved (6)

- High: security finding (details withheld)
- High: security finding (details withheld)
- Outdated: OpenTelemetry.Instrumentation.EntityFrameworkCore
- Outdated: OpenTelemetry.Instrumentation.GrpcNetClient
- The Helm install instructions are incomplete for Windows/macOS. (deployment/k8s/README.md)
- redundant comment (src/NKZSoft.Template.Presentation.Starter/GlobalUsings.cs)

## New (23)

- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium IaC: CKV2_GHA_1 (.github/workflows/build-by-tag.yaml)
- Medium IaC: CKV2_GHA_1 (.github/workflows/cleanup.yaml)
- Medium IaC: CKV_DOCKER_2 (Dockerfile)
- Medium IaC: CKV_SECRET_4 (src/NKZSoft.Template.Presentation.Starter/appsettings.Development.json)
- Medium IaC: CKV_SECRET_4 (src/NKZSoft.Template.Presentation.Starter/appsettings.Docker.json)
- Medium IaC: CKV_SECRET_4 (src/NKZSoft.Template.Presentation.Starter/bin/Debug/net9.0/appsettings.Development.json)
- Medium IaC: CKV_SECRET_4 (src/NKZSoft.Template.Presentation.Starter/bin/Debug/net9.0/appsettings.Docker.json)
- XML-doc coverage: NKZSoft.Template.Application (src/NKZSoft.Template.Application/NKZSoft.Template.Application.csproj)
- XML-doc coverage: NKZSoft.Template.Common (src/NKZSoft.Template.Common/NKZSoft.Template.Common.csproj)
- XML-doc coverage: NKZSoft.Template.Domain (src/NKZSoft.Template.Domain/NKZSoft.Template.Domain.csproj)
- XML-doc coverage: NKZSoft.Template.EFCore.Caching.Redis (src/NKZSoft.Template.EFCore.Caching.Redis/NKZSoft.Template.EFCore.Caching.Redis.csproj)
- XML-doc coverage: NKZSoft.Template.Events (src/NKZSoft.Template.Events/NKZSoft.Template.Events.csproj)
- XML-doc coverage: NKZSoft.Template.Infrastructure.Core (src/NKZSoft.Template.Infrastructure.Core/NKZSoft.Template.Infrastructure.Core.csproj)
- XML-doc coverage: NKZSoft.Template.MessageBrokers.RabbitMq (src/NKZSoft.Template.MessageBrokers.RabbitMq/NKZSoft.Template.MessageBrokers.RabbitMq.csproj)
- XML-doc coverage: NKZSoft.Template.Persistence.PostgreSQL (src/NKZSoft.Template.Persistence.PostgreSQL/NKZSoft.Template.Persistence.PostgreSQL.csproj)
- XML-doc coverage: NKZSoft.Template.Persistence.Redis (src/NKZSoft.Template.Persistence.Redis/NKZSoft.Template.Persistence.Redis.csproj)
- XML-doc coverage: NKZSoft.Template.Presentation.GraphQL (src/NKZSoft.Template.Presentation.GraphQL/NKZSoft.Template.Presentation.GraphQL.csproj)
- XML-doc coverage: NKZSoft.Template.Presentation.Grpc (src/NKZSoft.Template.Presentation.Grpc/NKZSoft.Template.Presentation.Grpc.csproj)
- …and 3 more

## API surface

- Unchanged — 2 HTTP endpoints
