# Changelog

## Score

- CAI 46 → 47 (+0.8)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 72 → 72 (-0.5)
- Architecture 100 → 100 (+0.0)
- Maturity 56 → 56 (+0.0)
- Readiness 21 → 27 (+5.9)
- Security 75 → 60 (-15.0)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (2)

- OSV Dependency Vulnerabilities not included (check did not complete)
- The promo README lists technologies and setup but omits any description of the service's purpose or how it fits into the broader ecosystem. (promo/README.md)

## New (52)

- Critical CVE: [GHSA redacted] (cart/package-lock.json)
- Critical CVE: [GHSA redacted] (catalog/package-lock.json)
- Critical CVE: [GHSA redacted] (account/go.mod)
- Critical CVE: [GHSA redacted] (cart/package-lock.json)
- Critical CVE: [GHSA redacted] (profile/package-lock.json)
- Critical CVE: [GHSA redacted] (promo/package-lock.json)
- Critical CVE: [GHSA redacted] (cart/package-lock.json)
- Critical CVE: [GHSA redacted] (cart/package-lock.json)
- Critical CVE: [GHSA redacted] (promo/package-lock.json)
- Critical CVE: [GHSA redacted] (account/go.mod)
- Critical CVE: [GHSA redacted] (authentication/go.mod)
- High CVE: [GHSA redacted] (cart/package-lock.json)
- High CVE: [GHSA redacted] (cart/package-lock.json)
- High CVE: [GHSA redacted] (cart/package-lock.json)
- High CVE: [GHSA redacted] (cart/package-lock.json)
- High CVE: [GHSA redacted] (account/go.mod)
- High CVE: [GHSA redacted] (gateway/go.mod)
- High CVE: [GHSA redacted] (cart/package-lock.json)
- High CVE: [GHSA redacted] (cart/package-lock.json)
- High CVE: [GHSA redacted] (catalog/package-lock.json)
- …and 32 more
