# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 62 (+1.4)
- Rubric changed (rubric-2026.09.13 → rubric-2026.10.1) — scores are not directly comparable.

## Lenses

- Code Health 84 → 89 (+5.3)
- Architecture 99 → 89 (-9.8)
- Maturity 67 → 67 (-0.4)
- Readiness 59 → 60 (+1.4)
- Security 63 → 75 (+12.5)
- Event-Driven 54 → 54 (-0.3)
- Event Sourcing 100 → 100 (+0.0)

## Resolved (13)

- Coverage not measured — no coverage collector is wired up
- Documentation: no installation or build instructions (priv/container/release/README.md)
- Duplicated block (5 lines × 2) (src/srv/compute/wm_compute.erl)
- Duplicated block (7 lines × 2) (src/lib/wm_file_utils.erl)
- FileTooLong: lib/mochijson2.erl (src/lib/mochijson2.erl)
- FixmeComment (src/srv/container/wm_docker.erl)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (src/net/wm_ssh_server.erl)
- TooManyFunctions: wm_docker (src/srv/container/wm_docker.erl)
- mochijson2.tokenize_number (cognitive 23) (src/lib/mochijson2.erl)
- mochijson2.tokenize_number (cyclomatic 28) (src/lib/mochijson2.erl)
- mochijson2.tokenize_string (cyclomatic 21) (src/lib/mochijson2.erl)
- wm_file_utils.create_tar_gz (cognitive 16) (src/lib/wm_file_utils.erl)
- wm_rpc.get_next_destination (cognitive 30) (src/net/wm_rpc.erl)

## New (45)

- Dependency not covered by the lockfile: katana_code
- Duplicated block (15 lines × 2) (src/lib/wm_topology.erl)
- Duplicated block (19 lines × 2) (scripts/skyport-container-prompt.py)
- Duplicated block (5 lines × 2) (src/srv/compute/wm_compute.erl)
- Duplicated block (7 lines × 2) (src/lib/wm_topology.erl)
- Duplicated block (8–9 lines × 2) (scripts/setup-swm-core.py)
- FileTooLong: compute/wm_pmix.erl (src/srv/compute/wm_pmix.erl)
- FileTooLong: container/wm_podman.erl (src/srv/container/wm_podman.erl)
- High CVE: [GHSA redacted] (rebar.lock)
- High CVE: [GHSA redacted] (rebar.lock)
- High CVE: [GHSA redacted] (rebar.lock)
- High IaC: DS-0029 (priv/container/debug/Dockerfile)
- High IaC: DS-0029 (priv/container/debug/Dockerfile)
- High IaC: DS-0029 (priv/container/debug/Dockerfile)
- High IaC: DS-0029 (priv/container/debug/Dockerfile)
- High: security finding (details withheld)
- Hotspot: src/lib/wm_commit.erl (src/lib/wm_commit.erl)
- Hotspot: src/lib/wm_entity.erl (src/lib/wm_entity.erl)
- Hotspot: src/lib/wm_topology.erl (src/lib/wm_topology.erl)
- Hotspot: src/srv/container/wm_container.erl (src/srv/container/wm_container.erl)
- …and 25 more

## Changes since last survey

- 29 commits — 25 feature/other, 4 fixes

## By area

- src/srv — 10 commits
- c_src/lib — 4 commits
- c_src/pmix — 3 commits
- priv/examples — 3 commits
- src/lib — 3 commits
- (root) — 2 commits
- priv/container — 2 commits
- HOWTO/JOBS.md — 1 commit
- scripts/install-openmpi.sh — 1 commit

## Notable commits

- fix: Fix C++ compilation
- fix: Fix order of includes in autogenerated c++ files
- fix: Fix running MPI on multiple nodes
- fix: Multiple fixes for running multi-node jobs
- change: Add C++ automatic formatting
- change: Add test for local job execution
- change: Allow to keep remote resources undestroyed after job is finished (disabled by default)
- change: Allow to resubmit old job via API and add openmpi compilation script
- change: Allow to run simple dev jobs locally
- change: Download task stdout as well
- change: Export useful SWM_* environment variables to job script
- change: Fix erlang warnings in latest code
- change: Implement PMIX fence mechanism
- change: Improve PMIx fence mechanism
- change: Improve instructions for ai agents how to compile
- change: Improve job error handling
- change: Install C++ formatting packages in dev dockerfile
- change: Migrate from docker to podman
- change: Move unit tests to separae erlang modules
- change: Reduce job start overhead
- …and 9 more
