# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 68 → 46 (-22.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 92 → 98 (+6.7)
- Architecture 100 → 94 (-5.9)
- Maturity 67 → 57 (-9.7)
- Readiness 60 → 30 (-30.2)
- Security 75 → 47 (-28.6)

## Resolved (19)

- Blueprint.register (cognitive 24) (src/flask/sansio/blueprints.py)
- Blueprint.register (cyclomatic 22) (src/flask/sansio/blueprints.py)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (14 lines × 2) (examples/tutorial/flaskr/blog.py)
- FileTooLong: flask/app.py (src/flask/app.py)
- FileTooLong: flask/cli.py (src/flask/cli.py)
- Flask.make_response (cognitive 23) (src/flask/app.py)
- Flask.make_response (cyclomatic 16) (src/flask/app.py)
- Flask.preprocess_request (cognitive 16) (src/flask/app.py)
- Flask.url_for (cognitive 22) (src/flask/app.py)
- Off-boarding risk: anonymized user #1
- TooManyMethods: App (src/flask/sansio/app.py)
- TooManyMethods: Flask (src/flask/app.py)
- cli.find_app_by_string (cognitive 18) (src/flask/cli.py)
- cli.find_best_app (cognitive 18) (src/flask/cli.py)
- cli.load_dotenv (cognitive 16) (src/flask/cli.py)
- cli.routes_command (cognitive 16) (src/flask/cli.py)
- scaffold._find_package_path (cognitive 17) (src/flask/sansio/scaffold.py)

## New (9)

- Coverage not measured — test suite did not build
- Dimension evaluation failed
- LLM evaluation failed
- Low: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No artifact signing
- No build provenance
- No tests found
