# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 39 → 41 (+1.6)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 40 → 40 (-0.3)
- Architecture 75 → 75 (-0.3)
- Maturity 55 → 56 (+0.3)
- Readiness 40 → 44 (+3.2)
- Security 46 → 54 (+7.9)
- Accessibility 35 → 35 (+0.0)
- Performance 85 (new)

## Resolved (71)

- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FilesController.expandFilesInObject (cognitive 19) (src/Controllers/FilesController.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 51 more

## New (84)

- Critical CVE: [GHSA redacted] (package-lock.json)
- End-of-life runtime: Node.js 20
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/GraphQL/ParseGraphQLServer.js (src/GraphQL/ParseGraphQLServer.js)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low cohesion: Config (LCOM4 6) (src/Config.js)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium vulnerability: [GHSA redacted] (package-lock.json)
- Medium: security finding (details withheld)
- …and 64 more

## Changes since last survey

- 57 commits — 41 feature/other, 16 fixes

## By area

- (root) — 39 commits
- spec/vulnerabilities.spec.js — 4 commits
- (repo) — 2 commits
- .github/workflows — 2 commits
- spec/ParseGraphQLServer.spec.js — 2 commits
- spec/AuthenticationAdapters.spec.js — 1 commit
- spec/EmailVerificationToken.spec.js — 1 commit
- spec/MongoStorageAdapter.spec.js — 1 commit
- spec/ParseLiveQuery.spec.js — 1 commit
- spec/ParseLiveQueryServer.spec.js — 1 commit
- spec/index.spec.js — 1 commit
- src/GraphQL — 1 commit
- src/Options — 1 commit

## Notable commits

- fix: fix: Bump @parse/push-adapter from 8.4.0 to 8.5.3 (#10676)
- fix: fix: Bump body-parser from 2.2.2 to 2.3.0 (#10600)
- fix: fix: Bump express-rate-limit from 8.3.1 to 8.7.0 (#10672)
- fix: fix: Bump parse from 8.6.0 to 8.6.2, @parse/push-adapter from 8.5.3 to 8.5.5 and ws from 8.21.0 to 8.21.3 (#10688)
- fix: fix: Bump qs from 6.15.2 to 6.16.0 (#10651)
- fix: fix: Bump undici from 7.28.0 to 7.29.1 (#10674)
- fix: fix: GraphQL argument and enum validation errors disclose target class names when public introspection is disabled ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10665)
- fix: fix: GraphQL schema is disclosed by replaying an automatic persisted query when public introspection is disabled ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10669)
- fix: fix: LiveQuery evaluates class-level permissions against an incomplete caller identity (#10675)
- fix: fix: LiveQuery ignores userField protectedFields groups and over-redacts fields the REST path returns (#10690)
- fix: fix: Parse Server option `graphQLPublicIntrospection` has no effect (#10696)
- fix: fix: Per-entry cache TTL is ignored by the in-memory cache adapter (#10671)
- fix: fix: Relation count query bypasses protectedFields for identity-scoped groups ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10667)
- fix: fix: Server crash via file pointer without URL in an object write ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10694)
- fix: fix: Server crash via unhandled error when sending verification or password reset email (([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted]))) (#10730)
- fix: fix: Transactional batch request can roll back or block writes of other clients ([[GHSA redacted]](https://github.com/parse-community/parse-server/security/advisories/[GHSA redacted])) (#10713)
- change: build: Release (#10689)
- change: chore(release): 9.10.1 [skip ci]
- change: chore(release): 9.10.1-alpha.12 [skip ci]
- change: chore(release): 9.10.1-alpha.13 [skip ci]
- …and 37 more
