# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 62 → 62 (+0.1)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

## Lenses

- Code Health 92 → 92 (-0.1)
- Architecture 100 → 92 (-8.5)
- Maturity 54 → 54 (+0.3)
- Readiness 74 → 77 (+2.7)
- Security 55 → 55 (+0.0)

## Resolved (13)

- Documentation: no contributor guidance
- Documentation: no installation or build instructions
- Documentation: no licence statement
- Documentation: no project overview
- Documentation: no usage examples
- Further sole-owners (lower concentration)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1

## New (9)

- Duplicated block (5 lines × 2) (gradle-twirl/src/main/java/play/twirl/gradle/internal/DefaultTwirlSourceDirectorySet.java)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Scanner failed to run — not a clean result

## Changes since last survey

- 45 commits — 43 feature/other, 2 fixes

## By area

- (repo) — 21 commits
- (root) — 4 commits
- gradle-twirl/gradle — 4 commits
- .github/workflows — 3 commits
- docs/build.sbt — 2 commits
- docs/project — 2 commits
- project/plugins.sbt — 2 commits
- sbt-twirl/src — 2 commits
- .github/scala-steward.conf — 1 commit
- compiler/src — 1 commit
- gradle-twirl/gradlew.bat — 1 commit
- gradle-twirl/src — 1 commit
- project/Dependencies.scala — 1 commit

## Notable commits

- fix: Revert "Use sbt nightly from (usually blocked) repo.scala-sbt.org to fix snapshots checksums"
- fix: Use sbt nightly from (usually blocked) repo.scala-sbt.org to fix snapshots checksums
- change: Allow to make use of sbt nightly from (usually blocked) repo.scala-sbt.org
- change: Avoid deprecated Gradle APIs on Gradle 9
- change: Build Scala 3 artifacts with 3.3 and test newer versions
- change: Build with sbt 2.1.0-M1 and Scala 3.9.0
- change: Bump com.diffplug.spotless from 8.10.0 to 8.10.2 in /gradle-twirl
- change: Bump com.gradle.plugin-publish from 2.1.1 to 2.2.1 in /gradle-twirl
- change: Bump gradle-wrapper from 9.4.1 to 9.7.1 in /gradle-twirl
- change: Bump gradle-wrapper from 9.7.1 to 9.8.0 in /gradle-twirl
- change: Centralize Scala versions in test builds
- change: Empty - just triggering new sonatype snapshot
- change: Latest sbt nightly
- change: Merge pull request #1290 from playframework/dependabot/gradle/gradle-twirl/gradle-wrapper-9.7.1
- change: Merge pull request #1295 from playframework/dependabot/gradle/gradle-twirl/org.freemarker-freemarker-2.3.35
- change: Merge pull request #1299 from scala-steward/update/scala3-compiler-3.9.0
- change: Merge pull request #1309 from scala-steward/update/patches
- change: Merge pull request #1313 from playframework/dependabot/gradle/gradle-twirl/com.gradle.plugin-publish-2.2.1
- change: Merge pull request #1314 from playframework/dependabot/gradle/gradle-twirl/com.diffplug.spotless-8.10.2
- change: Merge pull request #1317 from mkurz/pin-scala-2.13.x-main
- …and 25 more

## Architecture

- Containers 0 added · 0 removed · contexts 2 added · 1 removed · edges 0 added · 0 removed

## Added bounded contexts (2)

- docs
- gradle-twirl

## Removed bounded contexts (1)

- simple
