# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 61 → 64 (+3.1)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 80 → 80 (-0.0)
- Architecture 67 → 70 (+3.8)
- Maturity 70 → 68 (-2.2)
- Readiness 56 → 57 (+1.5)
- Security 60 → 70 (+10.6)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 68 → 68 (+0.0)
- Performance 100 (new)

## Resolved (29)

- Documentation: no architecture or design documentation (README.md)
- Documentation: written for insiders (docs/project/tof-on-demand.md)
- Documentation: written for insiders (docs/project/update-over-ble.md)
- Documentation: written for insiders (docs/robot/install-by-hand.md)
- Documentation: written for insiders (docs/robot/pair-a-gamepad.md)
- Duplicated block (18 lines × 2) (padd/src/tap.rs)
- Duplicated block (21 lines × 2) (duck-detect/src/lib.rs)
- Duplicated block (5 lines × 2) (padd/src/tap.rs)
- Edited copy of a member (17 corresponding lines) (pad-imu/src/lib.rs)
- Engine::recover_on_start (cyclomatic 16) (updater/src/engine.rs)
- FileTooLong: policy-shop/app.py (spaces/policy-shop/app.py)
- Hotspot: duck-ether/src/main.rs (duck-ether/src/main.rs)
- Hotspot: mediad/src/stream.rs (mediad/src/stream.rs)
- Hotspot: robotctl/src/show.rs (robotctl/src/show.rs)
- Hotspot: robotd-params/src/edit.rs (robotd-params/src/edit.rs)
- Link._open (cognitive 30) (spaces/policy-shop/app.py)
- Link._open (cyclomatic 18) (spaces/policy-shop/app.py)
- Link.describe (cognitive 16) (spaces/policy-shop/app.py)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 9 more

## New (67)

- Config::validate (cyclomatic 16) (updater/src/config.rs)
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Documentation: no project overview (README.md)
- Duplicate method signature with different parameter names (one uses `_lines`/`_boot`, the other uses `lines`/`boot`). This suggests an accidental overload or copy-paste error in the API definition.
- Duplicated block (11 lines × 2) (spaces/shared/control.py)
- Duplicated block (11–16 lines × 2) (duckctl/src/main.rs)
- Duplicated block (12 lines × 2) (spaces/shared/rendezvous.py)
- Duplicated block (14 lines × 2) (spaces/shared/rendezvous.py)
- Duplicated block (14 lines × 2) (spaces/shared/wire.py)
- Duplicated block (18 lines × 3) (mediad/src/frame.rs)
- Duplicated block (19 lines × 2) (spaces/shared/wire.py)
- Duplicated block (21 lines × 2) (spaces/shared/rendezvous.py)
- Duplicated block (21 lines × 2) (uyvy/src/lib.rs)
- Duplicated block (24 lines × 2) (spaces/shared/wire.py)
- Duplicated block (32 lines × 2) (spaces/shared/control.py)
- Duplicated block (34 lines × 2) (spaces/shared/wire.py)
- Duplicated block (38 lines × 2) (spaces/shared/control.py)
- Duplicated block (38 lines × 2) (spaces/shared/wire.py)
- Duplicated block (39 lines × 2) (spaces/shared/wire.py)
- Duplicated block (42 lines × 2) (spaces/shared/wire.py)
- …and 47 more

## Changes since last survey

- 189 commits — 189 feature/other, 0 fixes

## By area

- (repo) — 79 commits
- docs/design — 17 commits
- mediad/src — 12 commits
- (root) — 10 commits
- spaces/policy-playground — 9 commits
- btd/src — 8 commits
- updater/src — 8 commits
- spaces/policy-playground-next — 7 commits
- scripts/duck-sim — 6 commits
- duck-ipc-proto/src — 4 commits
- robotctl/src — 4 commits
- .github/workflows — 3 commits
- mediad/webclient — 3 commits
- docs/robot — 2 commits
- duck-control/src — 2 commits
- odometry/src — 2 commits
- spaces/shared — 2 commits
- deploy/updater.toml — 1 commit
- docs/README.md — 1 commit
- docs/project — 1 commit

## Notable commits

- change: "Already serves this" was indistinguishable from success
- change: Merge branch 'duck-sim-finds-the-sim-repo' into a-simulated-duck-is-a-duck
- change: Merge branch 'duck-sim-finds-the-sim-repo' into a-simulated-duck-is-a-duck
- change: Merge branch 'main' into padd-reset-holds-on-pad-loss
- change: Merge branch 'main' into safety-limit-journal
- change: Merge branch 'main' into updater-rollback-journal-and-apply-action
- change: Merge main
- change: Merge main
- change: Merge main into a-mode-switch-waits-for-a-policy-load
- change: Merge main: the version this entry claims moved 28 -> 35
- change: Merge main: v35 was taken, so this is v36
- change: Merge pull request #107 from pollen-robotics/docs-mobile-app-approach
- change: Merge pull request #179 from Nixxx19/auto-exposure-digital-gain-back-to-1x
- change: Merge pull request #195 from Nixxx19/mode-switch-waits-and-never-stands-a-limp-robot-up
- change: Merge pull request #197 from Nixxx19/boot-recovery-waits-for-a-robot-that-is-still-starting
- change: Merge pull request #198 from hadelan/updater-rollback-journal-and-apply-action
- change: Merge pull request #216 from yunloong-Y/safety-limit-journal
- change: Merge pull request #226 from Nixxx19/refuse-a-non-socket-path-before-bind
- change: Merge pull request #228 from Nixxx19/a-mode-switch-waits-for-a-policy-load
- change: Merge pull request #241 from larai-w/feat/media-frame
- …and 169 more
