# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 68 → 50 (-18.8)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 89 (-11.2)
- Architecture 100 → 94 (-5.9)
- Maturity 58 → 56 (-1.8)
- Readiness 65 → 30 (-35.2)
- Security 83 → 69 (-14.0)

## Resolved (14)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (src/black/linegen.py)
- Duplicated block (9 lines × 2) (src/black/parsing.py)
- Further orphaned files (smaller)
- Further sole-owners (lower concentration)
- Off-boarding risk: anonymized user #1
- Orphaned knowledge (profiling/list_big.py)
- Orphaned knowledge (profiling/list_huge.py)
- Orphaned knowledge (profiling/mix_big.py)
- Orphaned knowledge (profiling/mix_huge.py)
- The README's index page (the first document) appears to be a Sphinx template stub rather than a real documentation entry, as evidenced by the empty contents and the 'Show your style' admonition. (docs/index.md)
- The license section is an empty stub marked 'orphan: true' and includes a single `{include} ../LICENSE` directive, so the actual license content is not visible in this file. (docs/license.md)
- complexity unreadable for .py — churn × complexity hotspots could not be measured

## New (19)

- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (tests/test_black.py)
- Duplicated block (11 lines × 2) (tests/test_black.py)
- Duplicated block (17 lines × 2) (tests/data/cases/composition.py)
- Duplicated block (18 lines × 2) (tests/data/cases/composition_no_trailing_comma.py)
- Duplicated block (7 lines × 2) (src/blib2to3/pgen2/conv.py)
- Duplicated block (8 lines × 2) (src/blib2to3/pgen2/conv.py)
- High: security finding (details withheld)
- Low IaC: DS-0026 (Dockerfile)
- Low: security finding (details withheld)
- Medium: security finding (details withheld)
- No artifact signing
- No build provenance
- No tests found
- The Getting Started section is a single sentence ('New to _Black_? Don't worry...') with no real guidance on how to get started beyond the one-line promise, leaving readers unsure what they will find in the rest of the document. (docs/getting_started.md)
- early-stage repository — too little history to judge knowledge freshness
- single-commit history — no usable git history window to measure hotspots
- single-maintainer — knowledge-concentration (bus factor) risk
