# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 59 → 60 (+1.6)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 87 → 88 (+0.6)
- Architecture 99 → 93 (-6.0)
- Maturity 91 → 78 (-13.3)
- Readiness 63 → 67 (+3.9)
- Security 42 → 52 (+10.3)
- Domain Modelling 89 → 86 (-2.4)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 71 → 71 (-0.2)
- Performance 60 (new)

## Resolved (206)

- ArrowMetricsBatchBuilder::finish (cognitive 21) (quickwit/quickwit-opentelemetry/src/otlp/arrow_metrics.rs)
- ArrowSketchBatchBuilder::finish (cognitive 18) (quickwit/quickwit-parquet-engine/src/ingest/arrow_sketches.rs)
- Change coupling: mod.rs ↔ scheduling_logic_model.rs (quickwit/quickwit-control-plane/src/indexing_scheduler/mod.rs)
- CompactionModel::actions (cognitive 47) (quickwit/quickwit-dst/src/models/time_windowed_compaction.rs)
- CompactionModel::actions (cyclomatic 21) (quickwit/quickwit-dst/src/models/time_windowed_compaction.rs)
- DataModelModel::actions (cognitive 21) (quickwit/quickwit-dst/src/models/parquet_data_model.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Documentation: written for insiders (docs/internals/adr/gaps/README.md)
- Duplicated block (10 lines × 2) (quickwit/quickwit-dst/src/models/time_windowed_compaction.rs)
- Duplicated block (10 lines × 2) (quickwit/quickwit-indexing/src/actors/indexing_pipeline.rs)
- Duplicated block (10 lines × 2) (quickwit/quickwit-indexing/src/actors/merge_planner.rs)
- Duplicated block (10 lines × 2) (quickwit/quickwit-opentelemetry/src/otlp/logs.rs)
- Duplicated block (10 lines × 2) (quickwit/quickwit-parquet-engine/src/sort_fields/parser.rs)
- Duplicated block (11 lines × 2) (quickwit/quickwit-doc-mapper/src/query_builder.rs)
- Duplicated block (11 lines × 2) (quickwit/quickwit-indexing/src/actors/doc_processor.rs)
- Duplicated block (11 lines × 2) (quickwit/quickwit-indexing/src/actors/indexing_pipeline.rs)
- Duplicated block (11 lines × 2) (quickwit/quickwit-indexing/src/actors/merge_planner.rs)
- Duplicated block (11 lines × 2) (quickwit/quickwit-indexing/src/merge_policy/const_write_amplification.rs)
- Duplicated block (11 lines × 2) (quickwit/quickwit-janitor/src/actors/garbage_collector.rs)
- …and 186 more

## New (50)

- Coverage not measured — JavaScript/TypeScript suite
- Documentation: contradicts the code (quickwit/quickwit-metastore/migrations/postgresql_deferred/README.md)
- Duplicate intent: Same as above, `Mailbox` exposes both `ask` and `ask_for_res` with identical signatures. This inconsistency propagates from `ActorContext`.
- Duplicate intent: `ask` and `ask_for_res` have identical signatures. The suffix `_for_res` suggests a specific return type or behavior (perhaps returning a Result directly vs wrapping it), but the signature `Result` is generic enough to cover both. This creates ambiguity for the caller.
- Duplicate intent: `kill` and `quit` appear to perform the same action (terminating the actor) with identical signatures and return types. In actor models, 'kill' usually implies forceful termination while 'quit' might be graceful, but without distinct behavioral documentation or signature differences (e.g., returning a specific error for kill vs success for quit), they are confusingly redundant.
- Duplicate intent: `search_index` and `search_index_cli` have identical signatures and likely perform the same CLI execution logic. The `_cli` suffix is redundant if both are in the CLI module.
- Duplicated block (19 lines × 2) (quickwit/quickwit-indexing/src/actors/indexing_pipeline.rs)
- Duplicated block (6 lines × 2) (quickwit/quickwit-indexing/src/source/kafka_source.rs)
- Duplicated block (8 lines × 2) (quickwit/quickwit-query/src/query_ast/visitor.rs)
- FileTooLong: indexing_scheduler/mod.rs (quickwit/quickwit-control-plane/src/indexing_scheduler/mod.rs)
- FileTooLong: scheduling/mod.rs (quickwit/quickwit-control-plane/src/indexing_scheduler/scheduling/mod.rs)
- High CVE: [GHSA redacted] (quickwit/quickwit-ui/yarn.lock)
- High CVE: [GHSA redacted] (quickwit/quickwit-ui/yarn.lock)
- High CVE: [GHSA redacted] (quickwit/quickwit-ui/yarn.lock)
- Hotspot: quickwit/quickwit-datetime/src/java_date_time_format.rs (quickwit/quickwit-datetime/src/java_date_time_format.rs)
- Inconsistent naming and return types for observation: `ActorContext.observe` returns `ObservableState`, while `ActorHandle.observe` returns `Observation`. `Universe.observe` returns `ActorObservation`. These types likely contain overlapping data (state, type, etc.), but the naming (`observe` vs `observe` vs `observe`) and return types vary by context, making it unclear which method to use for a given level of detail.
- Low CVE: [GHSA redacted] (quickwit/quickwit-ui/yarn.lock)
- Medium vulnerability: RUSTSEC-2026-0285 (quickwit/Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0310 (quickwit/Cargo.lock)
- Medium: security finding (details withheld)
- …and 30 more

## Changes since last survey

- 19 commits — 15 feature/other, 4 fixes

## By area

- quickwit/quickwit-control-plane — 3 commits
- quickwit/quickwit-indexing — 3 commits
- quickwit/quickwit-datetime — 2 commits
- quickwit/quickwit-ingest — 2 commits
- quickwit/quickwit-query — 2 commits
- .github/workflows — 1 commit
- quickwit/Cargo.lock — 1 commit
- quickwit/quickwit-common — 1 commit
- quickwit/quickwit-compaction — 1 commit
- quickwit/quickwit-jaeger — 1 commit
- quickwit/quickwit-parquet-engine — 1 commit
- quickwit/quickwit-storage — 1 commit

## Notable commits

- fix: fix(Security): Apply patch update 0.9.1 to main (#6821)
- fix: fix(datetime): accept an eight-digit subsecond java date format token (#6804)
- fix: fix(datetime): reject a signed fractional part in a timestamp string (#6767)
- fix: fix(indexing): align sequencer capacity with upload concurrency (#6790)
- change: (Calculated fields) Add calculated-field predicates to QueryAst (#6777)
- change: AZ and decommissioning-aware indexing planning, plus optimizations (#6694)
- change: Add indexers AZ ready gate to indexer candidate pool (#6812)
- change: In memory indexing (#6807)
- change: Remove Parquet code (#6809)
- change: Remove ingest observation stream (#6822)
- change: Rework readiness/liveness; exit on server failures (#6673)
- change: Use generation ID for routing table entries, and react to the ingester pool (#6791)
- change: Use predicate cache for all non-timestamp predicates (#6760)
- change: Write split on source EOF (#6808)
- change: Zonally aware ingest controller (#6795)
- change: chore(CI): Run full tests in the merge queue (#6824)
- change: chore: update Tantivy to latest main (#6815)
- change: improvements to our gcs storage (#6802)
- change: use search priority for cpu scheduling (#6798)
