# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 40 → 43 (+2.9)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 68 → 70 (+2.1)
- Architecture 99 → 99 (-0.1)
- Maturity 64 → 65 (+0.9)
- Readiness 20 → 20 (+0.0)
- Security 61 → 67 (+5.9)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 44 → 52 (+7.9)

## Resolved (40)

- Boundary-crossing change coupling: onboarding.actions.ts ↔ page.tsx (actions/onboarding.actions.ts)
- Boundary-crossing change coupling: onboarding.actions.ts ↔ page.tsx (actions/onboarding.actions.ts)
- Change coupling: page.tsx ↔ page.tsx (app/(onboarding)/onboarding/farmer/page.tsx)
- Dependency hygiene not measured — no supported dependency manifest was read
- Further orphaned files (smaller)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 20 more

## New (30)

- Build action pinned to a mutable branch
- Change coupling clique: onboarding.actions.ts, page.tsx, page.tsx (actions/onboarding.actions.ts)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: _components/ListingDetail.tsx (app/marketplace/_components/ListingDetail.tsx)
- FileTooLong: _components/application-detail.tsx (app/(protected)/applications/_components/application-detail.tsx)
- FileTooLong: header/AuthHeader.tsx (components/header/AuthHeader.tsx)
- FileTooLong: role/page.tsx (app/(onboarding)/onboarding/role/page.tsx)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High vulnerability: [GHSA redacted] (pnpm-lock.yaml)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 10 more

## Changes since last survey

- 4 commits — 4 feature/other, 0 fixes

## By area

- (repo) — 2 commits
- (root) — 2 commits

## Notable commits

- change: Merge pull request #195 from rajputomsingh/dependabot/npm_and_yarn/sharp-0.35.3
- change: Merge pull request #196 from rajputomsingh/dependabot/npm_and_yarn/next-16.2.11
- change: chore(deps): bump next from 16.2.3 to 16.2.11
- change: chore(deps): bump sharp from 0.34.5 to 0.35.3
