# Changelog

## Score

- CAI 38 → 39 (+0.8)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 36 → 37 (+0.7)
- Architecture 97 → 97 (+0.1)
- Maturity 73 → 73 (-0.0)
- Readiness 21 → 23 (+2.3)
- Security 81 → 77 (-3.4)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 51 → 49 (-2.1)

## Resolved (3)

- ADR not followed: ADR-0024: Canvas migrated to React — logic-preserving port, no vanilla runtime left (docs/adr/0024-canvas-react-migration.md)
- Change coupling: server.js ↔ test-overview-api.js (dashboard/server.js)
- Medium CVE: [GHSA redacted] (dashboard/pnpm-lock.yaml)

## New (5)

- ADR not followed: ADR-0002: /api/status requires an explicit agentId (docs/adr/0002-api-status-requires-agent-id.md)
- High CVE: [GHSA redacted] (dashboard/package-lock.json)
- High CVE: [GHSA redacted] (dashboard/pnpm-lock.yaml)
- High vulnerability: [GHSA redacted] (dashboard/pnpm-lock.yaml)
- The Project Mode section explains how the server serves rule sections but does not state which rule sections are available or where they live in the docs tree (e.g., under /api/projects/:name/rules). (docs/project-mode/README.md)
