# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 58 → 60 (+2.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 67 → 67 (-0.3)
- Architecture 99 → 99 (+0.0)
- Maturity 53 → 69 (+16.4)
- Readiness 57 → 59 (+2.3)
- Security 53 → 53 (-0.2)

## Resolved (5)

- Build action pinned to a mutable branch
- Low: security finding (details withheld)
- Medium vulnerability: [GHSA redacted] (go.mod)
- The main README mentions a 'docs' directory with an overview SVG, but there is no link to the detailed documentation (https://raystack.github.io/raccoon/), which is where most readers go next. (README.md)
- complexity unreadable for .go, .java, .py — churn × complexity hotspots could not be measured

## New (14)

- Critical CVE: [GHSA redacted] (go.mod)
- Duplicated block (12 lines × 2) (clients/go/rest/rest.go)
- Duplicated block (15 lines × 2) (clients/go/examples/grpc/main.go)
- Duplicated block (19 lines × 2) (publisher/kinesis/kinesis.go)
- Duplicated block (8 lines × 2) (clients/go/rest/rest.go)
- High CVE: [GHSA redacted] (clients/js/package-lock.json)
- Medium CVE: [GHSA redacted] (go.mod)
- Medium CVE: GO-2026-5024 (go.mod)
- Medium CVE: GO-2026-5970 (go.mod)
- Medium IaC: CKV_DOCKER_3 (Dockerfile)
- Medium vulnerability: [GHSA redacted] (go.mod)
- Medium vulnerability: [GHSA redacted] (go.mod)
- Pool.worker (cognitive 19) (core/worker/worker.go)
- config.cfgMetadata (cognitive 16) (config/errors.go)
