# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 67 → 69 (+1.9)
- Rubric changed (rubric-2026.09.13 → rubric-2026.10.1) — scores are not directly comparable.

## Lenses

- Code Health 92 → 91 (-0.3)
- Architecture 100 → 98 (-2.0)
- Maturity 82 → 82 (+0.1)
- Readiness 46 → 52 (+6.1)
- Security 98 → 85 (-12.9)
- Event-Driven 80 → 80 (+0.0)
- Event Sourcing 100 → 100 (+0.0)

## Resolved (8)

- Coverage not measured — no coverage collector is wired up
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (6 lines × 2) (src/reckon_db_telemetry.erl)
- High IaC: WD-DOCKER-0001 (Dockerfile)
- Hotspot: src/reckon_db_store_registry.erl (src/reckon_db_store_registry.erl)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)

## New (32)

- Duplicated block (14–16 lines × 7) (native/reckon_db_archive_nif/src/lib.rs)
- Duplicated block (15–17 lines × 5) (native/reckon_db_filter_nif/src/lib.rs)
- Duplicated block (16 lines × 2) (native/reckon_db_filter_nif/src/lib.rs)
- Duplicated block (5 lines × 2) (native/reckon_db_archive_nif/src/lib.rs)
- Duplicated block (5 lines × 2) (native/reckon_db_archive_nif/src/lib.rs)
- Duplicated block (5 lines × 3) (native/reckon_db_aggregate_nif/src/lib.rs)
- Duplicated block (5 lines × 3) (native/reckon_db_archive_nif/src/lib.rs)
- Duplicated block (6 lines × 2) (src/reckon_db_telemetry.erl)
- Duplicated block (6–7 lines × 2) (native/reckon_db_archive_nif/src/lib.rs)
- Duplicated block (7 lines × 2) (native/reckon_db_aggregate_nif/src/lib.rs)
- Duplicated block (7 lines × 2) (native/reckon_db_crypto_nif/src/lib.rs)
- Duplicated block (9 lines × 2) (native/reckon_db_archive_nif/src/lib.rs)
- Duplicated block (9–11 lines × 2) (native/reckon_db_archive_nif/src/lib.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 12 more

## Changes since last survey

- 13 commits — 10 feature/other, 3 fixes

## By area

- (root) — 8 commits
- .github/workflows — 2 commits
- test/integration — 2 commits
- scripts/is_hex_publish_key_live.sh — 1 commit

## Notable commits

- fix: fix: DCB events get secondary-index entries; a one-time re-index for older ones (#2)
- fix: fix: logged durations are microseconds, not native units labelled `us'
- fix: fix: the DCB re-index runs off the leader loop; force re-run; rollback documented
- change: Add SECURITY.md: where to report a vulnerability, and what happens next
- change: chore: release 5.11.10, logged durations in the unit they say
- change: ci: OTP 28.4.3, and pin the project plugins, rebar3_hex at 7.2.0
- change: ci: reckon-db's first CI, ratcheted debt, and a guard on the NIF package
- change: ct: an unallowed skip fails the run (cth_skip_is_failure)
- change: docs: publishing is tag-to-release; stop describing a reviewer that is not there
- change: docs: rollback by undeclaring the indexes; the re-index run is linked, one retry timer
- change: publish: refuse, before publishing, unless hex.pm accepts HEX_API_KEY
- change: publish: the key preflight asks whether the key may write, not who owns it
- change: remove the Dockerfile and relx release sections: reckon-db is a library
