# Changelog

## Score

- CAI 55 → 40 (-15.4)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 59 → 61 (+1.9)
- Maturity 60 → 61 (+1.0)
- Readiness 51 → 24 (-27.5)
- Security 60 → 52 (-8.4)

## Resolved (15)

- (anonymous) (cognitive 22) (lib/monitor/match.js)
- (anonymous) (cognitive 24) (lib/nodemon.js)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High vulnerability: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- The README states 'nodemon does *not* require any additional changes' while the Sample nodemon.json file shows a local installation that must be run via npx, which requires no global change. This is a subtle inconsistency in the documentation. (README.md)
- exec (cognitive 58) (lib/config/exec.js)
- nodemonOption (cognitive 44) (lib/cli/parse.js)
- run (cognitive 33) (lib/monitor/run.js)

## New (51)

- (anonymous) (cognitive 23) (lib/monitor/match.js)
- (anonymous) (cognitive 25) (lib/nodemon.js)
- Boundary-crossing change coupling: index.js ↔ bus.js (lib/config/index.js)
- Boundary-crossing change coupling: index.js ↔ run.js (lib/cli/index.js)
- Boundary-crossing change coupling: load.js ↔ log.js (lib/config/load.js)
- Boundary-crossing change coupling: run.js ↔ bus.js (lib/monitor/run.js)
- Boundary-crossing change coupling: run.js ↔ index.js (lib/monitor/run.js)
- Boundary-crossing change coupling: run.js ↔ log.js (lib/monitor/run.js)
- Boundary-crossing change coupling: watch.js ↔ add.js (lib/monitor/watch.js)
- Boundary-crossing change coupling: watch.js ↔ bus.js (lib/monitor/watch.js)
- Boundary-crossing change coupling: watch.js ↔ index.js (lib/monitor/watch.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 31 more

## Changes since last survey

- 1 commits — 1 feature/other, 0 fixes

## By area

- (root) — 1 commit

## Notable commits

- change: chore: website
