# Changelog

## Score

- CAI 45 → 46 (+0.7)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 51 → 51 (+0.0)
- Architecture 100 → 90 (-10.4)
- Maturity 33 → 33 (+0.0)
- Readiness 50 → 54 (+4.1)
- Security 67 → 72 (+4.7)

## Resolved (5)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Hotspot: lib/server.js (lib/server.js)
- Off-boarding risk: anonymized user #1

## New (13)

- High CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
- Outdated (npm): csv
- Outdated (npm): formidable
- Outdated (npm): lru-cache
- Outdated (npm): mime
- Outdated (npm): negotiator
- Outdated (npm): pidusage
- Outdated (npm): pino
- Outdated (npm): qs
- Outdated (npm): restify-errors
- Projects may be oversized for their cohesion
