# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 56 → 57 (+0.7)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 83 → 84 (+1.2)
- Architecture 96 → 94 (-2.0)
- Maturity 82 → 88 (+6.0)
- Readiness 69 → 32 (-36.5)
- Security 53 → 68 (+15.0)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (6)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Further orphaned files (smaller)
- Further sole-owners (lower concentration)
- Off-boarding risk: anonymized user #1
- Unpinned build actions

## New (26)

- Change coupling: ActionCableSubscriber.ts ↔ addGraphQLSubscriptions.ts (javascript_client/src/subscriptions/ActionCableSubscriber.ts)
- Change coupling: ActionCableSubscriber.ts ↔ createActionCableHandler.ts (javascript_client/src/subscriptions/ActionCableSubscriber.ts)
- Change coupling: SubscriptionExchange.ts ↔ createActionCableHandler.ts (javascript_client/src/subscriptions/SubscriptionExchange.ts)
- Change coupling: addGraphQLSubscriptions.ts ↔ createActionCableHandler.ts (javascript_client/src/subscriptions/addGraphQLSubscriptions.ts)
- Change coupling: cli.ts ↔ sendPayload.ts (javascript_client/src/cli.ts)
- Change coupling: index.ts ↔ prepareIsolatedFiles.ts (javascript_client/src/sync/index.ts)
- Change coupling: index.ts ↔ prepareProject.ts (javascript_client/src/sync/index.ts)
- Change coupling: index.ts ↔ sendPayload.ts (javascript_client/src/sync/index.ts)
- Change coupling: jest.config.js ↔ index.ts (javascript_client/jest.config.js)
- Change coupling: prepareIsolatedFiles.ts ↔ prepareProject.ts (javascript_client/src/sync/prepareIsolatedFiles.ts)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (11 lines × 3) (lib/graphql/schema/addition.rb)
- Duplicated block (18 lines × 2) (lib/graphql/language/parser.rb)
- High CVE: [GHSA redacted] (javascript_client/package-lock.json)
- High CVE: [GHSA redacted] (javascript_client/package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Low CVE: [GHSA redacted] (javascript_client/package-lock.json)
- …and 6 more

## Changes since last survey

- 13 commits — 11 feature/other, 2 fixes

## By area

- .github/workflows — 3 commits
- graphql-c_parser/ext — 2 commits
- javascript_client/package-lock.json — 2 commits
- lib/generators — 2 commits
- spec/dummy — 2 commits
- (root) — 1 commit
- graphql-c_parser/CHANGELOG.md — 1 commit

## Notable commits

- fix: Merge pull request #5683 from ydah/fix-execution-system-stack-error
- fix: Merge pull request #5684 from ydah/fix-load-mounted-routes-before-integration-tests
- change: Add YYSTACK_USE_ALLOCA 1
- change: Bump brace-expansion in /javascript_client
- change: Bump shogo82148/actions-setup-redis from 1.55.0 to 1.56.0
- change: Handle SystemStackError during query execution
- change: Load mounted routes before integration tests
- change: Merge commit from fork
- change: Merge pull request #5680 from ydah/add-actions-lint-ci
- change: Merge pull request #5681 from rmosolgo/dependabot/npm_and_yarn/javascript_client/multi-5e81c1b34f
- change: Merge pull request #5682 from rmosolgo/dependabot/github_actions/shogo82148/actions-setup-redis-1.56.0
- change: c-parser 1.1.4
- change: pro-1.30.2

## Architecture

- Containers 0 added · 0 removed · contexts 0 added · 1 removed · edges 0 added · 0 removed

## Removed bounded contexts (1)

- graphql
