# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 67 → 36 (-30.7)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 83 → 36 (-47.5)
- Maturity 52 → 59 (+6.6)
- Readiness 73 → 25 (-48.0)
- Security 78 → 60 (-17.7)

## Resolved (35)

- Change coupling: mod.rs ↔ take_lines.rs (crates/mdbook-core/src/utils/mod.rs)
- Clean::new (cognitive 20) (src/cmd/clean.rs)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: html/tree.rs (crates/mdbook-html/src/html/tree.rs)
- Hotspot: crates/mdbook-html/src/html/tree.rs (crates/mdbook-html/src/html/tree.rs)
- MDBook::test_chapter (cognitive 38) (crates/mdbook-driver/src/mdbook.rs)
- MDBook::test_chapter (cyclomatic 19) (crates/mdbook-driver/src/mdbook.rs)
- MarkdownTreeBuilder::convert_fontawesome (cognitive 23) (crates/mdbook-html/src/html/tree.rs)
- MarkdownTreeBuilder::start_tag (cognitive 49) (crates/mdbook-html/src/html/tree.rs)
- MarkdownTreeBuilder::start_tag (cyclomatic 47) (crates/mdbook-html/src/html/tree.rs)
- MarkdownTreeBuilder::update_code_blocks (cognitive 26) (crates/mdbook-html/src/html/tree.rs)
- MarkdownTreeBuilder::update_code_blocks (cyclomatic 18) (crates/mdbook-html/src/html/tree.rs)
- Medium vulnerability: RUSTSEC-2026-0204 (Cargo.lock)
- Off-boarding risk: anonymized user #1
- PR-triggered workflow without a permissions block
- RenderToc::call (cognitive 37) (crates/mdbook-html/src/html_handlebars/helpers/toc.rs)
- RenderToc::call (cyclomatic 19) (crates/mdbook-html/src/html_handlebars/helpers/toc.rs)
- StaticFiles::hash_files (cognitive 30) (crates/mdbook-html/src/html_handlebars/static_files.rs)
- StaticFiles::write_files (cognitive 16) (crates/mdbook-html/src/html_handlebars/static_files.rs)
- …and 15 more

## New (11)

- Change coupling: book.js ↔ searcher.js (crates/mdbook-html/front-end/js/book.js)
- Dimension evaluation failed
- Hotspot: crates/mdbook-html/front-end/searcher/searcher.js (crates/mdbook-html/front-end/searcher/searcher.js)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No automated tests
- No tests found
- Scanner failed to run — not a clean result
- Title 'Document not found (404)' and body are identical; no context/problem or decision (guide/src/404.md)
- globalKeyHandler (cognitive 41) (crates/mdbook-html/front-end/searcher/searcher.js)

## Changes since last survey

- 5 commits — 5 feature/other, 0 fixes

## By area

- .github/workflows — 3 commits
- (root) — 2 commits

## Notable commits

- change: Merge pull request #3171 from rust-lang/update-dependencies
- change: Merge pull request #3172 from rust-lang/renovate/actions-checkout-7.x
- change: Merge pull request #3174 from rust-lang/renovate/browser-ui-test-0.x
- change: Merge pull request #3175 from rust-lang/renovate/actions-setup-node-7.x
- change: Merge pull request #3176 from rust-lang/renovate/cargo-semver-checks-0.x
