# Changelog

## Score

- CAI 39 → 41 (+2.8)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 86 → 86 (+0.0)
- Architecture 96 → 95 (-0.6)
- Maturity 66 → 67 (+0.2)
- Readiness 63 → 66 (+3.2)
- Security 53 → 63 (+10.1)
- Event-Driven 10 → 10 (+0.0)
- Performance 89 (new)

## Resolved (23)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Documentation: no usage examples (crates/proxy/README.md)
- Hotspot: crates/compression/src/lib.rs (crates/compression/src/lib.rs)
- Hotspot: crates/core/src/conn/proto.rs (crates/core/src/conn/proto.rs)
- Hotspot: crates/core/src/conn/quinn/builder.rs (crates/core/src/conn/quinn/builder.rs)
- Hotspot: crates/core/src/http/body/res.rs (crates/core/src/http/body/res.rs)
- Hotspot: crates/core/src/http/errors/status_error.rs (crates/core/src/http/errors/status_error.rs)
- Hotspot: crates/core/src/http/range.rs (crates/core/src/http/range.rs)
- Hotspot: crates/core/src/serde/request.rs (crates/core/src/serde/request.rs)
- Hotspot: crates/core/src/server.rs (crates/core/src/server.rs)
- Hotspot: crates/core/src/writing/seek.rs (crates/core/src/writing/seek.rs)
- Hotspot: crates/macros/src/extract.rs (crates/macros/src/extract.rs)
- Hotspot: crates/oapi-macros/src/component.rs (crates/oapi-macros/src/component.rs)
- Hotspot: crates/oapi-macros/src/feature.rs (crates/oapi-macros/src/feature.rs)
- Hotspot: crates/oapi-macros/src/schema_type.rs (crates/oapi-macros/src/schema_type.rs)
- Hotspot: crates/oapi/src/openapi.rs (crates/oapi/src/openapi.rs)
- Hotspot: crates/tus/src/handlers/patch.rs (crates/tus/src/handlers/patch.rs)
- Repeated repair: crates/core/src/http/response.rs (crates/core/src/http/response.rs)
- …and 3 more

## New (15)

- Ambiguous duplication. `insert_typed` and `inject` both take a value `V` and return `Self`. In many contexts, 'inject' is a synonym for 'insert'. Without seeing the implementation, it is unclear if they differ by key derivation or behavior, but the naming convention is inconsistent (one is explicit about type, one is generic verb).
- Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
- Documentation: no project overview (README.md)
- Duplicate method names with identical signatures. `directory` and `get_directory` appear to perform the same configuration action (setting a directory URL), likely due to a copy-paste error or incomplete refactoring.
- Duplicate method names with identical signatures. `get_typed`/`obtain` and `get_typed_mut`/`obtain_mut` appear to be synonyms for retrieving typed values from the depot.
- Duplicate method signatures. Two methods named `extension` with identical parameters but different return types (`Problem` vs `Self`). This is a compile error in Rust unless they are in different traits or one is a typo in the API surface description. Assuming it's a valid surface, this is a severe inconsistency/error.
- Inconsistent naming for removal operations. `delete` returns a `bool` (success/failure), while `remove` returns a `Box` (likely the removed value or a result). This is confusing because `remove` typically implies returning the value in Rust, while `delete` implies a void/bool action. However, the return types are vastly different, suggesting they might do different things, but the names are counter-intuitive relative to their signatures.
- Low cohesion: Cors (LCOM4 4) (crates/cors/src/lib.rs)
- Low cohesion: DynStream (LCOM4 4) (crates/core/src/conn.rs)
- Low cohesion: EncodeStream (LCOM4 6) (crates/compression/src/stream.rs)
- Low cohesion: OpenApi (LCOM4 7) (crates/oapi/src/openapi.rs)
- Low cohesion: Router (LCOM4 6) (crates/core/src/routing/router.rs)
- Off the main sequence: salvo-serde-util
- Off the main sequence: salvo_core
- Split crates/core

## Changes since last survey

- 4 commits — 2 feature/other, 2 fixes

## By area

- (root) — 2 commits
- crates/serve-static — 1 commit
- examples/otel-jaeger — 1 commit

## Notable commits

- fix: fix(examples): align OpenTelemetry examples with 0.33 (#1710)
- fix: fix(serve-static): block paths beneath dot directories (#1708)
- change: Release 1.0.0
- change: build(deps): upgrade OpenTelemetry crates to 0.33 together (#1709)
