# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 27 → 41 (+13.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 37 → 32 (-4.3)
- Architecture 91 (new)
- Maturity 51 → 51 (-0.1)
- Readiness 11 → 32 (+20.7)
- Security 50 → 73 (+23.2)

## Resolved (81)

- (anonymous) (cognitive 16) (src/js/controls.js)
- (anonymous) (cognitive 31) (src/js/source.js)
- (anonymous) (cognitive 34) (src/js/controls.js)
- (anonymous) (cyclomatic 23) (src/js/source.js)
- (anonymous) (cyclomatic 29) (src/js/controls.js)
- Change coupling: controls.js ↔ media.js (src/js/controls.js)
- Change coupling: defaults.js ↔ plyr.js (src/js/config/defaults.js)
- Change coupling: fullscreen.js ↔ plyr.js (src/js/fullscreen.js)
- Change coupling: listeners.js ↔ style.js (src/js/listeners.js)
- Change coupling: media.js ↔ plyr.js (src/js/media.js)
- Change coupling: plyr.js ↔ plyr.polyfilled.js (src/js/plyr.js)
- Change coupling: plyr.js ↔ style.js (src/js/plyr.js)
- Change coupling: plyr.js ↔ ui.js (src/js/plyr.js)
- Change coupling: vimeo.js ↔ style.js (src/js/plugins/vimeo.js)
- Change coupling: vimeo.js ↔ youtube.js (src/js/plugins/vimeo.js)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Dimension evaluation failed
- FileTooLong: js/controls.js (src/js/controls.js)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 61 more

## New (71)

- ClassTooLong: Listeners (src/js/listeners.js)
- ClassTooLong: Plyr (src/js/plyr.js)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FileTooLong: js/plyr.js (src/js/plyr.js)
- Floating npm dependency: @videojs/mux-video
- Floating npm dependency: @videojs/react
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 51 more

## Changes since last survey

- 17 commits — 12 feature/other, 5 fixes

## By area

- (root) — 9 commits
- site/src — 4 commits
- src/js — 2 commits
- demo/src — 1 commit
- site/package-lock.json — 1 commit

## Notable commits

- fix: chore: fix ci/cd workflows
- fix: fix(captions): case-insensitive language matching + keep selected track
- fix: fix(types): support default and CSS imports
- fix: fix: restore volume when unmuting from zero
- fix: refactor(site): add UTM params, style fixes
- change: Install Vercel Speed Insights
- change: chore(site): add Vercel Analytics
- change: chore(site): bump Video.js v10 preview to main@1c629d6
- change: chore(site): install Speed Insights with pnpm and block other lockfiles
- change: chore(site): limit button transitions and move the poster frame
- change: chore(site): move Vercel config into site for the site root directory
- change: chore: keep site changes out of release-please
- change: chore: tooling cleanup, site changes
- change: chore: update readme to clean it up
- change: perf(site): stream Mux video with the Video.js SPF engine instead of hls.js
- change: refactor(site): tweaks to dark button styles
- change: refactor: use preact instead of react
