# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 50 → 58 (+8.0)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 44 → 65 (+21.4)
- Architecture 57 → 57 (+0.0)
- Maturity 58 → 60 (+1.8)
- Readiness 55 → 56 (+1.1)
- Security 50 → 56 (+6.3)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 80 → 80 (+0.0)

## Resolved (58)

- Dependency hygiene not measured — no supported dependency manifest was read
- Dormant codebase
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 38 more

## New (37)

- Concentrated knowledge decay
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 17 more

## Changes since last survey

- 23 commits — 23 feature/other, 0 fixes

## By area

- (root) — 23 commits

## Notable commits

- change: chore(deps): bump commander from 11.1.0 to 14.0.3 (#224)
- change: chore(deps): bump commander from 14.0.3 to 15.0.0 (#252)
- change: chore(deps-dev): bump @babel/cli from 7.28.6 to 8.0.4 (#253)
- change: chore(deps-dev): bump @babel/core from 7.29.0 to 8.0.1 (#240)
- change: chore(deps-dev): bump @babel/eslint-parser from 7.28.6 to 8.0.1 (#256)
- change: chore(deps-dev): bump @babel/preset-env from 7.29.0 to 8.0.2 (#251)
- change: chore(deps-dev): bump @babel/register from 7.28.6 to 8.0.1 (#245)
- change: chore(deps-dev): bump babel-plugin-istanbul from 6.1.1 to 8.0.0 (#249)
- change: chore(deps-dev): bump c8 from 8.0.1 to 12.0.0 (#246)
- change: chore(deps-dev): bump chai from 5.3.3 to 6.2.2 (#241)
- change: chore(deps-dev): bump eslint-plugin-prettier from 5.5.5 to 5.5.6 (#254)
- change: chore(deps-dev): bump esmock from 2.7.3 to 2.7.6 (#255)
- change: chore(deps-dev): bump jest from 29.7.0 to 30.2.0 (#227)
- change: chore(deps-dev): bump jsdom from 28.0.0 to 30.0.0 (#250)
- change: chore(deps-dev): bump prettier from 3.1.1 to 3.8.1 (#219)
- change: chore(deps-dev): bump prettier from 3.8.1 to 3.9.6 (#248)
- change: chore(deps-dev): bump react from 19.2.4 to 19.2.8 (#239)
- change: chore(deps-dev): bump remark-footnotes from 4.0.1 to 5.0.0 (#247)
- change: chore(deps-dev): bump remark-preset-lint-consistent from 5.1.2 to 6.0.1 (#220)
- change: chore(deps-dev): bump remark-preset-lint-recommended from 6.1.3 to 7.0.1 (#242)
- …and 3 more
