# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 57 → 41 (-16.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 82 → 100 (+17.8)
- Architecture 100 → 94 (-5.9)
- Maturity 54 → 57 (+3.6)
- Readiness 76 → 32 (-44.2)
- Security 45 → 27 (-18.4)

## Resolved (14)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: src/backend.rs (x-api/src/backend.rs)
- FileTooLong: src/manifest.rs (src/manifest.rs)
- FileTooLong: src/runner.rs (src/runner.rs)
- Off-boarding risk: anonymized user #1
- TooManyFunctions: crate::runner (src/runner.rs)
- manifest::parse_class (cognitive 22) (src/manifest.rs)
- runner::execute_remote_command (cognitive 213) (src/runner.rs)
- runner::execute_remote_command (cyclomatic 199) (src/runner.rs)
- runner::extract_dm_users_by_id (cognitive 17) (src/runner.rs)
- runner::handle_direct_messages (cognitive 20) (src/runner.rs)
- runner::normalize_v2_tweet (cognitive 16) (src/runner.rs)
- runner::print_users (cyclomatic 16) (src/runner.rs)

## New (6)

- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No tests found
