# Changelog

## Score

- CAI 35 → 35 (+0.6)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 74 → 74 (+0.1)
- Architecture 44 → 44 (+0.2)
- Maturity 49 → 49 (-0.1)
- Readiness 17 → 18 (+0.8)
- Security 73 → 75 (+2.5)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 44 → 45 (+0.8)

## Resolved (13)

- Boundary-crossing change coupling: userApi.ts ↔ PostModalActions.tsx (Frontend/src/apis/api/userApi.ts)
- Change coupling clique: CreatePostBody.tsx, CreatePostFormSubmit.tsx, postSlice.ts (Frontend/src/components/create-post/CreatePostBody.tsx)
- High CVE: [GHSA redacted] (Backend/package-lock.json)
- Low CVE: [GHSA redacted] (Frontend/package-lock.json)
- Low CVE: [GHSA redacted] (Backend/package-lock.json)
- Low vulnerability: [GHSA redacted] (Backend/package-lock.json)
- Medium CVE: [GHSA redacted] (Frontend/package-lock.json)
- Medium CVE: [GHSA redacted] (Frontend/package-lock.json)
- Medium CVE: [GHSA redacted] (Backend/package-lock.json)
- Medium CVE: [GHSA redacted] (Backend/package-lock.json)
- Rotate the exposed credentials — git history can't be un-committed
- Secret: gcp-api-key (Frontend/src/firebase/farebase.ts)
- The frontend README is empty, so the front-end setup and routing are not documented. (Frontend/README.md)

## New (12)

- Boundary-crossing change coupling: CreatePostFormSubmit.tsx ↔ postSlice.ts (Frontend/src/components/create-post/CreatePostFormSubmit.tsx)
- Change coupling: App.tsx ↔ SignInForm.tsx (Frontend/src/App.tsx)
- Change coupling: CreatePostBody.tsx ↔ CreatePostFormSubmit.tsx (Frontend/src/components/create-post/CreatePostBody.tsx)
- Change coupling: Sidebar.tsx ↔ EditProfileForm.tsx (Frontend/src/components/common/Sidebar.tsx)
- High CVE: [GHSA redacted] (Backend/package-lock.json)
- High CVE: [GHSA redacted] (Backend/package-lock.json)
- High CVE: [GHSA redacted] (Backend/package-lock.json)
- High CVE: [GHSA redacted] (Frontend/package-lock.json)
- High CVE: [GHSA redacted] (Backend/package-lock.json)
- Medium CVE: [GHSA redacted] (Frontend/package-lock.json)
- Medium CVE: [GHSA redacted] (Frontend/package-lock.json)
- Medium CVE: [GHSA redacted] (Frontend/package-lock.json)
