# Changelog

## Score

- CAI 28 → 45 (+16.6)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 81 (new)
- Architecture 75 (new)
- Maturity 13 → 81 (+67.5)
- Readiness 15 → 28 (+12.8)
- Security 100 → 49 (-51.5)
- Domain Modelling 90 (new)
- Event-Driven 100 (new)
- Accessibility 51 (new)

## Resolved (5)

- No automated tests
- No tests found
- bus factor not measured — no commits were sampled
- early-stage repository — too little history to judge knowledge freshness
- single-commit history — no usable git history window to measure hotspots

## New (159)

- Consequences are restatements rather than trade-offs (e.g. learning curve for PlantUML/C4-PlantUML vs existing tools) (docs/ADR/decisions/0011-application-architecture-documentation.md)
- Consequences are thin ('We use next material for made our logger format') rather than trade-offs such as OTel integration cost or operational complexity (docs/ADR/decisions/0010-logger-format.md)
- Consequences are thin: only one bullet stating the outcome and no trade-offs (e.g. performance cost of reduced transparency) (docs/ADR/decisions/0039-ui-accessibility.md)
- Consequences section is sparse and only lists benefits with no trade-offs (e.g. vendor lock-in to Storybook tools, component quality vs. third-party alternatives) (docs/ADR/decisions/0040-ui-kit.md)
- Context and consequences are both cited to an external source (Michael Nygard's blog + adr-tools repo), leaving the ADR itself uninformative and its own rationale buried in links (docs/ADR/decisions/0001-record-architecture-decisions.md)
- Context and decision are identical ('We want to have a monorepository...') with no context/problem and no consequences; only one sentence in body (docs/ADR/decisions/0012-use-monorepository.md)
- Context is 'We want to know product metrics by each services.' and Decision is 'We made grafana dashboard for product-metrics by each services.' with Consequences only beginning ('1. Requirements dashboard') (docs/ADR/decisions/0008-product-metrics-by-services.md)
- Context is a one-line rationale ('We use tracing and logging systems to track application events') with no trade-offs; consequences are citations rather than real consequences (docs/ADR/decisions/0009-naming-spans-and-attributes.md)
- Context is a single sentence ('We want to use integration tests to verify the correctness of our code.') and decision restates 'We will use k6' with no rationale; consequences are boilerplate install commands (go install + xk6 build) plus one plugin link (docs/ADR/decisions/0020-k6.md)
- Context is thin ("This ADR addresses the need to standardize our code style tool, considering efficiency and developer experience."), decision is a one-line rationale with no trade-offs or alternatives considered (docs/ADR/decisions/0032-python-code-style-selection.md)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (boundaries/mobile/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (boundaries/api/api-gateway/go.mod)
- Critical CVE: [GHSA redacted] (boundaries/bff/go.mod)
- Critical CVE: [GHSA redacted] (boundaries/link/go.mod)
- Critical CVE: [GHSA redacted] (boundaries/mobile/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (boundaries/bff/go.mod)
- Critical CVE: [GHSA redacted] (boundaries/ui/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (boundaries/chrome-extension/pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (boundaries/mobile/pnpm-lock.yaml)
- …and 139 more
