# Changelog

## Score

- CAI 55 → 60 (+4.8)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 98 (-1.6)
- Architecture 100 → 100 (+0.0)
- Maturity 43 → 46 (+3.1)
- Readiness 36 → 46 (+10.4)
- Security 100 → 95 (-5.2)

## Resolved (7)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- No exposed public API
- Test reliability not included
- The container class creation example registers dependencies with memoize: true but the default behavior (memoize: false) is never stated or shown in the visible text. (README.md)
- The runtime-level namespace and dependency registration section describes fetching any type via #fetch but does not explain how to register a new type at runtime. (README.md)
- single-maintainer — knowledge-concentration (bus factor) risk

## New (19)

- Ambiguous duplication: `resolve` and `fetch` appear to perform the same core operation (retrieving a dependency by path). In dependency injection contexts, 'resolve' typically implies instantiation or graph traversal, while 'fetch' might imply a simple lookup, but without distinct behavioral documentation, they are confusingly similar public entry points.
- Documentation: no architecture or design documentation (README.md)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- Inconsistent naming for observer management: `Container` uses `observe`/`unobserve`/`clear_observers`, while the internal `DependencyWatcher` uses `watch`/`unwatch`/`clear_listeners`. The verbs (`observe` vs `watch`) and the noun for the callback (`observer` vs `listener`) are inconsistent.
- Inconsistent naming for registration operations: The `Container` class uses `register` and `namespace` as verbs, while the underlying `Registry` class uses `register_dependency` and `register_namespace`. This creates a split in intent expression between the facade (`Container`) and the internal storage (`Registry`).
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Outdated: armitage-rubocop
- Outdated: pry
- Outdated: rake
- Outdated: rspec
- State management inconsistency: `Container` exposes `freeze!`, `frozen?`, and `reload!`, while `Registry` only exposes `freeze!` and `frozen?`. The `reload!` capability is missing from `Registry`, suggesting an incomplete abstraction where the container manages state that the registry should also reflect or expose.
- TodoComment (lib/smart_core/container.rb)
- TodoComment (lib/smart_core/container.rb)
- TodoComment (lib/smart_core/container/dependency_watcher.rb)
- TodoComment (lib/smart_core/container/dependency_watcher.rb)
- TodoComment (lib/smart_core/container/dependency_watcher.rb)
- TodoComment (lib/smart_core/container/dependency_watcher.rb)
