# Changelog

## Score

- CAI 50 → 54 (+3.2)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (-0.4)
- Architecture 69 → 69 (+0.0)
- Maturity 43 → 46 (+3.1)
- Readiness 36 → 42 (+6.3)
- Security 100 → 93 (-6.7)

## Resolved (5)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- No exposed public API
- Test reliability not included
- single-maintainer — knowledge-concentration (bus factor) risk

## New (12)

- Critical CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- Inconsistent naming convention for iteration. Ruby standard library typically uses 'each' and 'reverse_each'. However, if other collection methods in this API follow a different pattern (e.g., 'iterate' vs 'loop'), this stands out. In this specific snippet, it is consistent with Ruby idioms, but 'list()' is also present. If 'list()' returns an array, 'each' is redundant if the object is Enumerable. If not, it's fine. This is a minor point, but 'list' vs 'each' suggests a potential confusion between getting a snapshot vs iterating.
- Inconsistent verb usage for similar operations. The DSL module uses 'import' while the Injector module uses 'inject' for what appears to be the same configuration action. Additionally, the '_static' suffix is used in both, but the base verbs differ.
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Outdated: armitage-rubocop
- Outdated: pry
- Outdated: rake
- Outdated: rspec
- Semantic duplication with inconsistent naming. Both methods appear to retrieve the set of containers associated with the current context (instance vs class). 'associated' and 'linked' are used interchangeably for the same concept.
- TodoComment (lib/smart_core/injection.rb)
