# Changelog

## Score

- CAI 64 → 35 (-28.9)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 73 → 54 (-18.9)
- Architecture 90 → 90 (-0.2)
- Maturity 75 → 58 (-17.1)
- Readiness 57 → 14 (-43.1)
- Security 60 → 46 (-13.6)

## Resolved (21)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: lib/cluster-adapter.ts (packages/socket.io-adapter/lib/cluster-adapter.ts)
- FileTooLong: lib/server.ts (packages/engine.io/lib/server.ts)
- FileTooLong: lib/socket.ts (packages/engine.io-client/lib/socket.ts)
- Further orphaned files (smaller)
- Further sole-owners (lower concentration)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High vulnerability: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Low CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- Medium CVE: [GHSA redacted] (package-lock.json)
- …and 1 more

## New (79)

- (anonymous) (cognitive 24) (packages/socket.io/client-dist/socket.io.js)
- (anonymous) (cyclomatic 22) (packages/socket.io/client-dist/socket.io.js)
- Dimension evaluation failed
- FileTooLong: client-dist/socket.io.js (packages/socket.io/client-dist/socket.io.js)
- FileTooLong: test/server.js (packages/engine.io/test/server.js)
- FileTooLong: test/webtransport.mjs (packages/engine.io/test/webtransport.mjs)
- FileTooLong: v5-test-suite/test-suite.js (docs/socket.io-protocol/v5-test-suite/test-suite.js)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- …and 59 more
