# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 53 → 56 (+3.4)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 86 → 87 (+0.8)
- Architecture 97 → 97 (+0.0)
- Maturity 83 → 83 (+0.0)
- Readiness 43 → 51 (+8.2)
- Security 58 → 60 (+1.7)
- Domain Modelling 100 → 100 (+0.0)
- Accessibility 48 → 48 (+0.0)

## Resolved (6)

- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- The optional AI advisor section states the feature is 'optional and disabled by default' but does not explain how to enable it (required API key, required Gemini model alias) or where to set those environment variables. (backend/README.md)

## New (13)

- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (frontend/pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Medium IaC: CKV_DOCKER_3 (backend/Dockerfile)
- Medium IaC: CKV_DOCKER_3 (frontend/Dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- The optional AI advisor section mentions a Google AI Studio API key but does not state the minimum free tier requirements or how to obtain one. (backend/README.md)
