# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 58 → 60 (+1.7)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 56 → 56 (+0.0)
- Architecture 78 → 80 (+1.5)
- Maturity 64 → 64 (+0.0)
- Readiness 57 → 57 (+0.5)
- Security 60 → 63 (+3.5)
- Performance 100 (new)

## Resolved (4)

- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: src/1-one/tokenize/methods/03-whitespace/tokenize.js (src/1-one/tokenize/methods/03-whitespace/tokenize.js)
- Hotspot: src/3-three/numbers/numbers/api.js (src/3-three/numbers/numbers/api.js)

## New (11)

- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- Hotspot: src/1-one/change/api/replace.js (src/1-one/change/api/replace.js)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No direct assertions: svo main clause after a preposition (tests/three/sentences/svo.test.js)
- Outdated (npm): efrt
- Outdated (npm): grad-school
- Outdated (npm): suffix-thumb
- Projects may be oversized for their cohesion

## Changes since last survey

- 3 commits — 3 feature/other, 0 fixes

## By area

- (repo) — 3 commits

## Notable commits

- change: Merge branch 'master' into dualfroz/relative-clause-subject
- change: Merge pull request #1224 from dualfroz/dualfroz/main-clause-openers
- change: Merge pull request #1225 from dualfroz/dualfroz/relative-clause-subject
