# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 66 → 67 (+0.8)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 92 → 92 (-0.0)
- Architecture 97 → 97 (-0.3)
- Maturity 62 → 62 (-0.0)
- Readiness 73 → 63 (-10.1)
- Security 57 → 67 (+9.6)
- Performance 85 (new)

## Resolved (10)

- Change coupling clique: lib.rs, lib.rs, lib.rs (crates/factor-variables/src/lib.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: crates/factor-outbound-redis/src/host.rs (crates/factor-outbound-redis/src/host.rs)
- Hotspot: crates/trigger/src/cli.rs (crates/trigger/src/cli.rs)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/key-value-azure/src/store.rs)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- TodoComment (crates/templates/src/renderer.rs)

## New (43)

- Ambiguous API for componentization. `componentize_if_necessary` suggests a check-then-act pattern, while `componentize` suggests an unconditional action. However, without clear documentation, it is unclear if `componentize` also performs a check internally or if it always transforms. This leads to potential double-processing or confusion about when to use which.
- Ambiguous naming for build functions. `build` takes many parameters including `target_checks` and `wit_generation`, while `build_default` takes fewer. The name `build_default` suggests it is a convenience wrapper, but `build` is not named `build_full` or `build_advanced`. This creates confusion about which method to use for standard builds.
- Change coupling: lib.rs ↔ lib.rs (crates/factor-variables/src/lib.rs)
- Change coupling: lib.rs ↔ lib.rs (crates/variables-env/src/lib.rs)
- Documentation: no project overview (README.md)
- FileTooLong: commands/deps.rs (src/commands/deps.rs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent error handling strategy for metadata retrieval. `get_metadata` implies a Result (likely returning an error on missing key), while `require_metadata` implies a Result (likely panicking or returning a specific 'not found' error variant). The naming convention is inconsistent with standard Rust patterns where `get` often returns `Option` and `require`/`expect` panics, or `get` returns `Result` and `require` is not present. Here, both return `Result`, making the distinction unclear and redundant.
- Low cohesion: ComponentStdioWriter (LCOM4 4) (crates/trigger/src/cli/stdio.rs)
- Low cohesion: KeyValue (LCOM4 6) (crates/componentize/src/abi_conformance/test_key_value.rs)
- Low cohesion: KeyValueDispatch (LCOM4 8) (crates/factor-key-value/src/host.rs)
- Low cohesion: Template (LCOM4 4) (crates/templates/src/template.rs)
- Medium advisory (unsound): RUSTSEC-2026-0306 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0313 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0314 (Cargo.lock)
- Medium vulnerability: RUSTSEC-2026-0315 (Cargo.lock)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (crates/key-value-azure/src/store.rs)
- Off the main sequence: spin-app
- …and 23 more

## Changes since last survey

- 26 commits — 22 feature/other, 4 fixes

## By area

- (repo) — 10 commits
- (root) — 3 commits
- crates/capabilities — 3 commits
- crates/templates — 3 commits
- .github/workflows — 1 commit
- crates/app — 1 commit
- crates/dependency-wit — 1 commit
- crates/key-value-azure — 1 commit
- crates/loader — 1 commit
- crates/runtime-config — 1 commit
- examples/spin-timer — 1 commit

## Notable commits

- fix: Fix WIT extractor emitting wrong interface when duplicated names
- fix: Merge pull request #3716 from itowlson/extract-deps-fix-dep-imports-and-exports-same-named-itf
- fix: Merge pull request #3720 from ChihweiLHBird/fix-cosmos-kv-sql-injection
- fix: ci: Fix release job when canary release is missing (#3725)
- change: Add OpenBao Variable Provider (#3719)
- change: Add impl for wasi:keyvalue/{atmoics,batch} in deny-all-adapter (#3724)
- change: Add schema directive to empty template
- change: Build the deny adapter without WASI std (#3723)
- change: Explain that FromUtf8Error::into_bytes returns the original bytes
- change: Match inherited capability imports by semver track (#3722)
- change: Merge pull request #3676 from itowlson/avoid-reinstall-env-templates-if-already-there-sorta-kinda-crossing-a-lotta-fingers
- change: Merge pull request #3710 from spinframework/bump-wasmtime/prerelease-49.0.0
- change: Merge pull request #3714 from spinframework/memoize-default-tlsclientconfig
- change: Merge pull request #3717 from itowlson/empty-template-schema-directive
- change: Merge pull request #3718 from spinframework/less-allocatin
- change: Merge pull request #3726 from spinframework/wasmtime-49-0-01
- change: Merge pull request #3727 from ChihweiLHBird/zhiwei/templates-reuse-utf8-buffers
- change: Merge remote-tracking branch 'origin/main' into prerelease-49.0.0
- change: Parameterize Azure Cosmos key-value queries
- change: Reduce string allocations
- …and 6 more
