# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 53 → 54 (+0.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

## Lenses

- Code Health 81 → 81 (+0.0)
- Architecture 99 → 99 (+0.1)
- Maturity 40 → 40 (+0.1)
- Readiness 60 → 60 (+0.0)
- Security 58 → 58 (+0.2)

## Resolved (6)

- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Off-boarding risk: anonymized user #2
- The README links out to a detailed upload example but does not state whether the client supports uploading leaks without an API key (Bugsnag only) or if there is an alternative library option. (docs/uploading.md)
- The upgrade guide mentions the no-op artifact but does not explain what happens if RefWatcher or ObjectWatcher code still appears in release builds. (docs/upgrading-to-leakcanary-2.0.md)

## New (3)

- LLM evaluation failed
- Off-boarding risk: anonymized user #2
- Off-boarding risk: anonymized user #1

## Architecture

- Containers 0 added · 0 removed · contexts 1 added · 1 removed · edges 0 added · 0 removed

## Added bounded contexts (1)

- .

## Removed bounded contexts (1)

- .
