# Changelog

## Score

- CAI 62 → 63 (+0.9)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 66 → 66 (+0.0)
- Architecture 100 → 89 (-10.5)
- Maturity 64 → 64 (+0.0)
- Readiness 55 → 56 (+0.9)
- Security 69 → 81 (+12.4)

## Resolved (4)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1

## New (5)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
