# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 56 → 57 (+1.0)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.1)
- Architecture 100 → 93 (-6.8)
- Maturity 37 → 41 (+3.7)
- Readiness 58 → 61 (+3.0)
- Security 80 → 73 (-6.7)

## Resolved (9)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (7 lines × 2) (lib/table_sync/publishing/batch.rb)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- Test reliability not included
- The README links to a GitHub Wiki page for usage, but no API reference is present. (README.md)

## New (44)

- Ambiguous intent of `find()` method in ORM adapters. In standard Ruby/ActiveRecord conventions, `find` usually retrieves a record by primary key. However, in the context of a sync library, this method likely performs a lookup to check for existence or fetch data for comparison. Without clear documentation or distinct naming (e.g., `lookup_record`, `fetch_for_sync`), it is unclear if this method returns the full object, a boolean, or raises an error if not found. Furthermore, `Base` defines `find()` but `Sequel` and `ActiveRecord` implementations might have different signatures or behaviors regarding arguments, creating a potential interface mismatch if not strictly typed.
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical vulnerability: [GHSA redacted] (Gemfile.lock)
- Duplicated block (6 lines × 2) (lib/table_sync/publishing/batch.rb)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent naming for synchronous vs asynchronous publishing operations. Batch and Single types expose both `publish_later` and `publish_now`, implying a choice between async and sync execution. However, the Raw type only exposes `publish_now`, lacking a `publish_later` equivalent despite having similar properties (routing_key, headers, etc.). This forces users to check the type to know if async publishing is supported.
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- …and 24 more
