# Changelog

## Score

- CAI 52 → 60 (+8.7)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Architecture 69 → 69 (+0.0)
- Maturity 40 → 51 (+11.1)
- Readiness 57 → 61 (+4.3)
- Security 57 → 76 (+19.6)
- Domain Modelling 100 → 100 (+0.0)

## Resolved (52)

- Dependency hygiene not measured — no supported dependency manifest was read
- Medium CVE: GO-2021-0223 (go.mod)
- Medium CVE: GO-2021-0224 (go.mod)
- Medium CVE: GO-2021-0226 (go.mod)
- Medium CVE: GO-2021-0234 (go.mod)
- Medium CVE: GO-2021-0235 (go.mod)
- Medium CVE: GO-2021-0239 (go.mod)
- Medium CVE: GO-2021-0240 (go.mod)
- Medium CVE: GO-2021-0241 (go.mod)
- Medium CVE: GO-2021-0242 (go.mod)
- Medium CVE: GO-2021-0243 (go.mod)
- Medium CVE: GO-2021-0245 (go.mod)
- Medium CVE: GO-2021-0263 (go.mod)
- Medium CVE: GO-2021-0264 (go.mod)
- Medium CVE: GO-2021-0317 (go.mod)
- Medium CVE: GO-2021-0319 (go.mod)
- Medium CVE: GO-2021-0347 (go.mod)
- Medium CVE: GO-2022-0236 (go.mod)
- Medium CVE: GO-2022-0273 (go.mod)
- Medium CVE: GO-2022-0288 (go.mod)
- …and 32 more

## New (3)

- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- LLM evaluation failed
- Workflow token permissions not restricted
