# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 60 → 45 (-15.1)
- Rubric changed (rubric-2026.08.18 → rubric-2026.08.15) — scores are not directly comparable.

## Lenses

- Code Health 95 → 99 (+4.1)
- Architecture 100 → 96 (-4.4)
- Maturity 48 → 47 (-1.1)
- Readiness 57 → 25 (-31.9)
- Security 74 → 64 (-10.9)

## Resolved (20)

- Client.request (cognitive 28) (src/Pay/Client.php)
- Client.request (cyclomatic 21) (src/Pay/Client.php)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (src/OpenPlatform/Server.php)
- Duplicated block (10 lines × 2) (src/OpenWork/JsApiTicket.php)
- Duplicated block (10 lines × 3) (src/OpenPlatform/Server.php)
- Duplicated block (11 lines × 2) (src/MiniApp/Application.php)
- Duplicated block (11 lines × 2) (src/OpenWork/JsApiTicket.php)
- Duplicated block (12 lines × 2) (src/MiniApp/Application.php)
- Duplicated block (12 lines × 6) (src/OfficialAccount/AccessToken.php)
- Duplicated block (13 lines × 2) (src/OpenWork/Server.php)
- Duplicated block (14 lines × 2) (src/OpenPlatform/ComponentAccessToken.php)
- Duplicated block (7 lines × 2) (src/MiniApp/Application.php)
- Duplicated block (9 lines × 2) (src/OpenWork/Application.php)
- Duplicated block (9 lines × 3) (src/MiniApp/Application.php)
- Further orphaned files (smaller)
- RequestUtil.formatBody (cognitive 17) (src/Kernel/HttpClient/RequestUtil.php)
- The README is a single-page project page with no links to the architecture or design docs, even though many such files exist. (README.md)
- The README lacks a 'Getting Started' or 'Installation' section that the example code implies but does not explicitly state (e.g. Composer dependency vs. manual install). (README.md)

## New (6)

- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- LLM evaluation failed
- No tests found
