# Changelog

## Score

- CAI 45 → 46 (+0.9)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 37 → 37 (+0.0)
- Architecture 85 → 87 (+2.4)
- Maturity 46 → 46 (+0.0)
- Readiness 59 → 57 (-2.3)
- Security 59 → 67 (+8.3)
- Accessibility 50 → 50 (+0.0)
- Performance 100 (new)

## Resolved (4)

- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)

## New (22)

- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Outdated (npm): application-config
- Outdated (npm): arch
- Outdated (npm): auto-launch
- Outdated (npm): bitfield
- Outdated (npm): chokidar
- Outdated (npm): create-torrent
- Outdated (npm): debounce
- Outdated (npm): iso-639-1
- Outdated (npm): music-metadata
- Outdated (npm): parse-torrent
- Outdated (npm): react
- Outdated (npm): react-dom
- Outdated (npm): rimraf
- Outdated (npm): semver
- …and 2 more
