# Changelog

## Score

- CAI 60 → 61 (+0.6)
- Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

## Lenses

- Code Health 100 → 100 (+0.0)
- Architecture 69 → 68 (-1.0)
- Maturity 79 → 76 (-3.2)
- Readiness 40 → 46 (+6.2)
- Security 95 → 75 (-20.0)

## Resolved (11)

- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — no supported dependency manifest was read
- No exposed public API
- Rotate the exposed credentials — git history can't be un-committed
- Secret: generic-api-key (config/secrets.yml)
- Test reliability not included
- The README lists requirements (ruby 2.4.2, PostgreSQL 10) but does not state which versions of Rails/ROM/GraphQL are supported or what environment variables the app needs to run. (README.md)
- complexity unreadable for .rb — churn × complexity hotspots could not be measured
- early-stage repository — too little history to judge knowledge freshness
- git history depth insufficient
- single-maintainer — knowledge-concentration (bus factor) risk

## New (22)

- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical CVE: [GHSA redacted] (Gemfile.lock)
- Critical vulnerability: [GHSA redacted] (Gemfile.lock)
- Documentation: no installation or build instructions (README.md)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- High CVE: [GHSA redacted] (Gemfile.lock)
- Low CVE: [GHSA redacted] (Gemfile.lock)
- Medium CVE: [GHSA redacted] (Gemfile.lock)
- …and 2 more
