# Changelog

## Score

- CAI 48 → 51 (+3.1)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.

## Lenses

- Code Health 63 → 62 (-0.2)
- Architecture 96 → 92 (-3.7)
- Maturity 58 → 56 (-2.4)
- Readiness 39 → 40 (+0.8)
- Security 46 → 64 (+18.0)
- Accessibility 56 → 56 (+0.0)
- Performance 100 (new)

## Resolved (29)

- Change coupling: tools.rs ↔ Settings.tsx (src-tauri/src/commands/tools.rs)
- Change-coupling hub: ProjectDetail.tsx → projects.rs, project_scanner.rs, WorkspaceView.tsx (src/views/ProjectDetail.tsx)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (28 lines × 2) (src-tauri/src/bin/skills-manager-cli.rs)
- Duplicated block (9 lines × 2) (src-tauri/src/commands/agent_workspace.rs)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [CVE redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Hotspot: src-tauri/src/commands/skills.rs (src-tauri/src/commands/skills.rs)
- Hotspot: src-tauri/src/core/merge/apply.rs (src-tauri/src/core/merge/apply.rs)
- Hotspot: src-tauri/src/core/merge/decision.rs (src-tauri/src/core/merge/decision.rs)
- Hotspot: src-tauri/src/core/merge/pending.rs (src-tauri/src/core/merge/pending.rs)
- …and 9 more

## New (52)

- Change coupling: ProjectDetail.tsx ↔ WorkspaceView.tsx (src/views/ProjectDetail.tsx)
- Change coupling: project_scanner.rs ↔ ProjectDetail.tsx (src-tauri/src/core/project_scanner.rs)
- Duplicate DTOs for GitHub connection state. Both types expose `url`, `login`, `repo_created`, and `repo_private`. `GithubBackupConnectResult` adds `remote_has_content` while `GithubConnectInfo` adds `repo_full_name`. This suggests two different layers (commands vs core API) are returning nearly identical data structures without sharing a common type.
- Duplicate scanning result structures. Both `ScanResultDto` and `ScanPlan` contain `tools_scanned`, `skills_found`, and a group/collection of discovered items (`groups` vs `discovered`). `ScanResultDto` is a DTO (likely for API/IPC) while `ScanPlan` is an internal core type, but they represent the same semantic state of a scan operation.
- Duplicated block (31 lines × 2) (src-tauri/src/bin/skills-manager-cli.rs)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- High CVE: [GHSA redacted] (package-lock.json)
- Hotspot: src-tauri/src/core/app_state.rs (src-tauri/src/core/app_state.rs)
- Hotspot: src/components/BatchTagDialog.tsx (src/components/BatchTagDialog.tsx)
- Hotspot: src/components/FirstRunRestoreDialog.tsx (src/components/FirstRunRestoreDialog.tsx)
- Hotspot: src/components/PresetBar.tsx (src/components/PresetBar.tsx)
- Hotspot: src/components/Sidebar.tsx (src/components/Sidebar.tsx)
- Hotspot: src/context/AppContext.tsx (src/context/AppContext.tsx)
- Inconsistent naming for audit record vs builder. `AuditEntry` is the final record, while `AuditDraft` is the builder. This is generally acceptable, but `AuditEntry` properties like `skill_id` are `PathBuf` while `AuditDraft` methods take `impl Into<String>`. The internal representation (`PathBuf`) vs input interface (`String`) mismatch is inconsistent with other parts of the API where `String` is often used for IDs.
- Medium vulnerability: RUSTSEC-2026-0285 (src-tauri/Cargo.lock)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (src-tauri/src/commands/projects.rs)
- Near-duplicate member pair (58 shared lines) (src-tauri/src/bin/skills-manager-cli.rs)
- Nearly identical result types for distinct operations. `UpdateSkillResult` and `ReimportSkillResult` share `skill`, `pending_removals`, and `removal_approval`. The only difference is the type name, implying the operations are handled separately despite having identical output contracts. This forces callers to handle two different types for effectively the same outcome.
- Outdated: anyhow
- …and 32 more

## Changes since last survey

- 32 commits — 12 feature/other, 20 fixes

## By area

- src-tauri/src — 16 commits
- (root) — 8 commits
- src/components — 3 commits
- src/i18n — 2 commits
- (repo) — 1 commit
- scripts/prepare-release.mjs — 1 commit
- src/lib — 1 commit

## Notable commits

- fix: Merge pull request #460 from zhirogo/fix/removal-ownership-preflight
- fix: fix(add-skills): stop shift-click from selecting the row text
- fix: fix(central-repo): address review of the relocation fix
- fix: fix(central-repo): make a changed library path actually take effect (#449 #469 #393)
- fix: fix(central-repo): set the old copy aside after a cross-volume move
- fix: fix(central-repo): share a lifetime library lease; tighten repoint and debris rules
- fix: fix(hash): stop line endings alone from reading as an update
- fix: fix(i18n): fall back to English outside the Chinese locales (#394)
- fix: fix(preset-bar): stop a half-applied preset from reading as untouched
- fix: fix(preset-bar): wrap preset chips onto multiple lines instead of (#448)
- fix: fix(projects): count one logical skill once and stop guessing its library match (#267)
- fix: fix(projects): let a unique content hash outrank another skill's directory
- fix: fix(sync): gate every row-driven removal behind the ownership preflight
- fix: fix(sync): keep a deployment another tool shares when disabling or unchecking one
- fix: fix(ui): keep the confirm dialog's buttons on screen with a long file list (#432)
- fix: fix(ui): make the confirm dialog's height cap survive the text-size zoom
- fix: fix(workspace): do not detach a source_ref through a symlinked adoption target
- fix: fix(workspace): re-point source_ref before an adoption replaces the import source dir (#425) (#427)
- fix: fix: preflight CLI dry-run deployments (#483)
- fix: fix: preserve nested agent skill paths during import (#482)
- …and 12 more
