# Changelog

> **This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.**

## Score

- CAI 46 → 46 (+0.1)
- Rubric changed (rubric-2026.08.17 → rubric-2026.08.18) — scores are not directly comparable.

## Lenses

- Code Health 45 → 45 (-0.2)
- Architecture 98 → 98 (-0.1)
- Maturity 66 → 67 (+0.4)
- Readiness 29 → 29 (+0.0)
- Security 70 → 71 (+1.2)
- Domain Modelling 100 → 100 (+0.0)
- Event-Driven 80 → 80 (+0.0)

## Resolved (16)

- Change coupling: repo_tag_repo.rs ↔ query.rs (crates/adapters/src/persistence/psql/repo_tag_repo.rs)
- Dependency hygiene not measured — no supported dependency manifest was read
- Further orphaned files (smaller)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: crates/adapters/src/persistence/psql/repo_repo.rs (crates/adapters/src/persistence/psql/repo_repo.rs)
- Low IaC: DS-0026 (Dockerfile)
- Low IaC: DS-0026 (Dockerfile.worker)
- PostgresRepoRepo.list_ranked (cognitive 17) (crates/adapters/src/persistence/psql/repo_repo.rs)

## New (24)

- Change coupling: footer.rs ↔ header_nav.rs (crates/ui/src/components/layout/user/footer.rs)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- FileTooLong: fuzzy_search/mod.rs (crates/ui/src/components/layout/user/fuzzy_search/mod.rs)
- FileTooLong: icons/mod.rs (crates/ui/src/components/icons/mod.rs)
- FileTooLong: psql/repo_tag_repo.rs (crates/adapters/src/persistence/psql/repo_tag_repo.rs)
- FileTooLong: sidebar/component.rs (crates/ui/src/components/ui/sidebar/component.rs)
- High CVE: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: RUSTSEC-2023-0071 (Cargo.lock)
- Medium advisory (unmaintained): RUSTSEC-2024-0320 (Cargo.lock)
- Medium advisory (unmaintained): RUSTSEC-2025-0141 (Cargo.lock)
- …and 4 more
