{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "sustinbebustin-citadel-mcp",
  "component": "citadel-mcp",
  "generated_at": "2026-09-21T15:07:05.964Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 38,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0c37e-94f3-70e3-85d2-48324f7a93cc",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-21",
      "occurred_at": "2026-09-21 10:24:07.440663+00",
      "observed_since": "2026-09-20",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a0c37e-94f3-70e3-85d2-48324f7a93cc"
    },
    {
      "id": "chg_01a0a49a-484e-7efd-a070-f5d6bb100139",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 10:26:09.511765+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a0a49a-484e-7efd-a070-f5d6bb100139"
    },
    {
      "id": "chg_01a0808c-757f-7659-9247-93dc7522ab04",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-08",
      "occurred_at": "2026-09-08 10:24:43.597803+00",
      "observed_since": "2026-09-07",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a0808c-757f-7659-9247-93dc7522ab04"
    },
    {
      "id": "chg_01a05c88-7f41-7d3f-b689-da78f7761064",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.none",
      "from_value": "partial",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "108",
        "assessed": "109",
        "resolved": "108",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-01",
      "occurred_at": "2026-09-01 10:34:04.464361+00",
      "observed_since": "2026-08-31",
      "source": "scan",
      "summary": "Known CVEs (partial → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a05c88-7f41-7d3f-b689-da78f7761064"
    },
    {
      "id": "chg_01a05c88-7f43-7308-9053-3bec1193ce0a",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-01",
      "occurred_at": "2026-09-01 10:34:04.464361+00",
      "observed_since": "2026-08-31",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a05c88-7f43-7308-9053-3bec1193ce0a"
    },
    {
      "id": "chg_01a0523c-7365-7ce2-9b9f-82b056b39f46",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.tree_partial",
      "from_value": "pass",
      "to_value": "partial",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "seen": "107",
        "assessed": "106",
        "resolved": "105",
        "unresolved": "2",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 10:34:48.324659+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "Known CVEs (pass → partial)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a0523c-7365-7ce2-9b9f-82b056b39f46"
    },
    {
      "id": "chg_01a00a13-5698-7634-9874-84590b206bef",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "108",
        "assessed": "109",
        "resolved": "108",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "Known CVEs (fail → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-5698-7634-9874-84590b206bef"
    },
    {
      "id": "chg_01a00a13-569a-7e18-b005-f12c0a017f29",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-11525",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-11525"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-11525 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569a-7e18-b005-f12c0a017f29"
    },
    {
      "id": "chg_01a00a13-569b-73d7-ac83-87be660eed94",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-12151",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-12151"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-12151 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569b-73d7-ac83-87be660eed94"
    },
    {
      "id": "chg_01a00a13-569b-7890-bf69-78e2e3578d3a",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-15157",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-15157"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-15157 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569b-7890-bf69-78e2e3578d3a"
    },
    {
      "id": "chg_01a00a13-569b-7ddd-b5c4-34617f15d5d7",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16728",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16728"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-16728 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569b-7ddd-b5c4-34617f15d5d7"
    },
    {
      "id": "chg_01a00a13-569c-729e-a7e6-bfc3c132ef97",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-9679",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-9679"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-9679 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569c-729e-a7e6-bfc3c132ef97"
    },
    {
      "id": "chg_01a00a13-569c-76ed-8752-d1d43edf1897",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-6733",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-6733"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-6733 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569c-76ed-8752-d1d43edf1897"
    },
    {
      "id": "chg_01a00a13-569c-7b79-811d-7fc2babc5c02",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1525",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1525"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-1525 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569c-7b79-811d-7fc2babc5c02"
    },
    {
      "id": "chg_01a00a13-569e-78d2-8f41-54eb00a61f95",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16729",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16729"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-16729 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569e-78d2-8f41-54eb00a61f95"
    },
    {
      "id": "chg_01a00a13-569e-7d6d-9cbe-3470761cfaf8",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22036",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22036"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-22036 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569e-7d6d-9cbe-3470761cfaf8"
    },
    {
      "id": "chg_01a00a13-569f-728e-9143-f10befb95378",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1526",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1526"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-1526 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569f-728e-9143-f10befb95378"
    },
    {
      "id": "chg_01a00a13-569f-7772-a812-26fb99d2f8ed",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1527",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1527"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-1527 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569f-7772-a812-26fb99d2f8ed"
    },
    {
      "id": "chg_01a00a13-569f-7b78-93e2-6e7d29f98fe7",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-2229",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-2229"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 10:17:14.56838+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "CVE-2026-2229 no longer affects this package",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_01a00a13-569f-7b78-93e2-6e7d29f98fe7"
    },
    {
      "id": "chg_019feb2e-84a1-7abd-aba7-92190e58f633",
      "kind": "check.unverifiable",
      "family": "provenance-repo",
      "subject_kind": "check",
      "subject": "provenance-repo",
      "subject_child": "",
      "from_code": "provenance.repo_verified",
      "to_code": "provenance.repo_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-10",
      "occurred_at": "2026-08-10 10:18:38.089382+00",
      "observed_since": "2026-08-09",
      "source": "scan",
      "summary": "Provenance (pass → unverified)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019feb2e-84a1-7abd-aba7-92190e58f633"
    },
    {
      "id": "chg_019fcc6e-0022-79cb-9f63-aa761ccc0359",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-15157",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-15157",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 10:59:48.877431+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-15157 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fcc6e-0022-79cb-9f63-aa761ccc0359"
    },
    {
      "id": "chg_019fcc6e-0021-722f-a744-433e0bf8dd0d",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16728",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16728",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 10:59:48.877431+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-16728 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fcc6e-0021-722f-a744-433e0bf8dd0d"
    },
    {
      "id": "chg_019fcc6e-0023-7125-a25b-ab84ca3f4fdf",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16729",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16729",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 10:59:48.877431+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-16729 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fcc6e-0023-7125-a25b-ab84ca3f4fdf"
    },
    {
      "id": "chg_019fc487-ba91-7b1f-b8b5-500d5a93a5f0",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-11525",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-11525",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-11525 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba91-7b1f-b8b5-500d5a93a5f0"
    },
    {
      "id": "chg_019fc487-ba98-79c8-91eb-b532da63755c",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1527",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1527",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-1527 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba98-79c8-91eb-b532da63755c"
    },
    {
      "id": "chg_019fc487-ba99-74b4-a37f-45b164615631",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-9679",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-9679",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-9679 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba99-74b4-a37f-45b164615631"
    },
    {
      "id": "chg_019fc487-ba99-7c40-8b39-7a39204081a9",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1525",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1525",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-1525 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba99-7c40-8b39-7a39204081a9"
    },
    {
      "id": "chg_019fc487-ba9a-7436-821b-137df2d0ae99",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-6733",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-6733",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-6733 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba9a-7436-821b-137df2d0ae99"
    },
    {
      "id": "chg_019fc487-ba9b-7089-af04-68f3876421c1",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22036",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22036",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-22036 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba9b-7089-af04-68f3876421c1"
    },
    {
      "id": "chg_019fc487-ba9c-7dba-a790-27a5e8eb78bf",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-12151",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-12151",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-12151 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba9c-7dba-a790-27a5e8eb78bf"
    },
    {
      "id": "chg_019fc487-ba9d-7bf2-ae4a-40c6f12fbd00",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-2229",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-2229",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-2229 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba9d-7bf2-ae4a-40c6f12fbd00"
    },
    {
      "id": "chg_019fc487-ba9e-75d7-a4fd-38915dfc7071",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "ai > @ai-sdk/provider-utils > undici",
        "refs": "[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-9679\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]",
        "seen": "112",
        "package": "undici",
        "version": "5.29.0",
        "assessed": "109",
        "resolved": "108",
        "severity": "high",
        "transitive": "1",
        "unresolved": "4",
        "vulnerable": "[{\"name\":\"undici\",\"version\":\"5.29.0\",\"depth\":3,\"path\":[\"ai\",\"@ai-sdk/provider-utils\",\"undici\"],\"refs\":[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-9679\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba9e-75d7-a4fd-38915dfc7071"
    },
    {
      "id": "chg_019fc487-ba9f-7a63-bdbb-9935baaf7906",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1526",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1526",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-1526 affects this package (high)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-ba9f-7a63-bdbb-9935baaf7906"
    },
    {
      "id": "chg_019fc487-baa1-74b3-a7fa-ff205458bd83",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-baa1-74b3-a7fa-ff205458bd83"
    },
    {
      "id": "chg_019fc487-baa1-7b3c-8978-f2b2a03f5551",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "repo": "sustinbebustin/citadel-mcp"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-baa1-7b3c-8978-f2b2a03f5551"
    },
    {
      "id": "chg_019fc487-baa2-7078-9c00-6ebdf14629f5",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": null,
      "to_value": "sustinbebustin/citadel-mcp",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "sustinbebustin/citadel-mcp",
        "from": ""
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:10:57.239625+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "The attested source repository moved (sustinbebustin/citadel-mcp)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc487-baa2-7078-9c00-6ebdf14629f5"
    },
    {
      "id": "chg_019fc3ee-bcad-7b4c-b14a-1ca0eaa6edd0",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 19:23:50.808183+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fc3ee-bcad-7b4c-b14a-1ca0eaa6edd0"
    },
    {
      "id": "chg_019fb1b3-7f69-75b7-be27-9cea6a1acb2c",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:25:58.621964+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/sustinbebustin-citadel-mcp/citadel-mcp#chg-chg_019fb1b3-7f69-75b7-be27-9cea6a1acb2c"
    }
  ],
  "days": [
    {
      "date": "2026-09-21",
      "total": 91,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-19",
      "total": 90,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 90,
        "to": 93,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 27,
          "to_days": 28
        },
        "partial": false,
        "compared_to": "2026-09-18",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-17",
      "total": 89,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 83,
        "to": 87,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 25,
          "to_days": 26
        },
        "partial": false,
        "compared_to": "2026-09-16",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-16",
      "total": 88,
      "delta": -3,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-15",
      "total": 91,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-13",
      "total": 90,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 90,
        "to": 93,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 27,
          "to_days": 28
        },
        "partial": false,
        "compared_to": "2026-09-12",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-12",
      "total": 89,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-11",
      "total": 89,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 83,
        "to": 87,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 25,
          "to_days": 26
        },
        "partial": false,
        "compared_to": "2026-09-10",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    }
  ]
}