Wardex v2.2.2: CI/CD Hardening After Cordyceps
The Cordyceps vulnerability class didn't affect Wardex — but the investigation exposed three gaps that did.
The Cordyceps vulnerability class didn't affect Wardex — but the investigation exposed three gaps that did.
Completing the CRA-ready auditability layer — silent failures become structured logs, and cross-execution memory arrives with BLAKE3 hash chain integrity.
SHA-256 and BLAKE3 config hashing, chained audit log verification, divergence detection via webhooks, and forensically verifiable release gate decisions.
Docker images, GitHub Action, NIST CSF catalog, and HTML reports — what changed and why, grounded in architectural decisions rather than market claims.
Turning vulnerability scanners into CRA-compliant audit evidence without changing how your team ships.