André Ataíde

Writing

Wardex v2.4.1: Code Health Audit Wrap-Up and Sealed Release

Three audit phases — security, tests, refactor — land in a maintenance release, anchored via the 3CP provenance flow.

Wardex v2.4.0: EU AI Act Framework and Gleipnir-Anchored Releases

The EU AI Act (Regulation 2024/1689) arrives as a 31-control framework, and releases gain cryptographic provenance via Gleipnir anchoring.

Wardex v2.3.0: Deterministic Canonicalization and 3CP Provenance Attestation

CBOR deterministic encoding replaces ad-hoc serialization; CDDL schemas define the envelopes; and tool provenance becomes a cryptographically-bound attestation.

Wardex v2.2.2: CI/CD Hardening After Cordyceps

The Cordyceps vulnerability class didn't affect Wardex — but the investigation exposed three gaps that did.

Wardex v2.2.1: Explicit Rejection Logging and Persistent State Store

Completing the CRA-ready auditability layer — silent failures become structured logs, and cross-execution memory arrives with BLAKE3 hash chain integrity.

Wardex v2.2: Configuration Provenance Link (CPL), Chained Audit Log Verification, and Divergence Webhooks

SHA-256 and BLAKE3 config hashing, chained audit log verification, divergence detection via webhooks, and forensically verifiable release gate decisions.

Wardex v2.1: Containerization, CI/CD Integration, and Multi-Framework Expansion

Docker images, GitHub Action, NIST CSF catalog, and HTML reports — what changed and why, grounded in architectural decisions rather than market claims.

Wardex v2.0: CRA Article 14 Evidence, KEV Correlation, and Risk-Driven Release Gates

Turning vulnerability scanners into CRA-compliant audit evidence without changing how your team ships.