Wardex v2.4.1: Code Health Audit Wrap-Up and Sealed Release
Three audit phases — security, tests, refactor — land in a maintenance release, anchored via the 3CP provenance flow.
Writing
Three audit phases — security, tests, refactor — land in a maintenance release, anchored via the 3CP provenance flow.
The EU AI Act (Regulation 2024/1689) arrives as a 31-control framework, and releases gain cryptographic provenance via Gleipnir anchoring.
CBOR deterministic encoding replaces ad-hoc serialization; CDDL schemas define the envelopes; and tool provenance becomes a cryptographically-bound attestation.
The Cordyceps vulnerability class didn't affect Wardex — but the investigation exposed three gaps that did.
Completing the CRA-ready auditability layer — silent failures become structured logs, and cross-execution memory arrives with BLAKE3 hash chain integrity.
SHA-256 and BLAKE3 config hashing, chained audit log verification, divergence detection via webhooks, and forensically verifiable release gate decisions.
Docker images, GitHub Action, NIST CSF catalog, and HTML reports — what changed and why, grounded in architectural decisions rather than market claims.
Turning vulnerability scanners into CRA-compliant audit evidence without changing how your team ships.