A phase-by-phase history of Fendix development. v0.7.0 shipped May 1, 2026 — the wedge is now defensible. Phase 14 (External Wedge) closed end-to-end with the GitHub App business logic; Phase 15 (Open & Extensible) ratified the open-source posture (ADR-007), shipped the plugin system, and delivered reachability/dataflow correlation. The correlator now distinguishes “DAST + SAST agreed” from “DAST + SAST agreed AND we can prove the exploit path” — the latter gets a double severity escalation.
May 1, 2026
May 1, 2026
April 30, 2026
April 30, 2026
April 30, 2026
April 29, 2026
April 29, 2026
April 2026
April 2026
April 2026
April 2026
April 2026
March 2026
March 2026
March 2026
March 2026
February 2026
February 2026
v0.7.0 shipped May 1, 2026 — the wedge is defensible. Phase 14 closed with the GitHub App; Phase 15 shipped open-source ratification (ADR-007), the plugin system (out-of-tree extension via NDJSON IPC), and reachability correlation (taint chains lift agreed findings to a build-failing severity tier). Every artifact still carries cosign keyless sidecars verifiable against the build's GitHub Actions OIDC identity.