12 September 2026 · remediation

Highest-impact technical gaps fixed

The source changes close the deterministic failures found in the fresh joint review. Hosted evidence remains necessary before the projected scores become release scores.

Projected: TrustWeave 9.2 · SaaS 8.7

TrustWeave CI evidence paths

Fixed and pushed. CI and release workflows now read evidence from each Gradle module's real build/reports directory. The Verifiable Intent test task declares the complete reports directory as a cache output, so tokens, metrics, operations and recovery evidence survive cache hits. A regression test checks both workflows and rejects the obsolete paths.

Accountly load qualification

Fixed. Every configured operation is exercised once before deadline-driven load begins. Empty operation sets and non-positive execution limits are rejected. The script suite now passes 22 tests.

Accountly webhook delivery identity

Fixed. Provider event IDs, including the event_id alias, now drive bounded deduplication keys. Identical state transitions from distinct deliveries no longer collapse; legacy payloads retain raw-payload redelivery protection. All four focused controller tests pass.

SDK source pairing

Fixed in the working tree. Accountly now pins TrustWeave abc5b6dcf3a06523208c65d88e32a974111445eb with the clean-checkout fingerprint ab5aa5cc94a2a90bb700363a22867109f70899d5311182ac9f5188eabdb44e92.

Evidence still needed

Local TrustWeave Python/documentation checks passed. The focused Accountly webhook tests passed; its filtered run correctly failed the repository-wide coverage threshold because only one test class was selected.