automated-release · built

The pipeline says which commit produced these bytes, and hands over the checksums that name them.

Give ci a keypair generated per run and bound to the pipeline’s own workload identity — tik bridge workload --github binds it to the token the platform already issues — so nothing long-lived exists to leak and the binding is what makes the signatures checkable afterwards.

The stage is sticky: a published version is never rebuilt, so “this commit produced these bytes” is a fact about a moment that stays true.

see history · edit this page