A preview build is only trustworthy if it was produced from the commit under review and
validated by the run that tested that commit. Without that link, a deploy can ship
something CI never checked.
The deploy path should run after CI rather than alongside it, download the triggering run's
evidence, and fail closed unless the evidence matches the exact commit being deployed.
No evidence means no deploy.
Pairs with the per-commit build stamping in #676 and #681: the stamp proves what a reviewer
installed, and this proves CI validated it.
Steps
Done when
A deploy cannot happen for a commit CI did not validate, and the failure is loud.
A preview build is only trustworthy if it was produced from the commit under review and
validated by the run that tested that commit. Without that link, a deploy can ship
something CI never checked.
The deploy path should run after CI rather than alongside it, download the triggering run's
evidence, and fail closed unless the evidence matches the exact commit being deployed.
No evidence means no deploy.
Pairs with the per-commit build stamping in #676 and #681: the stamp proves what a reviewer
installed, and this proves CI validated it.
Steps
Done when
A deploy cannot happen for a commit CI did not validate, and the failure is loud.