The database CI reads, pinned by SHA-256 in src/quantpulse/demo_data.py.
Separate from the rolling demo-data asset on purpose. CI used to fetch the rolling
one, so a bad nightly refresh failed unrelated code pull requests with a message that
pointed at the Streamlit Settings page rather than at the database -- which is exactly
what happened on 2026-09-15.
This copy changes only when someone deliberately rolls it forward and commits the new
digest. The rolling asset stays the thing the public demo and ./run.sh read, and the
current data is still exercised by the publish workflow's static-site gate.