Rolling build (master 4a5802b98c750b0b9159ae4f4ab4e6a702b57f9b)
Pre-releaseRolling continuous build from master 4a5802b98c750b0b9159ae4f4ab4e6a702b57f9b.
Published only after tests, security, and the platform
build matrix were green for this exact commit.
Every artifact carries a GitHub build-provenance attestation:
gh attestation verify <downloaded-file> --repo coherence-energy-labs/one-link
Read that attestation precisely. It proves the file was emitted
by this repository's publish_rolling.yml on a GitHub-hosted
runner, so a third party cannot substitute their own upload. Its
sourceRepositoryDigest is the commit the PUBLISHER ran from,
which is not necessarily the commit the binary was COMPILED from
(4a5802b98c750b0b9159ae4f4ab4e6a702b57f9b, named in the title above). It is not a reproducible
build claim: it does not let you rebuild these bytes and compare.
This is not a signed, reproducible release. That pipeline is
release.yml, fires only on v* tags, and remains the only
channel intended for production trust. SHA-256 for every artifact
is in manifest.txt and the per-file .sha256 sidecars.