v1.9.1 — CI stamping now attests its driver, so the forward-only rule can fire
Fixed
defprod-stampnow sendsdriver: cicdon every commit-attributed stage report. The backend's forward-only rule for pipeline reporting turns ondriver === cicd, and this script never sent the field at all — so the rule was unreachable from CI and shipped inert in v1.9.0. A re-swept commit could still rewind a change mid-review, which is the exact failure that rule was written to stop.
Why it is attested here rather than inferred
The backend cannot fill it in. An agent driving under a person's API key authenticates as that person, so the credential cannot distinguish automated pipeline reporting from a human action. And the value is never in doubt for this script: it derives the change and the stage from a git range on a build box, so every report it makes is automated pipeline reporting by construction.
Compatibility
Behaviour-preserving for the change records you already have. The field rides alongside commitSha on --start and finish only; --cancel and --fail carry no provenance and are unchanged. driver is first-report-wins per stage, so a stage already carrying one is not overwritten.
Pairs with a backend change that logs a warning whenever a commitSha-bearing report names no driver — so this can never again be silently inert for a consumer still pinned to an older version.
Upgrade
```
npx @defprod/scripts defprod-stamp --help
```
npx resolves unpinned by default, so an unpinned caller picks this up on its next invocation. Pinned consumers should move to `1.9.1`.
Full Changelog: v1.9.0...v1.9.1