Docs: record native build provenance - #11
Merged
Merged
Conversation
why: Native docs need the same source and artifact verification as shared builds before the publisher receives AWS credentials. what: - Keep source, native exporter and shared docs checkouts separate. - Record clean input revisions before generation and upload an exact artifact descriptor for the reviewed shared publisher. - Disable executable caches for selected source builds and cover the snapshot, descriptor and paired workflow pins in focused regressions.
tony
marked this pull request as ready for review
September 30, 2026 00:23
tony
added a commit
that referenced
this pull request
Sep 30, 2026
what: - Record source, native exporter, and shared docs revisions - Describe the exact uploaded artifact before publication - Build from sibling checkouts without executable caches why: The publisher needs to verify that native Lua documentation came from the selected clean source and reviewed build tools before it requests credentials or uploads to the site.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The native docs build now records the selected source, native exporter and shared docs revisions before generation. The uploaded content has an exact artifact descriptor, which the shared publisher verifies before requesting AWS credentials.
The three checkouts are siblings, and selected-source builds restore no executable caches. Existing source-ref selection, release aliases, fork build-only behavior and PR preview cleanup remain unchanged. Both shared docs pins use
42dd5b71e6eefd785b9bf8ce11d34e8f1a058a22.Validation:
PROGRAMFILES(X86)variable.The hosted native build and preview publication passed. Ordinary public GETs returned the guide and build record with bytes matching the uploaded artifact. The build record identifies clean source, native exporter and shared docs revisions. PR previews do not write a release manifest receipt; production publication remains to be verified after merge.