Changes touching this path

  • loot-forge: a runtime Dockerfile that COPYs the released binary (#613) 79336fa3 · dbf3dbe6…
  • loot-forge drains on SIGTERM and SIGINT instead of waiting out SIGKILL (#657) 0485a488 · dbf3dbe6…diff
  • the repo never goes public, so the anonymous download path moves to R2 (#652) #652 recorded a gate: flipping this repo public discloses sealed docs/pitch/zk-host.md through PR #161 surviving refs/pull/161/head, verified live 2026-07-30. Re-swept today across 321 PR head refs (up from 242), two ways -- still exactly one carrier, unchanged. But the gate own remedy needs GitHub Support, is not self-service, and has no date. ADR 0045 stops waiting. The repo stays private permanently, and the anonymous artifact path moves to Cloudflare R2 at dl.millerbyte.com instead. Attestations are out rather than deferred; sha256 is the integrity story by decision. Build: #806 DNS zone move, #807 R2 artifacts, #808 installer retarget and the smoke test back on, #809 the Install page attestation claim. ADR 0037 is superseded in two places and docs/specs/loot-site.md in three, marked in place with dated blocks. The comments that called #652 a temporary gate now say permanent, and CONTEXT.md no longer calls the GitHub mirror public. 9a04ab6f · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.