Changes touching this path

  • deploy releases build and publish off GitHub: a private R2 bucket and a signed manifest (#899, ADR 0049) 234ac037 · dbf3dbe6…
  • release: bump loot-cli and loot-forge to v0.4.4 for the 0006 migrate and the gc-tmp and auth-preamble redeploys (#895) 324e05c8 · dbf3dbe6…diff
  • the public installer artifacts stop waiting on GitHub's meter: ADR 0049's mac premise expired, so the six-triple story moves to a staged multi-machine publish and win-arm64 is left open on evidence (#1021) 8087ce6b · dbf3dbe6…diff
  • the staging-bucket question closes as decided: ADR 0049 records private staging on the deploy bucket, and the runbook demands both credentials for a Mac build (#1021) 8ead5704 · dbf3dbe6…diff
  • the public bucket stops shipping a private repo's source: dist's source-tarball default goes off at the root, the publish path stops naming the archive, and ADR 0060 makes the published set an allowlist so the next asset cannot arrive by default (#1054) fb358f42 · dbf3dbe6…diff
  • the one-place path spellings become reachable and reach: tree_path goes pub(crate) and covers the five walk-derived surfaces that could not call it, lane merge stops being the face #1049 missed, and two doc claims shrink to what is true (#1063) 94908511 · dbf3dbe6…diff
  • ADR 0049 live amendment says five triples and stops naming the source tarball its own ticket retracted (#1156) beaebb29 · dbf3dbe6…diff
  • ADR 0099 records the move of loot from millerbyte.com to loot.build (map #2412): the site and one-liner at the apex with www redirecting, artifacts at dl.loot.build, the forge at forge.loot.build, security@loot.build through Cloudflare Email Routing with no catch-all, the relay not recreated, and the production Clerk instance on loot.build; and a hard cutover, the operator decision, in which the new names serve beside the old, a release carries them, every clone re-points its forge remote, and the old names are removed with no alias or redirect kept. it states what that breaks for anything made before it, read from the code: an opted-in old binary POSTs telemetry to the old name silently, so the old names must end NXDOMAIN rather than answered by the millerbyte.com wildcard, which would hand those reports to Vercel; old --help links; installers and manifests pinned to dl.millerbyte.com; the crates.io placeholders published with the old homepage, which only a new publish by the operator fixes; and it records the measured costs of the move (a 19.2 s first unlock on the new origin, no forge change because a signed request does not bind the host). ADRs 0037, 0041, 0045, 0049, 0061, 0064, 0066, 0067, 0074 and 0097, whose decisions name a loot host, each gain an amendment pointing here, and a banner where they had none; their bodies keep the names they were written with (#2414) bf2242c5 · dbf3dbe6…diff

Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.