{{define "title"}}Build provenance ยท MeshTender{{end}} {{define "header"}}
{{.VersionPath}} on the public site, so an outside auditor
can check a running server too.
go run ./cmd/meshtender).
{{end}}
mise run image prints. A binary can't
derive its own image digest, so this value is supplied by the deployment (MESHTENDER_IMAGE_DIGEST),
which CI sets from the digest it published.
{{else}}
Not reported.
Set when the deployment passes MESHTENDER_IMAGE_DIGEST; unset for a run from source.
{{end}}
/ko-app/meshtender from a locally built image and hash it.
{{else}}
Unavailable — the executable could not be read.
{{end}}
Run these from a clean checkout. Go stamps the commit, its time, and a dirty-tree flag into the binary, so the tree has to be exactly this commit with no local edits or the digest will differ.