Engineering evidence
GitHub Evidence Bridge
GitHub supplies useful public evidence—commits, trees, tags, releases, workflow results and artifacts—but ENTITY treats each as evidence with a specific scope, not as sovereign authority.
Useful evidence
- Protected merge commit and Git tree.
- Signed tag/GitHub Release.
- Release assets and digests.
- Workflow/check conclusions and logs.
- Pull-request review/change history.
Binding into ENTITY
Capture immutable identifiers/hashes and ingest them as evidence/provenance references. The v3.4.2 BTDU repository ingest supports a pinned git://owner/repo@commit provenance reference and records commit/tree/aggregate/root information.
Boundary
GitHub hosting does not become authority over ENTITY users. A GitHub workflow pass proves the workflow result in that environment; it does not automatically prove independent validation or external deployment fitness.