Security and trust¶
Forge separates source-control authority from repository access used during deployment. The separation limits what each actor can do and what each proof can establish.
Authority table¶
| Capability | Authority |
|---|---|
| Ordinary Git operations | The operator's GitHub authority. |
| Repository access for deployment | Forge App authorization, requested only when deployment requires it. |
| Derived deployment context | Authorization and repository context. |
| Runtime behavior | The committed manifest and app source. |
Derived identity¶
Environment, tenant, account, installation, and app identity are not customer inputs. Forge derives them from authorization and repository context, and the CLI exposes no selector for them.
Source integrity¶
Forge deploys committed source. The default request uses the GitHub origin and committed HEAD. Automation may select only repository, ref, or commit.
Secret handling¶
Do not put credentials in the manifest, commit, proof packet, or support report. Redact secret-looking values before sharing logs.
Evidence boundary¶
A local proof establishes local behavior. A deployment result establishes the request outcome. Neither claim establishes hosted availability without accepted evidence.