The previous key was pasted into unom/punktfunk's secret store rather than
this one. Gitea secrets don't cross repos and can't be read back, so that
key was unusable here and is abandoned; INDEX_SIGNING_KEY on THIS repo now
holds the private half of the key pinned below.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The bootstrap key generated during implementation was lost with its scratch
directory. Nothing shipped pinning it, so this is a straight replacement of
slot 0 rather than a rotation — the second slot stays reserved for a real one.
The private half now lives only in the INDEX_SIGNING_KEY secret, so CI is the
only thing that can sign. This push is what makes it do so: the committed
signature is still the old key's, and the verify self-check will fail loudly
if the secret does not match the public key pinned here.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed locally with the key whose public half the host pins. ed25519 is
deterministic, so the publish workflow re-signing this exact document with
the same key produces byte-identical output — this is the bootstrap for a
repo whose CI secret is not yet configured, not a parallel signing path.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>