
PRs are too slow for agentic dev, but we still need a way to control which commits get CI credentials. Today’s loop is awful: push, wait for review, poll, fix, push again. I think review + CI should produce signed attestations attached directly to commits, so trust can be established before push and CI doesn’t have to wait for a post-push approval loop. Exploring this in github.com/buildkite/git-…. Anyone interested?












