Generated deployment setup
Production-ready CI/CD, generated for your repository.
Turn your GitHub repository into a reviewed GitHub Actions pipeline. DeployLint inspects application roots and package managers, previews your CI/CD workflows, and opens a setup pull request for your review.
Connect once. Review exactly what ships.
Choose repository access in GitHub. DeployLint inspects the project, explains a safe pipeline plan, and shows every generated file before opening a setup pull request.
Get startedEvery generated change is previewed, reviewed, and re-validated in a setup pull request.
- 01
Connect
Choose the repositories DeployLint should inspect in GitHub.
- 02
Inspect
Read the stack, workflows, branch rules, environments, and security controls already in place.
- 03
Plan and preview
Choose understandable safeguards and inspect the exact workflow, settings, and secret checklist.
- 04
Open a setup PR
Open one isolated pull request for review. DeployLint never writes to the default branch or merges it.
- Repository data
- Read only
- Checks + deploys
- Write decisions
- Code + workflows
- Setup PR branch only
Three decisions. One proof trail.
- 01
Evaluate
Pin the repository policy, inspect the exact changed paths, and produce a deterministic gate decision.
- 02
Require independence
The author cannot approve their own change. A separate human identity must review the exact commit.
- 03
Verify before deploy
The deployment gate checks the signed receipt against the repository, commit, and policy digest. Missing proof means no deploy.
Portable evidence
An approval should survive the tool that captured it.
Every eligible approval becomes a DSSE-signed in-toto statement. The receipt is repository-scoped, commit-bound, policy-bound, and independently verifiable.
Open your workspace- repository
- PyRo1121/omg
- commit
- 196c0e93f0b6…
- policy
- f84059fbd76d…
- approver
- independent human
- signatures
- 2 / DSSE PAE covered
- ledger
- inclusion verified
AI can explain the rule. AI cannot approve itself.
AI may
Explain a decision, draft a policy change, and show the evidence a human should review.
AI may not
Authorize a deployment, rewrite policy silently, or turn an evaluation failure into permission.