SIG Release rewrote the image promoter core. It cut 20% of the code. It added a pipeline engine, cosign signing, and SLSA attestations. Signing now sits separate from signature replication. Registry reads run in parallel - plan time dropped ~20m → ~2m. Per-request timeouts, retries, and HTTP connection reuse were added. Provenance is enabled by default.









