← CI/CD: build, validate, and deliver
03 / 6 · 40 MIN

Artifacts and evidence

Retain the evaluated output and distinguish persistence from cache optimization.

Concept and mechanism

An artifact retains execution outputs: a binary, package, report, or another result that needs to reach a consumer. A cache accelerates dependency reconstruction and should be able to disappear without making the process impossible. Do not use a mutable cache as the identity of an approved package. Connect output to its producer, revision, and content and confirm that the next job obtains the intended version. In GitLab, declaring dependencies or needs:artifacts changes which artifacts are downloaded; a missing file may result from that filtering. Check paths, upload conditions, retention, and access before attributing the issue to compilation. Producer success does not establish that the consumer received every file.

Guided application

In a fictional scenario, the recovery package exists only in a workflow scheduled for deletion. Define appropriate retention or publish the approved output in a release repository with suitable controls. In GitHub, deleting a run removes its associated artifacts. In Jenkins, stash normally serves files used within the same run rather than a general archive across jobs and runs. An attestation may connect an artifact to its provenance, but it must be verified and compared with expected-origin policy. A signature does not establish absence of vulnerabilities or functional correctness. Keep questions about identity, origin, test results, and promotion authorization separate. They all contribute to confidence without being equivalent.

IN PRACTICE

A valid signature from an unexpected build does not satisfy approved-origin policy.

Common pitfalls

Cache as approved package; success as available file; stash as archive; signature as quality.

Related topics: Integration and delivery · Jobs and dependencies · Tests and decisions

Take this idea with you

Preserve the correct artifact and verify the right evidence for each decision.

Create account

Reference: Durable run outputs versus performance caches · CI/CD practices 2026-09; scoped GitHub Actions GitLab Jenkins and Azure DevOps Services documentation