fix(ci): sign the commits this workflow creates - #92
Open
Piccirello wants to merge 1 commit into
Open
Conversation
Commits created with plain git are unsigned and are rejected by the org-wide signed-commits ruleset. Route them through the GitHub API so GitHub signs them with its own key.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Makes the workflow that commits in this repo produce signed commits.
Commits created with plain
gitare unsigned. PostHog is rolling the org-wide "Require signed commits" ruleset out to every repo, and this workflow would be rejected withGH013once it applies here. Routing the commit through the GitHub API instead means GitHub signs it with its own key, so it lands verified.Found while inventorying which workflows across the org still create unsigned commits.
planetscale/ghcommit-actionis the pattern already in use inposthog-js,posthog-roblox,brand,chartsand the SDK release fleet.Changes
Replaces
chart-releaser-action's built-in index push withinstall_onlyplus explicitcr upload/cr index, and commitsindex.yamltogh-pagesthrough the API.Testing
Not verified end to end, and this is the riskiest change in the set.
chart-releaser-actionhardcodescr index --push, so there is no input that turns the git write off; the only way to sign it is to drivecrdirectly.cr uploadonly talks to the releases API and needs no git write, so it is unchanged in substance. Worth a careful review from someone who knows this chart flow. Note the ruleset's ref condition is~ALL, so it coversgh-pagestoo.