fix(ci): sign the commits this workflow creates - #323
Open
Piccirello wants to merge 2 commits into
Open
Conversation
Commits created with plain git are unsigned and are rejected by the org-wide signed-commits ruleset. Route them through the GitHub API so GitHub signs them with its own key.
🧙 Wizard CIRun the Wizard CI and test your changes against wizard-workbench example apps by replying with a GitHub comment using one of the following commands: Test all apps:
Test all apps in a directory:
Test an individual app:
Show more apps
Results will be posted here when complete. |
Both clones embed the App token in their remote URL and now sit in the workspace rather than a mktemp dir, so remove them once the mirrors are committed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Makes the workflow that commits in this repo produce signed commits.
Commits created with plain
gitare unsigned. PostHog is rolling the org-wide "Require signed commits" ruleset out to every repo, and this workflow would be rejected withGH013once it applies here. Routing the commit through the GitHub API instead means GitHub signs it with its own key, so it lands verified.Found while inventorying which workflows across the org still create unsigned commits.
planetscale/ghcommit-actionis the pattern already in use inposthog-js,posthog-roblox,brand,chartsand the SDK release fleet.Changes
The two mirror pushes (
PostHog/skills,PostHog/ai-plugin) now commit through the API.Testing
Not run end to end. The working clones moved from
mktemp -dinto$GITHUB_WORKSPACE/.skills-pushand.ai-plugin-push, becauseghcommit-actionresolves itsrepositoryinput relative to the workspace. Both target repos already enforce signing, so these pushes were failing before this change.Review follow-up (pushed)
if: always()step. They embed the App token in.git/config, and moving them frommktemp -dinto$GITHUB_WORKSPACEmeant the token stayed readable by every later step in the job.Known limitation worth a decision before merge
The API commit path cannot set an executable bit. GraphQL
FileAdditionaccepts onlypathandcontents(verified by schema introspection), so a newly mirrored executable file lands as100644. Whether an existing100755file keeps its mode when its contents change is undocumented and I could not confirm it — no PostHog repo currently has an executable file that aghcommitworkflow has ever written.Blast radius today is two files under the tree this workflow mirrors into
PostHog/skills:skills/posthog/all/hooks/skill-reminder.shskills/team/customer-success/impersonation-toolkit/scripts/impersonate-audit.shBoth are currently
100755, and both were last written by the old plain-gitmirror. If either loses its exec bit, the hook silently stops running. Worth checking the mode on the first real mirror run after this merges.