fix: preserve Git verification keys and support macOS Bash - #871
Conversation
Retain enrolled YubiKey and configured 1Password verification keys across signing-mode changes. Keep new-commit signer selection unchanged. Use Bash 3.2-compatible startup directory matching and gate third-party Homebrew completions on Bash 4.4+. Add regression coverage and document both behaviors. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (9)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe change keeps enrolled YubiKey and configured 1Password public keys in ChangesSigning-Key Verification
Bash Startup Compatibility
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~15 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to No actionable issue remains in the supplied review evidence; the change is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Preserving older verification keys maintains access to signed history, but it also means switching signing methods no longer withdraws trust from those keys. The effect is limited to machines using this generated Git configuration; accepting a forged signature would still require control of a trusted signing key. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 4 files. (5 skipped: 5 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
A macOS dotfiles update exposed Bash 3.2 startup errors and proposed replacing existing YubiKey verification entries with the 1Password key. Switching signing backends should not discard trust in previously signed commits.
Changes
allowed_signers, regardless ofuseYubiKey. Selection of the signer for new commits and tags is unchanged.ykman's unsupportedcomplete -o nosortoption on macOS's built-in Bash. Homebrew environment setup and the dotfiles' own completion initializers remain enabled.Compatibility notes
YubiKey
.pubfiles must remain in~/.ssh/so chezmoi can regenerate their verification entries; the hardware does not need to be connected. This does not change installed files until the updated source is applied.Validation
/usr/bin/chmod, and a missingtimeoutcommand, among other environment-sensitive failures. Those broader issues are outside this PR.Summary by CodeRabbit
Bug Fixes
Documentation