Skip to content

ci(signed-commits): check that GitHub verifies every pull request commit - #67

Merged
AdeGneus merged 1 commit into
mainfrom
ci/signed-commits-check
Oct 1, 2026
Merged

AdeGneus merged 1 commit into
mainfrom
ci/signed-commits-check

Conversation

@AdeGneus

@AdeGneus AdeGneus commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Adds a Signed commits check on pull requests. scripts/check_signed_commits.py lists the pull request's commits through the API and fails unless GitHub reports verification.verified == true for every one, printing each offending sha with GitHub's reason and a link to the signing docs. It fails closed on an API error, an empty or truncated list, a head that moved since the event, and more than the 250 commits the endpoint can list. The workflow runs the script's own tests (a fake gh on PATH driving the command line) before the real check.

GitHub's docs say branch protection already evaluates the head branch's commits at merge time; this makes the result a named status on every push that can be required. Dependabot and web-UI commits pass: GitHub signs web-UI commits ("Commits signed by GitHub will have a verified status"), and Dependabot commits across the org list as verified: true, reason: valid.

What's left: add Signed commits as a required status check after merge; this PR changes no protection. As with any pull_request check, a pull request can edit this workflow or script and neuter its own run; review of .github/ and scripts/ is the backstop.

Type of change

CI only; no listed type applies.

Required checklist

  • pytest -q passes
  • ruff check . and ruff format --check . pass
  • Pre-commit passes for changed files
  • Every new .py file has the Apache-2.0 license header
  • SDK contract and security items: not applicable

Related issue

None.

Testing notes

python3 scripts/test_check_signed_commits.py
python3 scripts/check_signed_commits.py --repo ori-platform/ori-sdk-python --pr <n> --head-sha <head sha>
python scripts/check_workflows.py && pytest -q

The check failed on an unsigned commit pushed to ori-platform/ori-canonicaljson#3 and passed once it was removed.

Adds a Signed commits check that lists the pull request's commits through
the API and fails unless each one has a verified signature, naming every
offender with GitHub's reason. It fails closed when the list cannot be read
in full: an API error, an empty or truncated list, a head that moved, or more
than the 250 commits the endpoint returns.
@AdeGneus AdeGneus self-assigned this Oct 1, 2026
@AdeGneus
AdeGneus merged commit 874405a into main Oct 1, 2026
7 checks passed
@AdeGneus
AdeGneus deleted the ci/signed-commits-check branch October 1, 2026 15:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant