Skip to content

ci: add commit verification workflow and update job dependencies - #2992

Open
Coelho-Gustavo wants to merge 1 commit into
NVIDIA:mainfrom
Coelho-Gustavo:issue-2990-commit-verification
Open

Coelho-Gustavo wants to merge 1 commit into
NVIDIA:mainfrom
Coelho-Gustavo:issue-2990-commit-verification

Conversation

@Coelho-Gustavo

Copy link
Copy Markdown

Description

Fixes #2990

PRs can pass DCO while containing unsigned or unverified commits — DCO sign-off does not verify commit signatures — so unverified code can run the whole pipeline (builds, image pushes, e2e) before anyone notices. This checks GitHub's signature-verification metadata for the triggering commit (github.sha) first and blocks everything else until it passes.

Changes

  • New .github/workflows/commit-verification.yaml reusable workflow (workflow_call, contents: read) — fails if the commit isn't verified, reports the SHA and verification reason, and fails if the metadata can't be retrieved
  • Updated .github/workflows/ci.yaml — new commit-verification job runs first, added to needs of all other jobs (existing dependencies preserved)

Tests

No Go code touched, so no unit tests — verified the workflow logic read-only with gh 2.101.0 against the live API, running the exact gh api command from the step.

Unsigned commit (local HEAD 36100733) fails as expected:

{"verified":false,"reason":"unsigned","signature":null,...}
Commit SHA: 36100733af792370de3b62b10611df2c02c9fad3
Verified: false
Reason: unsigned
::error::Commit 36100733... is not verified (reason: unsigned).

Verified commit (origin main, GitHub PGP signature) passes:

Verified: true
Reason: valid
::notice::Commit main signature verified (reason: valid).

Unretrievable metadata (nonexistent SHA) fails closed:

gh: No commit found for SHA: 0000... (HTTP 422)
::error::Could not retrieve verification metadata for commit 0000....

@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@Coelho-Gustavo
Coelho-Gustavo force-pushed the issue-2990-commit-verification branch 2 times, most recently from 928ccad to 6e99c32 Compare October 1, 2026 01:44
Signed-off-by: CoelDev <gustavocoelhosantos@gmail.com>
@Coelho-Gustavo
Coelho-Gustavo force-pushed the issue-2990-commit-verification branch from 6e99c32 to 86b2010 Compare October 1, 2026 01:52
@Coelho-Gustavo
Coelho-Gustavo marked this pull request as ready for review October 1, 2026 01:55
@Coelho-Gustavo
Coelho-Gustavo requested a review from a team as a code owner October 1, 2026 01:55
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: NVIDIA/gpu-operator/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 2613c96d-6b08-4893-8dbe-4e51a2bfb3d6

📥 Commits

Reviewing files that changed from the base of the PR and between 75210df and 86b2010.

📒 Files selected for processing (2)
  • .github/workflows/ci.yaml
  • .github/workflows/commit-verification.yaml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The CI workflow adds a reusable commit-verification job. The job retrieves signature-verification metadata for the triggering commit and fails if retrieval fails or the commit is not verified. Other CI jobs now depend on this job while retaining their existing dependencies.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 86b20

The change blocks CI when commit verification fails while preserving existing job prerequisites. No merge-blocking issue was identified.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 potential issues.

Devin Review

Comment thread .github/workflows/ci.yaml
Comment on lines +32 to +35
commit-verification:
permissions:
contents: read
uses: ./.github/workflows/commit-verification.yaml

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Standalone runs remain outside the gate

workflow_dispatch runs of golang-checks, config-checks, and e2e-tests bypass this dependency graph. Clarify whether “blocks everything else” applies only to CI-triggered runs.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

- name: Verify triggering commit signature
env:
GH_TOKEN: ${{ github.token }}
COMMIT_SHA: ${{ github.sha }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟥 Unsigned earlier commits pass verification

When a push contains an unsigned commit followed by a verified one, COMMIT_SHA checks only the final commit. The pipeline then builds and publishes code from the unsigned commit.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@rahulait

rahulait commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Thanks @Coelho-Gustavo for the contribution. We'll review it soon.

@rahulait

rahulait commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR can be reviewed and merged once #2997 is fixed as there is a dependency on that change first.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Verify the triggering commit before running other CI jobs

2 participants