ci: add commit verification workflow and update job dependencies - #2992
Coelho-Gustavo wants to merge 1 commit into
Conversation
928ccad to
6e99c32
Compare
Signed-off-by: CoelDev <gustavocoelhosantos@gmail.com>
6e99c32 to
86b2010
Compare
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: NVIDIA/gpu-operator/.coderabbit.yaml Review profile: QUIET Plan: Enterprise Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review. 📝 WalkthroughWalkthroughThe CI workflow adds a reusable commit-verification job. The job retrieves signature-verification metadata for the triggering commit and fails if retrieval fails or the commit is not verified. Other CI jobs now depend on this job while retaining their existing dependencies. Priority: ➖ Normal Merge Risk: ⚪ Minimal · up to The change blocks CI when commit verification fails while preserving existing job prerequisites. No merge-blocking issue was identified.
Comment |
| commit-verification: | ||
| permissions: | ||
| contents: read | ||
| uses: ./.github/workflows/commit-verification.yaml |
There was a problem hiding this comment.
🔍 Standalone runs remain outside the gate
workflow_dispatch runs of golang-checks, config-checks, and e2e-tests bypass this dependency graph. Clarify whether “blocks everything else” applies only to CI-triggered runs.
Was this helpful? React with 👍 or 👎 to provide feedback.
| - name: Verify triggering commit signature | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| COMMIT_SHA: ${{ github.sha }} |
There was a problem hiding this comment.
|
Thanks @Coelho-Gustavo for the contribution. We'll review it soon. |
|
This PR can be reviewed and merged once #2997 is fixed as there is a dependency on that change first. |
Description
Fixes #2990
PRs can pass DCO while containing unsigned or unverified commits — DCO sign-off does not verify commit signatures — so unverified code can run the whole pipeline (builds, image pushes, e2e) before anyone notices. This checks GitHub's signature-verification metadata for the triggering commit (
github.sha) first and blocks everything else until it passes.Changes
.github/workflows/commit-verification.yamlreusable workflow (workflow_call,contents: read) — fails if the commit isn'tverified, reports the SHA and verificationreason, and fails if the metadata can't be retrieved.github/workflows/ci.yaml— newcommit-verificationjob runs first, added toneedsof all other jobs (existing dependencies preserved)Tests
No Go code touched, so no unit tests — verified the workflow logic read-only with
gh2.101.0 against the live API, running the exactgh apicommand from the step.Unsigned commit (local HEAD
36100733) fails as expected:Verified commit (origin
main, GitHub PGP signature) passes:Unretrievable metadata (nonexistent SHA) fails closed: