The cherry-pick workflow currently creates backport commits locally and pushes them without signing. Recent automated backports report verified: false with reason unsigned, even when the original commits were signed.
This is incompatible with CI signature verification proposed in #2992 and branch protection requiring signed commits.
Update .github/scripts/backport.js to produce verified backport commits. Follow the approach implemented in nvidia-container-toolkit PR #2012:
- Recreate each cherry-picked commit through GitHub’s Git Data API, preserving its tree, message, and commit order.
- Update the backport branch to reference the resulting signed commit chain.
- Preserve existing PR creation and conflict-handling behavior.
This approach avoids managing a separate GPG or SSH signing key for the bot.
Acceptance criteria:
- GitHub reports verified: true for every generated backport commit.
- Backports preserve the expected changes and commit messages.
- Backport CI passes the signature-verification gate when enabled.
- Both clean backports and backports requiring manual conflict resolution remain supported.
The cherry-pick workflow currently creates backport commits locally and pushes them without signing. Recent automated backports report verified: false with reason unsigned, even when the original commits were signed.
This is incompatible with CI signature verification proposed in #2992 and branch protection requiring signed commits.
Update .github/scripts/backport.js to produce verified backport commits. Follow the approach implemented in nvidia-container-toolkit PR #2012:
This approach avoids managing a separate GPG or SSH signing key for the bot.
Acceptance criteria: