diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index fce4ee235e..bf2222c75b 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -29,12 +29,19 @@ concurrency: permissions: {} jobs: + commit-verification: + permissions: + contents: read + uses: ./.github/workflows/commit-verification.yaml + variables: + needs: [commit-verification] permissions: contents: read uses: ./.github/workflows/variables.yaml code-scanning: + needs: [commit-verification] permissions: contents: read security-events: write @@ -42,31 +49,34 @@ jobs: uses: ./.github/workflows/code-scanning.yaml config-checks: + needs: [commit-verification] permissions: contents: read uses: ./.github/workflows/config-checks.yaml golang-checks: + needs: [commit-verification] permissions: contents: read id-token: write uses: ./.github/workflows/golang-checks.yaml third-party-notices: + needs: [commit-verification] permissions: contents: read id-token: write uses: ./.github/workflows/third-party-notices-check.yaml coverage: - needs: [golang-checks] + needs: [commit-verification, golang-checks] permissions: contents: read id-token: write uses: ./.github/workflows/coverage.yaml image-builds: - needs: [variables, config-checks, golang-checks] + needs: [commit-verification, variables, config-checks, golang-checks] permissions: contents: read id-token: write @@ -79,7 +89,7 @@ jobs: operator_image_base: ${{ needs.variables.outputs.operator_image_base }} e2e-tests: - needs: [variables, image-builds] + needs: [commit-verification, variables, image-builds] permissions: contents: read id-token: write @@ -95,7 +105,7 @@ jobs: release: if: github.event_name == 'push' && github.ref == 'refs/heads/main' - needs: [variables, e2e-tests] + needs: [commit-verification, variables, e2e-tests] permissions: contents: read packages: write diff --git a/.github/workflows/commit-verification.yaml b/.github/workflows/commit-verification.yaml new file mode 100644 index 0000000000..6a0eba28da --- /dev/null +++ b/.github/workflows/commit-verification.yaml @@ -0,0 +1,55 @@ +# Copyright NVIDIA CORPORATION +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +name: Commit Verification + +on: + workflow_call: {} + +permissions: + contents: read + +jobs: + commit-verification: + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: Verify triggering commit signature + env: + GH_TOKEN: ${{ github.token }} + COMMIT_SHA: ${{ github.sha }} + REPOSITORY: ${{ github.repository }} + run: | + echo "Checking signature verification for commit ${COMMIT_SHA}..." + + if ! VERIFICATION_JSON="$(gh api "repos/${REPOSITORY}/commits/${COMMIT_SHA}" --jq '.commit.verification')"; then + echo "::error::Could not retrieve verification metadata for commit ${COMMIT_SHA}." + exit 1 + fi + + echo "Verification metadata: ${VERIFICATION_JSON}" + + VERIFIED="$(echo "${VERIFICATION_JSON}" | jq -r '.verified')" + REASON="$(echo "${VERIFICATION_JSON}" | jq -r '.reason')" + + echo "Commit SHA: ${COMMIT_SHA}" + echo "Verified: ${VERIFIED}" + echo "Reason: ${REASON}" + + if [ "${VERIFIED}" != "true" ]; then + echo "::error::Commit ${COMMIT_SHA} is not verified (reason: ${REASON})." + exit 1 + fi + + echo "::notice::Commit ${COMMIT_SHA} signature verified (reason: ${REASON})." \ No newline at end of file