Repository navigation
fix: reliable GitLab commit verification when the CLI runs through Dagger - #3550
Conversation
PR validation — ✅ 3 passing
AI Session Checks — 🟢 90% · ✅ 0 failing
|
| Status | Policy | Material | Messages |
|---|---|---|---|
| ✅ Passed | ai-config-ai-agents-allowed |
ai-coding-session-38d0eb |
- |
| ✅ Passed | ai-config-no-dangerous-commands |
ai-coding-session-38d0eb |
- |
| ✅ Passed | ai-config-no-secrets |
ai-coding-session-38d0eb |
- |
| ✅ Passed | ai-config-mcp-servers-allowed |
ai-coding-session-38d0eb |
- |
Security Checks — ✅ 6 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
✅ iac-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | iac-misconfiguration |
- |
Scans not applied (2)
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
Security context
This change touches code with 4 recorded security-fix advisories. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.
View in Chainloop ↗ · How this works ↗
Powered by Chainloop and Chainloop Trace
- Discover runners in a fixed order with the Dagger runner first. The Chainloop Dagger module passes the parent GitLab CI context to the CLI container, so the Dagger and GitLab runners both matched and map iteration picked one at random. When the GitLab runner won, attestation init failed on missing GitLab variables. - Send GITLAB_TOKEN (read_api scope) as PRIVATE-TOKEN. The GitLab commit signature API does not accept job tokens. - Only a "404 Signature Not Found" response marks the commit as unsigned. "Project Not Found" and "Commit Not Found" now give an unavailable status with the GitLab message. - Report verified_system signatures (made by GitLab) as verified. - Take signature.algorithm from the commit signature when the platform does not report it. - Log the reason of an unavailable verification as a warning. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
Add --gitlab-token, passed to the CLI as GITLAB_TOKEN, to verify commits of private and internal projects, and --gitlab-ca to trust the CA of a self-managed Gitlab server through SSL_CERT_DIR. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
The CLI image is scratch-based and had no /tmp, so collectors that write temporary files, such as the PR/MR metadata collector, failed. Assisted-by: Claude Code Signed-off-by: Javier Rodriguez <javier@chainloop.dev> Chainloop-Trace-Sessions: 38d0eb57-8573-4185-8a52-f49f140d0ea8
080da79 to
260c3ad
Compare
Summary
Makes GitLab commit author verification work when the CLI runs through the Chainloop Dagger module on a self-managed GitLab server.
attestation initfailed on missing GitLab variables.GITLAB_TOKEN(read_apiscope) asPRIVATE-TOKEN. The GitLab commit signature API does not accept job tokens, so commits of private and internal projects could not be verified.404 Signature Not Foundresponse marks a commit as unsigned.404 Project Not Foundand404 Commit Not Foundnow give anunavailablestatus with the GitLab message, instead of "Commit is not signed".verified_systemstatus, which GitLab creates for web UI and merge commits, are reported asverified.signature.algorithmannotation of the git head subject falls back to the type of the commit signature when the platform does not report it.unavailableverification is logged as a warning.initaccepts--gitlab-token, and--gitlab-cafor self-managed GitLab servers that use a certificate from a private CA./tmp, which the PR/MR metadata collector needs.Refs PFM-7635
AI disclosure
This change was developed with assistance from Claude Code.