Repository navigation
Add advisory PR commit signature verification - #12703
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #12703 +/- ##
==========================================
- Coverage 59.82% 59.82% -0.01%
==========================================
Files 779 779
Lines 46058 46058
==========================================
- Hits 27555 27552 -3
- Misses 18503 18506 +3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Adds advisory commit-signature verification for pull requests and documents cryptographic signing as a contributor requirement.
Changes:
- Adds signature detection and sticky PR guidance.
- Supports automatic and manual verification.
- Updates contributor signing documentation.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
.github/workflows/verify-commit-signatures.yml |
Runs verification and posts guidance. |
.github/scripts/verify-commit-signatures.sh |
Finds unverified commits through GitHub GraphQL. |
CONTRIBUTING.md |
Adds the signing requirement. |
docs/contributing/contributing-pull-requests/README.md |
Documents signature-check behavior. |
docs/contributing/contributing-code/contributing-code-first-commit/first-commit-06-creating-a-pr/index.md |
Marks commit signing as required. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2 Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
This reverts commit ca94950. Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Radius functional test overviewClick here to see the test run details
Test Status⌛ Building Radius and pushing container images for functional tests... |
Summary
Add an advisory pull request workflow that checks every commit for a GitHub Verified cryptographic signature. A pinned
actions/github-scriptstep loads the trusted.github/scripts/verify-commit-signatures.mjsmodule, which paginates the commits, reports the result, and creates or updates a polite guidance comment that remains after all commits are verified. Maintainers can also run the workflow manually by providing a pull request number.Reason for change
New contributors are asked to use cryptographically signed commits, so we want to give an early indication that it is required via a comment on the PR. Automating that reminder makes the cryptographic signing requirement visible after each push while keeping it separate from the existing DCO
Signed-off-byrequirement.The workflow remains non-blocking for unsigned commits. API or workflow failures still fail the job so broken verification remains visible.
Example message
Thank you for contributing to Radius.
The following commits do not currently show a GitHub Verified signature:
19c7a592a80f28Please follow our commit-signing guide to configure GPG, SSH, or S/MIME signing. Then re-sign the affected commits and force-push the rewritten branch with
--force-with-lease.Cryptographic commit signing is separate from the DCO
Signed-off-byline; both are required.