Skip to content

Add advisory PR commit signature verification - #12703

Merged
brooke-hamilton merged 19 commits into
mainfrom
brooke-hamilton-commit-signoff-check
Sep 11, 2026
Merged

brooke-hamilton merged 19 commits into
mainfrom
brooke-hamilton-commit-signoff-check

Conversation

@brooke-hamilton

@brooke-hamilton brooke-hamilton commented Aug 18, 2026 •

Copy link
Copy Markdown
Member

Summary

Add an advisory pull request workflow that checks every commit for a GitHub Verified cryptographic signature. A pinned actions/github-script step loads the trusted .github/scripts/verify-commit-signatures.mjs module, which paginates the commits, reports the result, and creates or updates a polite guidance comment that remains after all commits are verified. Maintainers can also run the workflow manually by providing a pull request number.

Reason for change

New contributors are asked to use cryptographically signed commits, so we want to give an early indication that it is required via a comment on the PR. Automating that reminder makes the cryptographic signing requirement visible after each push while keeping it separate from the existing DCO Signed-off-by requirement.

The workflow remains non-blocking for unsigned commits. API or workflow failures still fail the job so broken verification remains visible.

NOTE: When a user updates their commits to add signing and force pushes to the PR branch, the advisory message will not be deleted from the PR. This is by design so that PR authors can quote-reply the message to give status.

Example message

Thank you for contributing to Radius.

The following commits do not currently show a GitHub Verified signature:

Please follow our commit-signing guide to configure GPG, SSH, or S/MIME signing. Then re-sign the affected commits and force-push the rewritten branch with --force-with-lease.

Cryptographic commit signing is separate from the DCO Signed-off-by line; both are required.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
@brooke-hamilton brooke-hamilton added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Aug 18, 2026
@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 🟢 7
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1024 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Packaging⚠️ -1packaging workflow not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies⚠️ 3dependency not pinned by hash detected -- score normalized to 3
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
actions/actions/github-script 3a2844b7e9c422d3c10d287c895573f7108da1b3 🟢 6.7
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 9security policy file detected
SAST🟢 10SAST tool is run on all commits
Branch-Protection🟢 6branch protection is not maximal on development and all release branches

Scanned Files

  • .github/workflows/verify-commit-signatures.yml

@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files  ±0    461 suites  ±0   9m 20s ⏱️ +41s
6 531 tests ±0  6 529 ✅ ±0  2 💤 ±0  0 ❌ ±0 
7 807 runs  ±0  7 805 ✅ ±0  2 💤 ±0  0 ❌ ±0 

Results for commit 8cb4e64. ± Comparison against base commit 468c715.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 59.82%. Comparing base (468c715) to head (8cb4e64).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #12703      +/-   ##
==========================================
- Coverage   59.82%   59.82%   -0.01%     
==========================================
  Files         779      779              
  Lines       46058    46058              
==========================================
- Hits        27555    27552       -3     
- Misses      18503    18506       +3     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Functional Tests - upgrade-noncloud

3 tests  ±0   3 ✅ ±0   3m 38s ⏱️ -46s
1 suites ±0   0 💤 ±0 
1 files   ±0   0 ❌ ±0 

Results for commit fcbf3e3. ± Comparison against base commit 6882b5f.

♻️ This comment has been updated with latest results.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Comment thread .github/workflows/verify-commit-signatures.yml Fixed
brooke-hamilton and others added 3 commits August 19, 2026 10:36
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Comment thread .github/workflows/verify-commit-signatures.yml Fixed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds advisory commit-signature verification for pull requests and documents cryptographic signing as a contributor requirement.

Changes:

  • Adds signature detection and sticky PR guidance.
  • Supports automatic and manual verification.
  • Updates contributor signing documentation.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 4 comments.

Show a summary per file
File Description
.github/workflows/verify-commit-signatures.yml Runs verification and posts guidance.
.github/scripts/verify-commit-signatures.sh Finds unverified commits through GitHub GraphQL.
CONTRIBUTING.md Adds the signing requirement.
docs/contributing/contributing-pull-requests/README.md Documents signature-check behavior.
docs/contributing/contributing-code/contributing-code-first-commit/first-commit-06-creating-a-pr/index.md Marks commit signing as required.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/verify-commit-signatures.yml Outdated
Comment thread .github/scripts/verify-commit-signatures.sh Outdated
Comment thread .github/workflows/verify-commit-signatures.yml Outdated
Comment thread .github/workflows/verify-commit-signatures.yml Outdated
brooke-hamilton and others added 3 commits August 19, 2026 11:26
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
@brooke-hamilton
brooke-hamilton marked this pull request as ready for review August 19, 2026 15:43
@brooke-hamilton
brooke-hamilton requested review from a team as code owners August 19, 2026 15:43
Comment thread .github/workflows/verify-commit-signatures.yml
@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown

Functional Tests - corerp-cloud

32 tests  ±0   31 ✅ +2   20m 10s ⏱️ - 2m 48s
 2 suites ±0    1 💤 ±0 
 1 files   ±0    0 ❌  - 2 

Results for commit 6833783. ± Comparison against base commit 031840f.

♻️ This comment has been updated with latest results.

brooke-hamilton and others added 3 commits August 19, 2026 14:09
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Comment thread .github/scripts/verify-commit-signatures.mjs Outdated
Comment thread .github/scripts/verify-commit-signatures.mjs
brooke-hamilton and others added 6 commits August 26, 2026 09:36
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 67182a39-6aba-466e-b1c0-ced6f91ac5a2
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
This reverts commit ca94950.

Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
@github-actions

github-actions Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Functional Tests - multicluster-noncloud

6 tests  ±0   6 ✅ ±0   2m 42s ⏱️ ±0s
1 suites ±0   0 💤 ±0 
1 files   ±0   0 ❌ ±0 

Results for commit 5b4bab3. ± Comparison against base commit fa29a3d.

♻️ This comment has been updated with latest results.

@radius-functional-tests

radius-functional-tests Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref 8cb4e64
Unique ID funcbf80ae48d1
Image tag pr-funcbf80ae48d1
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-funcbf80ae48d1
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-funcbf80ae48d1
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-funcbf80ae48d1
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-funcbf80ae48d1
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-funcbf80ae48d1
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

@brooke-hamilton
brooke-hamilton added this pull request to the merge queue Sep 11, 2026
Merged via the queue into main with commit ad66e8d Sep 11, 2026
80 checks passed
@brooke-hamilton
brooke-hamilton deleted the brooke-hamilton-commit-signoff-check branch September 11, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants