Skip to content

feat(authority): add reviewed File and SQLite provider cutover #4432

feat(authority): add reviewed File and SQLite provider cutover

feat(authority): add reviewed File and SQLite provider cutover #4432

Workflow file for this run

name: DCO
on:
pull_request:
permissions:
contents: read
jobs:
signoff:
name: Sign-off
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Check out pull-request history
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Require DCO trailers on contribution commits
env:
BASE_REF: ${{ github.event.pull_request.base.ref }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
GH_TOKEN: ${{ github.token }}
shell: bash
run: |
set -euo pipefail
# The event's base SHA can predate upstream commits already in the PR.
# Refresh the exact target branch before selecting PR-only commits.
git fetch --no-tags origin \
"+refs/heads/${BASE_REF}:refs/remotes/origin/${BASE_REF}"
# Keep this outside process substitution so a failed range lookup
# cannot silently turn into a successful check of zero commits.
commits=$(git rev-list --reverse "refs/remotes/origin/${BASE_REF}..${HEAD_SHA}")
missing=0
while IFS= read -r commit; do
[[ -z "${commit}" ]] && continue
if git show -s --format=%B "${commit}" |
grep -Eq '^Signed-off-by: [^<]+ <[^<>[:space:]]+@[^<>[:space:]]+>$'; then
continue
fi
# GitHub adds signed integration commits without DCO trailers.
# A name/email alone is forgeable: require GitHub's verified record
# for this exact two-parent merge. Its parent commits stay in the
# range and are checked independently; manual merges are not exempt.
read -ra parents <<< "$(git show -s --format=%P "${commit}")"
if [[ "${#parents[@]}" -eq 2 ]] &&
[[ "$(git show -s --format=%cn "${commit}")" == "GitHub" ]] &&
[[ "$(git show -s --format=%ce "${commit}")" == "noreply@github.com" ]]; then
if ! metadata=$(gh api "repos/${GITHUB_REPOSITORY}/commits/${commit}"); then
echo "::error::Cannot verify GitHub merge provenance for ${commit}; retry the check when the API is available."
exit 1
fi
if jq -e --arg sha "${commit}" --arg first "${parents[0]}" --arg second "${parents[1]}" '
.sha == $sha and .committer.login == "web-flow" and
.commit.committer.name == "GitHub" and
.commit.committer.email == "noreply@github.com" and
.commit.verification.verified == true and
.commit.verification.reason == "valid" and
([.parents[].sha] == [$first, $second])
' <<< "${metadata}" >/dev/null; then
echo "Verified GitHub-generated merge ${commit}; checking its contributions separately."
continue
fi
fi
echo "::error::Commit ${commit} is missing a valid Signed-off-by trailer."
missing=1
done <<< "${commits}"
if [[ "${missing}" -ne 0 ]]; then
echo "Add the DCO certification with: git commit --amend -s"
exit 1
fi