feat(authority): add reviewed File and SQLite provider cutover #4432
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: DCO | |
| on: | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| signoff: | |
| name: Sign-off | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| steps: | |
| - name: Check out pull-request history | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Require DCO trailers on contribution commits | |
| env: | |
| BASE_REF: ${{ github.event.pull_request.base.ref }} | |
| HEAD_SHA: ${{ github.event.pull_request.head.sha }} | |
| GH_TOKEN: ${{ github.token }} | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| # The event's base SHA can predate upstream commits already in the PR. | |
| # Refresh the exact target branch before selecting PR-only commits. | |
| git fetch --no-tags origin \ | |
| "+refs/heads/${BASE_REF}:refs/remotes/origin/${BASE_REF}" | |
| # Keep this outside process substitution so a failed range lookup | |
| # cannot silently turn into a successful check of zero commits. | |
| commits=$(git rev-list --reverse "refs/remotes/origin/${BASE_REF}..${HEAD_SHA}") | |
| missing=0 | |
| while IFS= read -r commit; do | |
| [[ -z "${commit}" ]] && continue | |
| if git show -s --format=%B "${commit}" | | |
| grep -Eq '^Signed-off-by: [^<]+ <[^<>[:space:]]+@[^<>[:space:]]+>$'; then | |
| continue | |
| fi | |
| # GitHub adds signed integration commits without DCO trailers. | |
| # A name/email alone is forgeable: require GitHub's verified record | |
| # for this exact two-parent merge. Its parent commits stay in the | |
| # range and are checked independently; manual merges are not exempt. | |
| read -ra parents <<< "$(git show -s --format=%P "${commit}")" | |
| if [[ "${#parents[@]}" -eq 2 ]] && | |
| [[ "$(git show -s --format=%cn "${commit}")" == "GitHub" ]] && | |
| [[ "$(git show -s --format=%ce "${commit}")" == "noreply@github.com" ]]; then | |
| if ! metadata=$(gh api "repos/${GITHUB_REPOSITORY}/commits/${commit}"); then | |
| echo "::error::Cannot verify GitHub merge provenance for ${commit}; retry the check when the API is available." | |
| exit 1 | |
| fi | |
| if jq -e --arg sha "${commit}" --arg first "${parents[0]}" --arg second "${parents[1]}" ' | |
| .sha == $sha and .committer.login == "web-flow" and | |
| .commit.committer.name == "GitHub" and | |
| .commit.committer.email == "noreply@github.com" and | |
| .commit.verification.verified == true and | |
| .commit.verification.reason == "valid" and | |
| ([.parents[].sha] == [$first, $second]) | |
| ' <<< "${metadata}" >/dev/null; then | |
| echo "Verified GitHub-generated merge ${commit}; checking its contributions separately." | |
| continue | |
| fi | |
| fi | |
| echo "::error::Commit ${commit} is missing a valid Signed-off-by trailer." | |
| missing=1 | |
| done <<< "${commits}" | |
| if [[ "${missing}" -ne 0 ]]; then | |
| echo "Add the DCO certification with: git commit --amend -s" | |
| exit 1 | |
| fi |