-
Notifications
You must be signed in to change notification settings - Fork 0
156 lines (152 loc) · 7.27 KB
/
Copy pathvalidate.yml
File metadata and controls
156 lines (152 loc) · 7.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
name: validate-readiness-declaration
on:
pull_request_target:
permissions:
contents: read
statuses: write
concurrency:
group: validate-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
validate:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
with:
ref: ${{ github.event.repository.default_branch }}
path: trusted
persist-credentials: false
- name: Fetch the exact candidate SHA as inert data
env:
CANDIDATE_ORIGIN: ${{ github.event.pull_request.head.repo.clone_url }}
HEAD_REVISION: ${{ github.event.pull_request.head.sha }}
run: |
git init candidate
git -C candidate remote add origin "$CANDIDATE_ORIGIN"
git -C candidate fetch --filter=blob:none --no-tags origin "$HEAD_REVISION"
git -C candidate checkout --detach "$HEAD_REVISION"
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
with:
node-version: 22.12.0
- name: Fetch the exact trusted comparison base
env:
BASE_REVISION: ${{ github.event.pull_request.base.sha }}
working-directory: candidate
run: git fetch --filter=blob:none --no-tags https://github.com/sourcey/agent-ready-services.git "$BASE_REVISION"
- name: Install the exact Sourcey Catalog Verifier
run: |
npm ci --prefix trusted/.github/catalog-verifier \
--ignore-scripts --no-audit --no-fund
requested_version="$(
jq -er '.dependencies["@sourcey/catalog-verifier"]' \
trusted/.github/catalog-verifier/package.json
)"
installed_version="$(
jq -er '.version' \
trusted/.github/catalog-verifier/node_modules/@sourcey/catalog-verifier/package.json
)"
test "$installed_version" = "$requested_version"
verifier_digest="$(<trusted/.github/sourcey-catalog-verifier.sha256)"
[[ "$verifier_digest" =~ ^[a-f0-9]{64}$ ]]
verifier_url="$(
jq -er '.packages["node_modules/@sourcey/catalog-verifier"].resolved' \
trusted/.github/catalog-verifier/package-lock.json
)"
curl --fail-with-body --silent --show-error --max-time 30 \
"$verifier_url" --output "$RUNNER_TEMP/sourcey-catalog-verifier.tgz"
test "$(sha256sum "$RUNNER_TEMP/sourcey-catalog-verifier.tgz" | awk '{print $1}')" = \
"$verifier_digest"
- name: Issue the exact bounded Catalog identity context
env:
BASE_REVISION: ${{ github.event.pull_request.base.sha }}
HEAD_REVISION: ${{ github.event.pull_request.head.sha }}
PULL_REQUEST_NUMBER: ${{ github.event.pull_request.number }}
run: |
verifier="trusted/.github/catalog-verifier/node_modules/.bin/sourcey-catalog-verify"
curl --fail-with-body --silent --show-error --max-time 30 \
https://api.sourcey.com/v1/release \
--output "$RUNNER_TEMP/sourcey-live-release.json"
live_parent_release_id="$(
jq -er '.release_id | select(test("^sha256:[a-f0-9]{64}$"))' \
"$RUNNER_TEMP/sourcey-live-release.json"
)"
live_root_digest="$(
jq -er '.descriptor.snapshot_core.root_set_digest
| select(test("^sha256:[a-f0-9]{64}$"))' \
"$RUNNER_TEMP/sourcey-live-release.json"
)"
trusted_root_digest="$(<trusted/.github/sourcey-root-set.digest)"
test "$live_root_digest" = "$trusted_root_digest"
"$verifier" identity-context-request agent-readiness \
--repository "$GITHUB_WORKSPACE/candidate" \
--base "$BASE_REVISION" \
--head "$HEAD_REVISION" \
--live-parent-release-id "$live_parent_release_id" \
--candidate-repository "$GITHUB_REPOSITORY" \
--pull-request "$PULL_REQUEST_NUMBER" \
> "$RUNNER_TEMP/sourcey-identity-query.json"
curl --fail-with-body --silent --show-error --max-time 30 \
-H 'content-type: application/json' \
--data-binary @"$RUNNER_TEMP/sourcey-identity-query.json" \
https://api.sourcey.com/v1/catalog-verifier/identity-contexts \
--output "$RUNNER_TEMP/sourcey-identity-response.json"
jq -e \
--arg release_id "$live_parent_release_id" \
'.release_id == $release_id
and .data.query.liveParentReleaseId == $release_id' \
"$RUNNER_TEMP/sourcey-identity-response.json" >/dev/null
jq -e '.data' "$RUNNER_TEMP/sourcey-identity-response.json" \
> "$RUNNER_TEMP/sourcey-identity-context.json"
- name: Validate only the changed declaration closure
env:
BASE_REVISION: ${{ github.event.pull_request.base.sha }}
HEAD_REVISION: ${{ github.event.pull_request.head.sha }}
PULL_REQUEST_NUMBER: ${{ github.event.pull_request.number }}
run: |
verified_at="$(node -p 'new Date().toISOString()')"
trusted_root_digest="$(<trusted/.github/sourcey-root-set.digest)"
trusted/.github/catalog-verifier/node_modules/.bin/sourcey-catalog-verify \
validate agent-readiness \
--repository "$GITHUB_WORKSPACE/candidate" \
--base "$BASE_REVISION" \
--head "$HEAD_REVISION" \
--identity-context "$RUNNER_TEMP/sourcey-identity-context.json" \
--root-set trusted/.github/sourcey-root-set.json \
--trusted-root-digest "$trusted_root_digest" \
--verified-at "$verified_at" \
--candidate-repository "$GITHUB_REPOSITORY" \
--pull-request "$PULL_REQUEST_NUMBER" \
--format json
- name: Verify Developer Certificate of Origin sign-off
env:
BASE_REVISION: ${{ github.event.pull_request.base.sha }}
HEAD_REVISION: ${{ github.event.pull_request.head.sha }}
working-directory: candidate
run: |
change_base="$(git merge-base "$BASE_REVISION" "$HEAD_REVISION")"
missing=()
while IFS= read -r commit; do
if ! git show -s --format=%B "$commit" \
| grep -Eq '^Signed-off-by: .+ <[^>]+>$'; then
missing+=("$commit")
fi
done < <(git rev-list --no-merges "$change_base..$HEAD_REVISION")
if (( ${#missing[@]} > 0 )); then
printf 'Commits missing Signed-off-by certification:\n%s\n' "${missing[*]}" >&2
exit 1
fi
- name: Publish the exact Sourcey validation result
if: always()
env:
GH_TOKEN: ${{ github.token }}
HEAD_REVISION: ${{ github.event.pull_request.head.sha }}
VALIDATION_STATE: ${{ job.status == 'success' && 'success' || 'failure' }}
VALIDATION_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
run: |
gh api --method POST \
"repos/${GITHUB_REPOSITORY}/statuses/${HEAD_REVISION}" \
-f state="$VALIDATION_STATE" \
-f context=sourcey/validation \
-f description="Sourcey changed-closure validation ${VALIDATION_STATE}" \
-f target_url="$VALIDATION_URL"