diff --git a/.github/workflows/notify-merge.yml b/.github/workflows/notify-merge.yml new file mode 100644 index 0000000..2f076d2 --- /dev/null +++ b/.github/workflows/notify-merge.yml @@ -0,0 +1,36 @@ +name: notify-sourcey-merge + +on: + push: + branches: [main] + paths: + - "entities/**/*.yaml" + +permissions: + contents: read + +concurrency: + group: notify-merge-${{ github.sha }} + cancel-in-progress: false + +jobs: + notify: + if: github.event.before != '0000000000000000000000000000000000000000' + runs-on: ubuntu-latest + timeout-minutes: 2 + steps: + # -f sends every field as a string; -F would turn the numeric + # repository id into a JSON number and the workspace lane pins it as text. + - name: Dispatch the exact merged head to Sourcey + env: + GH_TOKEN: ${{ secrets.SOURCEY_WORKSPACE_DISPATCH_TOKEN }} + BASE_SHA: ${{ github.event.before }} + HEAD_SHA: ${{ github.sha }} + REPOSITORY_ID: ${{ github.repository_id }} + run: | + test -n "$GH_TOKEN" + gh api --method POST repos/sourcey/sourcey-workspace/dispatches \ + -f event_type=agent-ready-services-merge \ + -f client_payload[base_sha]="$BASE_SHA" \ + -f client_payload[head_sha]="$HEAD_SHA" \ + -f client_payload[repository_id]="$REPOSITORY_ID" diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 7bccb4d..a937689 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -278,7 +278,9 @@ curl --fail-with-body --silent --show-error -H 'content-type: application/json' This is the same public package, signed identity-context protocol, and rooted trust input used by CI—not a second validator. Context issuance is explicit; final validation is offline over those bytes. -After merge, Sourcey retains the exact repository, commit, path, Git blob OID, -and SHA-256 blob digest before any private assessment begins. Identity, -authority, evidence coverage, human review, and release admission remain -separate gates. +After merge, a workflow in this repository tells Sourcey the exact merged head +(`notify-merge.yml`; it sends only the base and head commits and this +repository's id). Sourcey then retains the exact repository, commit, path, Git +blob OID, and SHA-256 blob digest before any private assessment begins. +Identity, authority, evidence coverage, human review, and release admission +remain separate gates.