Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions .github/workflows/notify-merge.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
name: notify-sourcey-merge

on:
push:
branches: [main]
paths:
- "entities/**/*.yaml"

permissions:
contents: read

concurrency:
group: notify-merge-${{ github.sha }}
cancel-in-progress: false

jobs:
notify:
if: github.event.before != '0000000000000000000000000000000000000000'
runs-on: ubuntu-latest
timeout-minutes: 2
steps:
# -f sends every field as a string; -F would turn the numeric
# repository id into a JSON number and the workspace lane pins it as text.
- name: Dispatch the exact merged head to Sourcey
env:
GH_TOKEN: ${{ secrets.SOURCEY_WORKSPACE_DISPATCH_TOKEN }}
BASE_SHA: ${{ github.event.before }}
HEAD_SHA: ${{ github.sha }}
REPOSITORY_ID: ${{ github.repository_id }}
run: |
test -n "$GH_TOKEN"
gh api --method POST repos/sourcey/sourcey-workspace/dispatches \
-f event_type=agent-ready-services-merge \
-f client_payload[base_sha]="$BASE_SHA" \
-f client_payload[head_sha]="$HEAD_SHA" \
-f client_payload[repository_id]="$REPOSITORY_ID"
10 changes: 6 additions & 4 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -278,7 +278,9 @@ curl --fail-with-body --silent --show-error -H 'content-type: application/json'
This is the same public package, signed identity-context protocol, and rooted trust input used by
CI—not a second validator. Context issuance is explicit; final validation is offline over those bytes.

After merge, Sourcey retains the exact repository, commit, path, Git blob OID,
and SHA-256 blob digest before any private assessment begins. Identity,
authority, evidence coverage, human review, and release admission remain
separate gates.
After merge, a workflow in this repository tells Sourcey the exact merged head
(`notify-merge.yml`; it sends only the base and head commits and this
repository's id). Sourcey then retains the exact repository, commit, path, Git
blob OID, and SHA-256 blob digest before any private assessment begins.
Identity, authority, evidence coverage, human review, and release admission
remain separate gates.
Loading