fix(ci): sign the commits this workflow creates - #4
Merged
Conversation
Commits created with plain git are unsigned and are rejected by the org-wide signed-commits ruleset. Route them through the GitHub API so GitHub signs them with its own key.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Makes the workflow that commits in this repo produce signed commits.
Commits created with plain
gitare unsigned. PostHog is rolling the org-wide "Require signed commits" ruleset out to every repo, and this workflow would be rejected withGH013once it applies here. Routing the commit through the GitHub API instead means GitHub signs it with its own key, so it lands verified.Found while inventorying which workflows across the org still create unsigned commits.
planetscale/ghcommit-actionis the pattern already in use inposthog-js,posthog-roblox,brand,chartsand the SDK release fleet.Changes
The release version bump is committed through the API. The job's
committedoutput now comes from an explicit check step rather than the commit step.Testing
Not run end to end (release runs behind an approval gate). Downstream jobs read
needs.version-bump.outputs.committed, which is preserved.