chainguard-dev / chainguard-dev/actions

Configured but not signing

Open
#469 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
173
Forks
83
Avg merge
1d 15h
Merged PRs (30d)
11

Description

Is there an extra step I still have to configure to get my commits to be signed?

I am getting an error because my commit is not signed:

remote: - Commits must have verified signatures.        

Here is my yaml file:

name: Ruff Linting

on:
  push:
    branches:
      - master
  pull_request:
    branches:
      - master

jobs:
  lint:
    permissions:
      contents: write
      id-token: write # Enable OIDC

    runs-on: ubuntu-latest

    steps:
      - name: Checkout code
        uses: actions/checkout@v3

      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: "3.12"

      - name: Install ruff
        run: pip install ruff

      - name: Run ruff
        run: ruff check . --ignore F841 --fix

      - name: Format code
        run: ruff format

      - uses: chainguard-dev/actions/setup-gitsign@main

      - uses: stefanzweifel/git-auto-commit-action@v4
        with:
          commit_message: "style fixes by ruff"
          # commit_options: "-S"

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the workflow YAML shown, especially the setup-gitsign action and stefanzweifel/git-auto-commit-action step, and check how the generated commit is signed and verified. Confirm the workflow's resulting commit satisfies the repository requirement for verified signatures.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, github-actions, yaml
Domain
ci-cd, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.