google-github-actions / google-github-actions/run-gemini-cli

Feat: add verified signature on commit

Open
#130 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

area/workflows kind/enhancement priority/p2
Dominant language
TypeScript
Stars
2.1k
Forks
285
Avg merge
8h 8m
Merged PRs (30d)
1

Description

TL;DR

Verified signature commit of Gemini-cli bot is enabled by default.

Detailed design

Gemini-cli bot doesn't sign a commit now.

Image

Commit signing supported for bots and other GitHub Apps.

Image

Businesses and open source projects alike want to be sure that a commit is from a verified source—whether it’s from a developer across the world or a bot that’s integrated into their workflow.

Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository file, test, or implementation entry point is identified. Start by tracing how the GitHub Action invokes the Gemini CLI bot and how its commits are created, using the linked example and GitHub's commit-signing support as context. Done means bot-generated commits are shown as verified without disrupting the action.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, github-actions
Domain
ci-cd, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.