googleapis / googleapis/release-please-action

Commit signing

Open
#1,104 3 comments 4 reactions 0 assignees View on GitHub
priority: p3 type: question
Dominant language
TypeScript
Stars
2.5k
Forks
327
PR merge metrics
No merged PRs in 30d

Description

Thanks for stopping by to ask us a question! Please make sure to include:
- What you're trying to do
- What code you've already tried
- Any error messages you're getting

**PLEASE READ**: If you have a support contract with Google, please create an issue in the [support console](https://cloud.google.com/support/) instead of filing on GitHub. This will ensure a timely response.

When the GitHub Actions bot commits or creates a release, although GitHub initially lists the commits as Verified, the actual commits or releases are listed as Partially Verified. I like to have fully-verified signatures on all commits/release, so I'm wondering if this is a GitHub limitation or whether release-please can do this.

Contributor guide

Open the contributing guide

Research direction

No file or test is named. Start by reviewing the action's GitHub Actions commit and release flow alongside GitHub's commit-signing and verification behavior. Done means establishing whether fully verified signatures are supported and, if so, defining the required implementation or documentation change.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, github-actions, typescript
Domain
release, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.