Skip to content

fix: create bump commits via GraphQL API so GitHub signs them - #24

Merged
tomfuertes merged 1 commit into
mainfrom
fix/signed-bump-commits
Jul 15, 2026
Merged

tomfuertes merged 1 commit into
mainfrom
fix/signed-bump-commits

Conversation

@tomfuertes

Copy link
Copy Markdown
Contributor

PR #23 was unmergeable: the main ruleset requires verified signatures, and the bump commit was created by plain git commit on the runner — unsigned, since runners have no signing key.

Changes

  • Branch ref + commit are now created through the API (POST /git/refs + GraphQL createCommitOnBranch). API-created commits are signed by GitHub's web-flow key and show Verified, satisfying the ruleset with no key material in CI.
  • All runner-side git write operations go away: gh auth setup-git, git config user.*, checkout -b, commit, push. sed still edits the local Dockerfile, but only to compute the new contents for the mutation.
  • Stale-branch cleanup switches from git push --delete to the refs API.

After merge: close #23, delete its branch, and re-dispatch — the workflow will recreate the bump PR with a verified commit.

The main ruleset requires verified signatures. git commits made on the
runner are unsigned, so bump PRs (e.g. #23) were unmergeable. Branch ref
and commit now go through the REST/GraphQL API (createCommitOnBranch),
which GitHub signs with its web-flow key. Drops gh auth setup-git and all
runner-side git write operations.
@tomfuertes
tomfuertes marked this pull request as ready for review July 15, 2026 15:06
@tomfuertes
tomfuertes merged commit d5d1ada into main Jul 15, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant