1password/Check Signed Commits in PR

Ensure PRs don't contain unsigned commits and help getting started with commit signing.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stalelast commit Feb 12, 2024
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: 1password/check-signed-commits-action@ed2885f3ed2577a4f5d3c3fe895432a557d23d52 # v1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
tokenGitHub token to comment on the PR${{ github.token }}
commentThe comment to place in the PR⚠️ This PR contains unsigned commits. To get your PR merged, please sign those commits (`git rebase --exec 'git commit -S --amend --no-edit -n' @{upstream}`) and force push them to this branch (`git push --force-with-lease`). If you're new to commit signing, there are different ways to set it up: <details> <summary><b>Sign commits with <code>gpg</code></b></summary> <p></p> Follow the steps below to set up commit signing with `gpg`: 1. [Generate a GPG key](https://docs.github.com/en/authentication/managing-commit-signature-verification/generating-a-new-gpg-key) 2. [Add the GPG key to your GitHub account](https://docs.github.com/en/authentication/managing-commit-signature-verification/adding-a-gpg-key-to-your-github-account) 3. [Configure `git` to use your GPG key for commit signing](https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-gpg-key) </details> <details> <summary><b>Sign commits with <code>ssh-agent</code></b></summary> <p></p> Follow the steps below to set up commit signing with `ssh-agent`: 1. [Generate an SSH key and add it to `ssh-agent`](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent) 2. [Add the SSH key to your GitHub account](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/adding-a-new-ssh-key-to-your-github-account) 3. [Configure `git` to use your SSH key for commit signing](https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key) </details> <details> <summary><b>Sign commits with 1Password</b></summary> <p></p> You can also sign commits using 1Password, which lets you sign commits with biometrics without the signing key leaving the local 1Password process. Learn how to [use 1Password to sign your commits](https://developer.1password.com/docs/ssh/git-commit-signing/). <a href="https://www.youtube.com/watch?feature=player_embedded&v=BMFvhl0WRFQ" target="_blank"> <img src="https://img.youtube.com/vi/BMFvhl0WRFQ/hqdefault.jpg" alt="Watch the demo" width=380 /> </a> </details>

no outputs