1password/Check Signed Commits in PR
Ensure PRs don't contain unsigned commits and help getting started with commit signing.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stalelast commit Feb 12, 2024
- License
- MIT
Pinned Snippet
uses: 1password/check-signed-commits-action@ed2885f3ed2577a4f5d3c3fe895432a557d23d52 # v1tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| token | GitHub token to comment on the PR | — | ${{ github.token }} |
| comment | The comment to place in the PR | — | ⚠️ This PR contains unsigned commits. To get your PR merged, please sign those commits (`git rebase --exec 'git commit -S --amend --no-edit -n' @{upstream}`) and force push them to this branch (`git push --force-with-lease`). If you're new to commit signing, there are different ways to set it up: <details> <summary><b>Sign commits with <code>gpg</code></b></summary> <p></p> Follow the steps below to set up commit signing with `gpg`: 1. [Generate a GPG key](https://docs.github.com/en/authentication/managing-commit-signature-verification/generating-a-new-gpg-key) 2. [Add the GPG key to your GitHub account](https://docs.github.com/en/authentication/managing-commit-signature-verification/adding-a-gpg-key-to-your-github-account) 3. [Configure `git` to use your GPG key for commit signing](https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-gpg-key) </details> <details> <summary><b>Sign commits with <code>ssh-agent</code></b></summary> <p></p> Follow the steps below to set up commit signing with `ssh-agent`: 1. [Generate an SSH key and add it to `ssh-agent`](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent) 2. [Add the SSH key to your GitHub account](https://docs.github.com/en/authentication/connecting-to-github-with-ssh/adding-a-new-ssh-key-to-your-github-account) 3. [Configure `git` to use your SSH key for commit signing](https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key) </details> <details> <summary><b>Sign commits with 1Password</b></summary> <p></p> You can also sign commits using 1Password, which lets you sign commits with biometrics without the signing key leaving the local 1Password process. Learn how to [use 1Password to sign your commits](https://developer.1password.com/docs/ssh/git-commit-signing/). <a href="https://www.youtube.com/watch?feature=player_embedded&v=BMFvhl0WRFQ" target="_blank"> <img src="https://img.youtube.com/vi/BMFvhl0WRFQ/hqdefault.jpg" alt="Watch the demo" width=380 /> </a> </details> |
Outputs
no outputs