Skip to content

Commit signature workflow fails when PR base predates verifier script #12974

Description

@willdavsmith

Engineering Improvement

Area for Improvement

The verify-commit-signatures workflow should load its trusted verifier script from the current default-branch workflow revision. It currently checks out github.event.pull_request.base.sha, which can refer to a commit from before the verifier script was added.

Observed behavior

The Verify Commit Signatures job failed for #12951 in workflow run 34867646799, job 104055411501.

The workflow itself ran from the current default branch, but its checkout step resolved this expression:

ref: ${{ github.event.pull_request.base.sha || github.sha }}

to commit fffca1e778bf66315058d32b3d18732da1bf4a10. That commit predates ad66e8d69, which added .github/scripts/verify-commit-signatures.mjs and .github/workflows/verify-commit-signatures.yml.

The sparse checkout therefore produced no verifier script. The next step failed before checking any signatures:

Error [ERR_MODULE_NOT_FOUND]: Cannot find module '/home/runner/work/radius/radius/.github/scripts/verify-commit-signatures.mjs'

All commits in #12951 have valid GitHub-verified GPG signatures, so this failure is unrelated to their signature status.

Desired behavior

The workflow always checks out the verifier implementation from the trusted revision that supplied the running workflow. Pull requests whose recorded base SHA predates the workflow must still be verified successfully.

Acceptance criteria:

  • A pull_request_target run for a PR with an older pull_request.base.sha can load the verifier script.
  • The workflow continues to execute only trusted base-repository code and never checks out PR-head code.
  • Valid signed commits pass verification and unsigned or invalidly signed commits receive the existing guidance.
  • A regression test or workflow test covers a PR whose base SHA predates the verifier files.

Proposed Fix

For pull_request_target, check out the current trusted base/default-branch workflow revision, such as github.sha, instead of github.event.pull_request.base.sha. Preserve the github.sha behavior for manual dispatch, or explicitly resolve the repository default branch before checkout.

The commit list being verified should continue to come from the pull request API; only the trusted verifier implementation needs to be checked out.

System information

rad Version

N/A — this is a GitHub Actions workflow failure.

Operating system

GitHub-hosted ubuntu-24.04 runner.

Additional context

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    maintenanceIssue is a non-user-facing task like updating tests, improving automation, etc..

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions