Engineering Improvement
Area for Improvement
The verify-commit-signatures workflow should load its trusted verifier script from the current default-branch workflow revision. It currently checks out github.event.pull_request.base.sha, which can refer to a commit from before the verifier script was added.
Observed behavior
The Verify Commit Signatures job failed for #12951 in workflow run 34867646799, job 104055411501.
The workflow itself ran from the current default branch, but its checkout step resolved this expression:
ref: ${{ github.event.pull_request.base.sha || github.sha }}
to commit fffca1e778bf66315058d32b3d18732da1bf4a10. That commit predates ad66e8d69, which added .github/scripts/verify-commit-signatures.mjs and .github/workflows/verify-commit-signatures.yml.
The sparse checkout therefore produced no verifier script. The next step failed before checking any signatures:
Error [ERR_MODULE_NOT_FOUND]: Cannot find module '/home/runner/work/radius/radius/.github/scripts/verify-commit-signatures.mjs'
All commits in #12951 have valid GitHub-verified GPG signatures, so this failure is unrelated to their signature status.
Desired behavior
The workflow always checks out the verifier implementation from the trusted revision that supplied the running workflow. Pull requests whose recorded base SHA predates the workflow must still be verified successfully.
Acceptance criteria:
- A
pull_request_target run for a PR with an older pull_request.base.sha can load the verifier script.
- The workflow continues to execute only trusted base-repository code and never checks out PR-head code.
- Valid signed commits pass verification and unsigned or invalidly signed commits receive the existing guidance.
- A regression test or workflow test covers a PR whose base SHA predates the verifier files.
Proposed Fix
For pull_request_target, check out the current trusted base/default-branch workflow revision, such as github.sha, instead of github.event.pull_request.base.sha. Preserve the github.sha behavior for manual dispatch, or explicitly resolve the repository default branch before checkout.
The commit list being verified should continue to come from the pull request API; only the trusted verifier implementation needs to be checked out.
System information
rad Version
N/A — this is a GitHub Actions workflow failure.
Operating system
GitHub-hosted ubuntu-24.04 runner.
Additional context
Engineering Improvement
Area for Improvement
The
verify-commit-signaturesworkflow should load its trusted verifier script from the current default-branch workflow revision. It currently checks outgithub.event.pull_request.base.sha, which can refer to a commit from before the verifier script was added.Observed behavior
The
Verify Commit Signaturesjob failed for #12951 in workflow run 34867646799, job 104055411501.The workflow itself ran from the current default branch, but its checkout step resolved this expression:
to commit
fffca1e778bf66315058d32b3d18732da1bf4a10. That commit predatesad66e8d69, which added.github/scripts/verify-commit-signatures.mjsand.github/workflows/verify-commit-signatures.yml.The sparse checkout therefore produced no verifier script. The next step failed before checking any signatures:
All commits in #12951 have valid GitHub-verified GPG signatures, so this failure is unrelated to their signature status.
Desired behavior
The workflow always checks out the verifier implementation from the trusted revision that supplied the running workflow. Pull requests whose recorded base SHA predates the workflow must still be verified successfully.
Acceptance criteria:
pull_request_targetrun for a PR with an olderpull_request.base.shacan load the verifier script.Proposed Fix
For
pull_request_target, check out the current trusted base/default-branch workflow revision, such asgithub.sha, instead ofgithub.event.pull_request.base.sha. Preserve thegithub.shabehavior for manual dispatch, or explicitly resolve the repository default branch before checkout.The commit list being verified should continue to come from the pull request API; only the trusted verifier implementation needs to be checked out.
System information
rad Version
N/A — this is a GitHub Actions workflow failure.
Operating system
GitHub-hosted
ubuntu-24.04runner.Additional context
ad66e8d69fffca1e778bf66315058d32b3d18732da1bf4a10