Skip to content

Latest commit

 

History

31 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

commit-verifier

Verifies that pull request commits are SSH-signed with enrolled, hardware-backed (sk-, FIDO2) keys. Runs on pull requests and in merge queues as an organization required workflow; the enrollment registry is allowed_signers.

Bot exemptions are per repository: ALLOWED_BOTS in verify_commits.sh maps owner/repo to the bot logins allowed there, plus a "*" list that applies everywhere. A bot listed nowhere gets no exemption.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages