From 2ac502c747cbdc1205994d1e7ed7e2ca99c38e8d Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:02:28 -0700 Subject: [PATCH 01/11] add test workflow variants for ruleset validation testing --- .github/workflows/test-1.yml | 7 +++++++ .github/workflows/test-2.yml | 11 +++++++++++ .github/workflows/test-3.yml | 10 ++++++++++ .github/workflows/test-4.yml | 11 +++++++++++ .github/workflows/test-5.yml | 11 +++++++++++ 5 files changed, 50 insertions(+) create mode 100644 .github/workflows/test-1.yml create mode 100644 .github/workflows/test-2.yml create mode 100644 .github/workflows/test-3.yml create mode 100644 .github/workflows/test-4.yml create mode 100644 .github/workflows/test-5.yml diff --git a/.github/workflows/test-1.yml b/.github/workflows/test-1.yml new file mode 100644 index 0000000..9ecfddd --- /dev/null +++ b/.github/workflows/test-1.yml @@ -0,0 +1,7 @@ +name: Test 1 +on: [pull_request, merge_group] +jobs: + test: + runs-on: ubuntu-latest + steps: + - run: echo "test 1" diff --git a/.github/workflows/test-2.yml b/.github/workflows/test-2.yml new file mode 100644 index 0000000..ef3bb75 --- /dev/null +++ b/.github/workflows/test-2.yml @@ -0,0 +1,11 @@ +name: Test 2 +on: + pull_request: + branches: + - '*' + merge_group: +jobs: + test: + runs-on: ubuntu-latest + steps: + - run: echo "test 2" diff --git a/.github/workflows/test-3.yml b/.github/workflows/test-3.yml new file mode 100644 index 0000000..dc7f662 --- /dev/null +++ b/.github/workflows/test-3.yml @@ -0,0 +1,10 @@ +name: Test 3 +on: + pull_request: + types: [opened, synchronize] + merge_group: +jobs: + test: + runs-on: ubuntu-latest + steps: + - run: echo "test 3" diff --git a/.github/workflows/test-4.yml b/.github/workflows/test-4.yml new file mode 100644 index 0000000..62a15bc --- /dev/null +++ b/.github/workflows/test-4.yml @@ -0,0 +1,11 @@ +name: Test 4 +on: + pull_request: + paths: + - '.github/**' + merge_group: +jobs: + test: + runs-on: ubuntu-latest + steps: + - run: echo "test 4" diff --git a/.github/workflows/test-5.yml b/.github/workflows/test-5.yml new file mode 100644 index 0000000..153221c --- /dev/null +++ b/.github/workflows/test-5.yml @@ -0,0 +1,11 @@ +name: Test 5 +on: + pull_request: + branches: ['**'] + merge_group: + workflow_dispatch: +jobs: + test: + runs-on: ubuntu-latest + steps: + - run: echo "test 5" From 798068da322d9251d68c40599bd52827a7618891 Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:04:48 -0700 Subject: [PATCH 02/11] work --- .github/workflows/signed-commit-authors.yml | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/.github/workflows/signed-commit-authors.yml b/.github/workflows/signed-commit-authors.yml index 7a8c6e2..84a34ac 100644 --- a/.github/workflows/signed-commit-authors.yml +++ b/.github/workflows/signed-commit-authors.yml @@ -8,10 +8,7 @@ # The verifier needs a pull_request payload, so merge_group no-ops and passes. name: Signed Commit Authors -on: - pull_request: - branches: ['**'] - merge_group: +on: [pull_request, merge_group] permissions: {} From 88918f79744de86ce950373dff49f5e1b9c4230e Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:06:18 -0700 Subject: [PATCH 03/11] work --- .github/workflows/test-1.yml | 41 +++++++++++++++++++++++++++++++++--- 1 file changed, 38 insertions(+), 3 deletions(-) diff --git a/.github/workflows/test-1.yml b/.github/workflows/test-1.yml index 9ecfddd..84a34ac 100644 --- a/.github/workflows/test-1.yml +++ b/.github/workflows/test-1.yml @@ -1,7 +1,42 @@ -name: Test 1 +# Org-wide required workflow enforced by the org ruleset "workflows" rule. +# +# The verifier and SSH signing policy live in rocicorp/.github. Configure repo +# and branch targeting in the ruleset; required workflow event filters such as +# branches, paths, and types are ignored by GitHub. +# +# Because this is a required workflow, it must subscribe to merge_group too. +# The verifier needs a pull_request payload, so merge_group no-ops and passes. +name: Signed Commit Authors + on: [pull_request, merge_group] + +permissions: {} + +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' + cancel-in-progress: true + jobs: - test: + verify: + name: Verify Signed Commit Authors runs-on: ubuntu-latest + permissions: + contents: read # Required to checkout trusted base code and fetch commits. steps: - - run: echo "test 1" + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event: pull request commits are verified before entering the queue." + + - name: Check out trusted base + if: github.event_name == 'pull_request' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: ${{ github.event.pull_request.base.sha }} + persist-credentials: false + + - name: Verify signed commit authors + if: github.event_name == 'pull_request' + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main # zizmor: ignore[unpinned-uses] Cross-repo staging branch; pin after the shared workflow lands. + with: + enforce: false # Temporary until allowed_signers is populated. + github-token: ${{ github.token }} From 3ea6cadef9b661712b9493ac636899dfb82fc7cb Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:10:29 -0700 Subject: [PATCH 04/11] diagnose: add new variants of signed-commit-authors configuration --- .github/workflows/test-1.yml | 41 +++--------------------------------- .github/workflows/test-2.yml | 33 +++++++++++++++++++++++------ .github/workflows/test-3.yml | 28 ++++++++++++++++++------ .github/workflows/test-4.yml | 28 ++++++++++++++++++------ .github/workflows/test-5.yml | 37 ++++++++++++++++++++++++++------ 5 files changed, 102 insertions(+), 65 deletions(-) diff --git a/.github/workflows/test-1.yml b/.github/workflows/test-1.yml index 84a34ac..9ecfddd 100644 --- a/.github/workflows/test-1.yml +++ b/.github/workflows/test-1.yml @@ -1,42 +1,7 @@ -# Org-wide required workflow enforced by the org ruleset "workflows" rule. -# -# The verifier and SSH signing policy live in rocicorp/.github. Configure repo -# and branch targeting in the ruleset; required workflow event filters such as -# branches, paths, and types are ignored by GitHub. -# -# Because this is a required workflow, it must subscribe to merge_group too. -# The verifier needs a pull_request payload, so merge_group no-ops and passes. -name: Signed Commit Authors - +name: Test 1 on: [pull_request, merge_group] - -permissions: {} - -concurrency: - group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' - cancel-in-progress: true - jobs: - verify: - name: Verify Signed Commit Authors + test: runs-on: ubuntu-latest - permissions: - contents: read # Required to checkout trusted base code and fetch commits. steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event: pull request commits are verified before entering the queue." - - - name: Check out trusted base - if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - with: - ref: ${{ github.event.pull_request.base.sha }} - persist-credentials: false - - - name: Verify signed commit authors - if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main # zizmor: ignore[unpinned-uses] Cross-repo staging branch; pin after the shared workflow lands. - with: - enforce: false # Temporary until allowed_signers is populated. - github-token: ${{ github.token }} + - run: echo "test 1" diff --git a/.github/workflows/test-2.yml b/.github/workflows/test-2.yml index ef3bb75..f189313 100644 --- a/.github/workflows/test-2.yml +++ b/.github/workflows/test-2.yml @@ -1,11 +1,30 @@ name: Test 2 -on: - pull_request: - branches: - - '*' - merge_group: + +on: [pull_request, merge_group] + +permissions: {} + jobs: - test: + verify: + name: Verify Signed Commit Authors runs-on: ubuntu-latest + permissions: + contents: read steps: - - run: echo "test 2" + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event" + + - name: Check out trusted base + if: github.event_name == 'pull_request' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd + with: + ref: ${{ github.event.pull_request.base.sha }} + persist-credentials: false + + - name: Verify signed commit authors + if: github.event_name == 'pull_request' + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main + with: + enforce: false + github-token: ${{ github.token }} diff --git a/.github/workflows/test-3.yml b/.github/workflows/test-3.yml index dc7f662..2644922 100644 --- a/.github/workflows/test-3.yml +++ b/.github/workflows/test-3.yml @@ -1,10 +1,26 @@ name: Test 3 -on: - pull_request: - types: [opened, synchronize] - merge_group: + +on: [pull_request, merge_group] + jobs: - test: + verify: + name: Verify Signed Commit Authors runs-on: ubuntu-latest steps: - - run: echo "test 3" + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event" + + - name: Check out trusted base + if: github.event_name == 'pull_request' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd + with: + ref: ${{ github.event.pull_request.base.sha }} + persist-credentials: false + + - name: Verify signed commit authors + if: github.event_name == 'pull_request' + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main + with: + enforce: false + github-token: ${{ github.token }} diff --git a/.github/workflows/test-4.yml b/.github/workflows/test-4.yml index 62a15bc..5e7b951 100644 --- a/.github/workflows/test-4.yml +++ b/.github/workflows/test-4.yml @@ -1,11 +1,25 @@ name: Test 4 -on: - pull_request: - paths: - - '.github/**' - merge_group: + +on: [pull_request, merge_group] + +permissions: {} + +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' + cancel-in-progress: true + jobs: - test: + verify: + name: Verify Signed Commit Authors runs-on: ubuntu-latest + permissions: + contents: read steps: - - run: echo "test 4" + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event" + + - name: Dummy steps + run: | + echo "Simulate checkout base" + echo "Simulate verify signed commit authors" diff --git a/.github/workflows/test-5.yml b/.github/workflows/test-5.yml index 153221c..53811eb 100644 --- a/.github/workflows/test-5.yml +++ b/.github/workflows/test-5.yml @@ -1,11 +1,34 @@ name: Test 5 -on: - pull_request: - branches: ['**'] - merge_group: - workflow_dispatch: + +on: [pull_request, merge_group] + +permissions: {} + +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' + cancel-in-progress: true + jobs: - test: + verify: + name: Verify Signed Commit Authors runs-on: ubuntu-latest + permissions: + contents: read steps: - - run: echo "test 5" + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event" + + - name: Check out trusted base + if: github.event_name == 'pull_request' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd + with: + ref: ${{ github.event.pull_request.base.sha }} + persist-credentials: false + + - name: Verify signed commit authors + if: github.event_name == 'pull_request' + uses: ./.github/actions/verify-signed-commit-authors + with: + enforce: false + github-token: ${{ github.token }} From 71347938c78248e472ea7cf6a5cd6e4bb06fee3b Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:17:26 -0700 Subject: [PATCH 05/11] diagnose: strip all comments from signed-commit-authors workflow --- .github/workflows/signed-commit-authors.yml | 16 ++++------------ 1 file changed, 4 insertions(+), 12 deletions(-) diff --git a/.github/workflows/signed-commit-authors.yml b/.github/workflows/signed-commit-authors.yml index 84a34ac..2a9fb6a 100644 --- a/.github/workflows/signed-commit-authors.yml +++ b/.github/workflows/signed-commit-authors.yml @@ -1,11 +1,3 @@ -# Org-wide required workflow enforced by the org ruleset "workflows" rule. -# -# The verifier and SSH signing policy live in rocicorp/.github. Configure repo -# and branch targeting in the ruleset; required workflow event filters such as -# branches, paths, and types are ignored by GitHub. -# -# Because this is a required workflow, it must subscribe to merge_group too. -# The verifier needs a pull_request payload, so merge_group no-ops and passes. name: Signed Commit Authors on: [pull_request, merge_group] @@ -21,7 +13,7 @@ jobs: name: Verify Signed Commit Authors runs-on: ubuntu-latest permissions: - contents: read # Required to checkout trusted base code and fetch commits. + contents: read steps: - name: Merge group no-op if: github.event_name == 'merge_group' @@ -29,14 +21,14 @@ jobs: - name: Check out trusted base if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd with: ref: ${{ github.event.pull_request.base.sha }} persist-credentials: false - name: Verify signed commit authors if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main # zizmor: ignore[unpinned-uses] Cross-repo staging branch; pin after the shared workflow lands. + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main with: - enforce: false # Temporary until allowed_signers is populated. + enforce: false github-token: ${{ github.token }} From 87b49f08d3b05b63279a56bfc0a9bcea651bf7f8 Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:20:41 -0700 Subject: [PATCH 06/11] diagnose: add test-everything with and without comments --- .../test-everything-with-comments.yml | 42 +++++++++++++++++++ .../test-everything-without-comments.yml | 34 +++++++++++++++ 2 files changed, 76 insertions(+) create mode 100644 .github/workflows/test-everything-with-comments.yml create mode 100644 .github/workflows/test-everything-without-comments.yml diff --git a/.github/workflows/test-everything-with-comments.yml b/.github/workflows/test-everything-with-comments.yml new file mode 100644 index 0000000..e568441 --- /dev/null +++ b/.github/workflows/test-everything-with-comments.yml @@ -0,0 +1,42 @@ +# Org-wide required workflow enforced by the org ruleset "workflows" rule. +# +# The verifier and SSH signing policy live in rocicorp/.github. Configure repo +# and branch targeting in the ruleset; required workflow event filters such as +# branches, paths, and types are ignored by GitHub. +# +# Because this is a required workflow, it must subscribe to merge_group too. +# The verifier needs a pull_request payload, so merge_group no-ops and passes. +name: Test Everything With Comments + +on: [pull_request, merge_group] + +permissions: {} + +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' + cancel-in-progress: true + +jobs: + verify: + name: Verify Signed Commit Authors + runs-on: ubuntu-latest + permissions: + contents: read # Required to checkout trusted base code and fetch commits. + steps: + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event: pull request commits are verified before entering the queue." + + - name: Check out trusted base + if: github.event_name == 'pull_request' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: ${{ github.event.pull_request.base.sha }} + persist-credentials: false + + - name: Verify signed commit authors + if: github.event_name == 'pull_request' + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main # zizmor: ignore[unpinned-uses] Cross-repo staging branch; pin after the shared workflow lands. + with: + enforce: false # Temporary until allowed_signers is populated. + github-token: ${{ github.token }} diff --git a/.github/workflows/test-everything-without-comments.yml b/.github/workflows/test-everything-without-comments.yml new file mode 100644 index 0000000..53c70f6 --- /dev/null +++ b/.github/workflows/test-everything-without-comments.yml @@ -0,0 +1,34 @@ +name: Test Everything Without Comments + +on: [pull_request, merge_group] + +permissions: {} + +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' + cancel-in-progress: true + +jobs: + verify: + name: Verify Signed Commit Authors + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Merge group no-op + if: github.event_name == 'merge_group' + run: echo "merge_group event: pull request commits are verified before entering the queue." + + - name: Check out trusted base + if: github.event_name == 'pull_request' + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd + with: + ref: ${{ github.event.pull_request.base.sha }} + persist-credentials: false + + - name: Verify signed commit authors + if: github.event_name == 'pull_request' + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main + with: + enforce: false + github-token: ${{ github.token }} From 875709dfe54a0dd1d955ab61e6379e597659f76e Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:31:36 -0700 Subject: [PATCH 07/11] fix: remove concurrency block from signed-commit-authors workflow --- .github/workflows/signed-commit-authors.yml | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/.github/workflows/signed-commit-authors.yml b/.github/workflows/signed-commit-authors.yml index 2a9fb6a..c10c1cd 100644 --- a/.github/workflows/signed-commit-authors.yml +++ b/.github/workflows/signed-commit-authors.yml @@ -1,19 +1,23 @@ +# Org-wide required workflow enforced by the org ruleset "workflows" rule. +# +# The verifier and SSH signing policy live in rocicorp/.github. Configure repo +# and branch targeting in the ruleset; required workflow event filters such as +# branches, paths, and types are ignored by GitHub. +# +# Because this is a required workflow, it must subscribe to merge_group too. +# The verifier needs a pull_request payload, so merge_group no-ops and passes. name: Signed Commit Authors on: [pull_request, merge_group] permissions: {} -concurrency: - group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' - cancel-in-progress: true - jobs: verify: name: Verify Signed Commit Authors runs-on: ubuntu-latest permissions: - contents: read + contents: read # Required to checkout trusted base code and fetch commits. steps: - name: Merge group no-op if: github.event_name == 'merge_group' @@ -21,14 +25,14 @@ jobs: - name: Check out trusted base if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: ref: ${{ github.event.pull_request.base.sha }} persist-credentials: false - name: Verify signed commit authors if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main + uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main # zizmor: ignore[unpinned-uses] Cross-repo staging branch; pin after the shared workflow lands. with: - enforce: false + enforce: false # Temporary until allowed_signers is populated. github-token: ${{ github.token }} From 3a884ce2deb633acfc3ecee14d4ccb2a895277f2 Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:34:46 -0700 Subject: [PATCH 08/11] fix: remove colon from echo command to avoid validator split bug --- .github/workflows/signed-commit-authors.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/signed-commit-authors.yml b/.github/workflows/signed-commit-authors.yml index c10c1cd..7fcf133 100644 --- a/.github/workflows/signed-commit-authors.yml +++ b/.github/workflows/signed-commit-authors.yml @@ -21,7 +21,7 @@ jobs: steps: - name: Merge group no-op if: github.event_name == 'merge_group' - run: echo "merge_group event: pull request commits are verified before entering the queue." + run: echo "merge_group event - pull request commits are verified before entering the queue" - name: Check out trusted base if: github.event_name == 'pull_request' From 1ccc3d957a8cdc37df73ce63f023b91b7c9f6012 Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:36:24 -0700 Subject: [PATCH 09/11] clean: remove temporary ruleset test workflows --- .github/workflows/test-1.yml | 7 ---- .github/workflows/test-2.yml | 30 ------------- .github/workflows/test-3.yml | 26 ------------ .github/workflows/test-4.yml | 25 ----------- .github/workflows/test-5.yml | 34 --------------- .../test-everything-with-comments.yml | 42 ------------------- .../test-everything-without-comments.yml | 34 --------------- 7 files changed, 198 deletions(-) delete mode 100644 .github/workflows/test-1.yml delete mode 100644 .github/workflows/test-2.yml delete mode 100644 .github/workflows/test-3.yml delete mode 100644 .github/workflows/test-4.yml delete mode 100644 .github/workflows/test-5.yml delete mode 100644 .github/workflows/test-everything-with-comments.yml delete mode 100644 .github/workflows/test-everything-without-comments.yml diff --git a/.github/workflows/test-1.yml b/.github/workflows/test-1.yml deleted file mode 100644 index 9ecfddd..0000000 --- a/.github/workflows/test-1.yml +++ /dev/null @@ -1,7 +0,0 @@ -name: Test 1 -on: [pull_request, merge_group] -jobs: - test: - runs-on: ubuntu-latest - steps: - - run: echo "test 1" diff --git a/.github/workflows/test-2.yml b/.github/workflows/test-2.yml deleted file mode 100644 index f189313..0000000 --- a/.github/workflows/test-2.yml +++ /dev/null @@ -1,30 +0,0 @@ -name: Test 2 - -on: [pull_request, merge_group] - -permissions: {} - -jobs: - verify: - name: Verify Signed Commit Authors - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event" - - - name: Check out trusted base - if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd - with: - ref: ${{ github.event.pull_request.base.sha }} - persist-credentials: false - - - name: Verify signed commit authors - if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main - with: - enforce: false - github-token: ${{ github.token }} diff --git a/.github/workflows/test-3.yml b/.github/workflows/test-3.yml deleted file mode 100644 index 2644922..0000000 --- a/.github/workflows/test-3.yml +++ /dev/null @@ -1,26 +0,0 @@ -name: Test 3 - -on: [pull_request, merge_group] - -jobs: - verify: - name: Verify Signed Commit Authors - runs-on: ubuntu-latest - steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event" - - - name: Check out trusted base - if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd - with: - ref: ${{ github.event.pull_request.base.sha }} - persist-credentials: false - - - name: Verify signed commit authors - if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main - with: - enforce: false - github-token: ${{ github.token }} diff --git a/.github/workflows/test-4.yml b/.github/workflows/test-4.yml deleted file mode 100644 index 5e7b951..0000000 --- a/.github/workflows/test-4.yml +++ /dev/null @@ -1,25 +0,0 @@ -name: Test 4 - -on: [pull_request, merge_group] - -permissions: {} - -concurrency: - group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' - cancel-in-progress: true - -jobs: - verify: - name: Verify Signed Commit Authors - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event" - - - name: Dummy steps - run: | - echo "Simulate checkout base" - echo "Simulate verify signed commit authors" diff --git a/.github/workflows/test-5.yml b/.github/workflows/test-5.yml deleted file mode 100644 index 53811eb..0000000 --- a/.github/workflows/test-5.yml +++ /dev/null @@ -1,34 +0,0 @@ -name: Test 5 - -on: [pull_request, merge_group] - -permissions: {} - -concurrency: - group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' - cancel-in-progress: true - -jobs: - verify: - name: Verify Signed Commit Authors - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event" - - - name: Check out trusted base - if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd - with: - ref: ${{ github.event.pull_request.base.sha }} - persist-credentials: false - - - name: Verify signed commit authors - if: github.event_name == 'pull_request' - uses: ./.github/actions/verify-signed-commit-authors - with: - enforce: false - github-token: ${{ github.token }} diff --git a/.github/workflows/test-everything-with-comments.yml b/.github/workflows/test-everything-with-comments.yml deleted file mode 100644 index e568441..0000000 --- a/.github/workflows/test-everything-with-comments.yml +++ /dev/null @@ -1,42 +0,0 @@ -# Org-wide required workflow enforced by the org ruleset "workflows" rule. -# -# The verifier and SSH signing policy live in rocicorp/.github. Configure repo -# and branch targeting in the ruleset; required workflow event filters such as -# branches, paths, and types are ignored by GitHub. -# -# Because this is a required workflow, it must subscribe to merge_group too. -# The verifier needs a pull_request payload, so merge_group no-ops and passes. -name: Test Everything With Comments - -on: [pull_request, merge_group] - -permissions: {} - -concurrency: - group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' - cancel-in-progress: true - -jobs: - verify: - name: Verify Signed Commit Authors - runs-on: ubuntu-latest - permissions: - contents: read # Required to checkout trusted base code and fetch commits. - steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event: pull request commits are verified before entering the queue." - - - name: Check out trusted base - if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - with: - ref: ${{ github.event.pull_request.base.sha }} - persist-credentials: false - - - name: Verify signed commit authors - if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main # zizmor: ignore[unpinned-uses] Cross-repo staging branch; pin after the shared workflow lands. - with: - enforce: false # Temporary until allowed_signers is populated. - github-token: ${{ github.token }} diff --git a/.github/workflows/test-everything-without-comments.yml b/.github/workflows/test-everything-without-comments.yml deleted file mode 100644 index 53c70f6..0000000 --- a/.github/workflows/test-everything-without-comments.yml +++ /dev/null @@ -1,34 +0,0 @@ -name: Test Everything Without Comments - -on: [pull_request, merge_group] - -permissions: {} - -concurrency: - group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' - cancel-in-progress: true - -jobs: - verify: - name: Verify Signed Commit Authors - runs-on: ubuntu-latest - permissions: - contents: read - steps: - - name: Merge group no-op - if: github.event_name == 'merge_group' - run: echo "merge_group event: pull request commits are verified before entering the queue." - - - name: Check out trusted base - if: github.event_name == 'pull_request' - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd - with: - ref: ${{ github.event.pull_request.base.sha }} - persist-credentials: false - - - name: Verify signed commit authors - if: github.event_name == 'pull_request' - uses: rocicorp/.github/.github/actions/verify-signed-commit-authors@main - with: - enforce: false - github-token: ${{ github.token }} From e371b387838fab9e5933a6834b5aae8db50a81cb Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:39:28 -0700 Subject: [PATCH 10/11] fix: revert trigger syntax back to original layout --- .github/workflows/signed-commit-authors.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/signed-commit-authors.yml b/.github/workflows/signed-commit-authors.yml index 7fcf133..71cf5f6 100644 --- a/.github/workflows/signed-commit-authors.yml +++ b/.github/workflows/signed-commit-authors.yml @@ -8,7 +8,9 @@ # The verifier needs a pull_request payload, so merge_group no-ops and passes. name: Signed Commit Authors -on: [pull_request, merge_group] +on: + pull_request: + merge_group: permissions: {} From de84f24f6c2089371b5db27adfa911d33da82ad0 Mon Sep 17 00:00:00 2001 From: Greg Baker Date: Wed, 8 Jul 2026 14:41:47 -0700 Subject: [PATCH 11/11] fix: restore concurrency block to signed-commit-authors workflow --- .github/workflows/signed-commit-authors.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/signed-commit-authors.yml b/.github/workflows/signed-commit-authors.yml index 71cf5f6..94aabba 100644 --- a/.github/workflows/signed-commit-authors.yml +++ b/.github/workflows/signed-commit-authors.yml @@ -14,6 +14,10 @@ on: permissions: {} +concurrency: + group: '${{ github.workflow }} @ ${{ github.event.pull_request.number || github.event.merge_group.head_sha || github.run_id }}' + cancel-in-progress: true + jobs: verify: name: Verify Signed Commit Authors