feat: validate the attestation tag in CI and drive the pull request through the forge #6

Merged
beddari merged 1 commit from pr-validation-and-forge-wiring into main 2026-09-17 16:44:07 +00:00
Owner

Steps 2 and 3 of the README next steps, plus the registry Actions secrets from step 1 and implementation-conventions.md for step 4.

  • .forgejo/workflows/validate-attestation.yaml + .forgejo/attesters: bash-only CI check of the signed attestation/<head> tag on every PR push. Tested against a local signed-tag fixture; this PR has no attestation tag, so its own run fails by design.
  • pr_merge_state on the forgejo model; the pull-request stage drives pr_ensure and pr_merge_state, pull-request evidence carries the PR index.
  • agent-constraints/implementation-conventions.md is the implementing stage constraints.
  • Protected paths changed: .forgejo/, agent-constraints/, models/, extensions/. Human review required.
  • Open: release.yaml reads COSIGN_PRIVATE_KEY from Actions secrets, which the signing-key design forbids; see README step 1.
Steps 2 and 3 of the README next steps, plus the registry Actions secrets from step 1 and implementation-conventions.md for step 4. - `.forgejo/workflows/validate-attestation.yaml` + `.forgejo/attesters`: bash-only CI check of the signed `attestation/<head>` tag on every PR push. Tested against a local signed-tag fixture; this PR has no attestation tag, so its own run fails by design. - `pr_merge_state` on the forgejo model; the `pull-request` stage drives `pr_ensure` and `pr_merge_state`, `pull-request` evidence carries the PR index. - `agent-constraints/implementation-conventions.md` is the implementing stage constraints. - Protected paths changed: `.forgejo/`, `agent-constraints/`, `models/`, `extensions/`. Human review required. - Open: `release.yaml` reads `COSIGN_PRIVATE_KEY` from Actions secrets, which the signing-key design forbids; see README step 1.
feat: validate the attestation tag in CI and drive the pull request through the forge
Some checks failed
validate-attestation / validate (pull_request) Failing after 2m53s
6b9a04686a
CI (.forgejo/workflows/validate-attestation.yaml, bash only) checks on every PR push that attestation/<head> is an
annotated tag on the PR head signed by an attester in .forgejo/attesters (read from the base branch), that the
document attests that head with green verification and no unresolved critical/high findings, that the protected-paths
digest recomputes, and that the protected files the branch changed are the ones listed; non-empty means a human.
Tested against a local signed-tag fixture, not yet on the real runner or required on main.

The pull-request stage now drives the forgejo model: pr_ensure opens the PR and the new pr_merge_state reads the merge
commit, time, and merger, so pull-request and merge evidence are copied from the API. implementation-conventions.md
is the implementing stage's constraints. REGISTRY_USERNAME and REGISTRY_PASSWORD are Actions secrets from the vault.
beddari deleted branch pr-validation-and-forge-wiring 2026-09-17 16:44:07 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/fabrikk!6
No description provided.