Skip to content

require-signed-release: write the way forward on an unsigned verdict - #57

Merged
gronke merged 1 commit into
mainfrom
unsigned-guidance
Aug 24, 2026
Merged

require-signed-release: write the way forward on an unsigned verdict#57
gronke merged 1 commit into
mainfrom
unsigned-guidance

Conversation

@gronke

@gronke gronke commented Aug 24, 2026

Copy link
Copy Markdown
Owner

An unsigned verdict rehearses instead of failing, but the notice names no concrete next step. The opt-in unsigned-guidance input puts the exact companion commands into the step summary: fetch the tag, sign the companion on the release commit, push it. The companion's name derives from the attestation-tags glob, so v*-sig suggests vX.Y.Z-sig and the default glob suggests <tag>-sig. Pipelines that print their own guidance keep the plain notice.

An unsigned verdict rehearses instead of failing, but the notice names no concrete next step.
The opt-in unsigned-guidance input puts the exact companion commands into the step summary: fetch the tag, sign the companion on the release commit, push it.
The companion's name derives from the attestation-tags glob, so v*-sig suggests vX.Y.Z-sig and the default glob suggests <tag>-sig.
Pipelines that print their own guidance keep the plain notice.
@gronke
gronke force-pushed the unsigned-guidance branch from c72b644 to 8a3831c Compare August 24, 2026 13:17
@gronke
gronke merged commit a5f4823 into main Aug 24, 2026
20 checks passed
@gronke
gronke deleted the unsigned-guidance branch August 24, 2026 14:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant