diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml deleted file mode 100644 index c48c4bc..0000000 --- a/.github/workflows/merge.yml +++ /dev/null @@ -1,51 +0,0 @@ -name: Fast-Forward Merge - -on: - issue_comment: - types: [created] - -jobs: - merge: - if: ${{ github.event.issue.pull_request && github.event.comment.body == '/m' }} - runs-on: ubuntu-latest - steps: - - name: Generate Token - id: get_token - uses: actions/create-github-app-token@v1 - with: - app-id: ${{ secrets.APP_ID }} - private-key: ${{ secrets.APP_PRIVATE_KEY }} - - - name: Checkout - uses: actions/checkout@v4 - with: - token: ${{ steps.get_token.outputs.token }} - fetch-depth: 0 - - - name: Fetch Target Branch - id: pr - env: - GH_TOKEN: ${{ steps.get_token.outputs.token }} - run: | - # We only need the base branch name (e.g., main) to know where to push - PR_DATA=$(gh pr view ${{ github.event.issue.number }} --json baseRefName) - echo "base=$(echo "$PR_DATA" | jq -r .baseRefName)" >> $GITHUB_OUTPUT - - - name: Configure Git - run: | - git config --global user.name "github-actions[bot]" - git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com" - - - name: Merge - run: | - # 1. Fetch the exact PR commit into a temporary local branch named 'pr-branch' - git fetch origin pull/${{ github.event.issue.number }}/head:pr-branch - - # 2. Checkout the target base branch (e.g., main) - git checkout ${{ steps.pr.outputs.base }} - - # 3. Perform the fast-forward merge from the temporary branch - git merge --ff-only pr-branch - - # 4. Push to the protected branch using the App token - git push origin ${{ steps.pr.outputs.base }} diff --git a/.github/workflows/team-approve.yml b/.github/workflows/team-approve.yml deleted file mode 100644 index 2625ed2..0000000 --- a/.github/workflows/team-approve.yml +++ /dev/null @@ -1,60 +0,0 @@ -name: Require Team Approval - -on: - pull_request_review: - types: [submitted, dismissed] - pull_request_target: - types: [opened, synchronize, reopened] - -jobs: - check-approval: - runs-on: ubuntu-latest - steps: - - name: Generate Token - id: get_token - uses: actions/create-github-app-token@v1 - with: - app-id: ${{ secrets.APP_ID }} - private-key: ${{ secrets.APP_PRIVATE_KEY }} - owner: ${{ github.repository_owner }} - - - name: Verify and Auto-Approve - env: - GH_TOKEN: ${{ steps.get_token.outputs.token }} - run: | - ORG="${{ github.repository_owner }}" - TEAM="${{ github.event.repository.name }}" - PR="${{ github.event.pull_request.number }}" - AUTHOR="${{ github.event.pull_request.user.login }}" - - # 1. Check if the PR author is a maintainer - if gh api orgs/$ORG/teams/$TEAM/memberships/$AUTHOR > /dev/null 2>&1; then - echo "Author is a maintainer. Having the bot submit an official approval..." - - # The bot physically approves the PR, satisfying GitHub's native UI requirements - gh pr review $PR --approve --body "🤖 **Auto-Approved:** PR authored by an authorized maintainer (@$AUTHOR)." - - exit 0 - fi - - # 2. If the author is NOT a maintainer, check if a maintainer has manually approved it - APPROVERS=$(gh api repos/$ORG/$TEAM/pulls/$PR/reviews --jq '.[] | select(.state == "APPROVED") | .user.login' | sort -u) - - if [ -z "$APPROVERS" ]; then - echo "No approvals found." - exit 1 - fi - - APPROVED=false - for USER in $APPROVERS; do - if gh api orgs/$ORG/teams/$TEAM/memberships/$USER > /dev/null 2>&1; then - echo "Approved by authorized maintainer: @$USER" - APPROVED=true - break - fi - done - - if [ "$APPROVED" = false ]; then - echo "Approvals found, but none are from the authorized maintainer team." - exit 1 - fi diff --git a/.github/workflows/team-sigs.yml b/.github/workflows/team-sigs.yml deleted file mode 100644 index b1284e9..0000000 --- a/.github/workflows/team-sigs.yml +++ /dev/null @@ -1,63 +0,0 @@ -name: Verify Team Signature - -on: - pull_request_target: - types: [opened, synchronize, reopened] - -jobs: - verify-signatures: - runs-on: ubuntu-latest - steps: - - name: Generate Token - id: get_token - uses: actions/create-github-app-token@v1 - with: - app-id: ${{ secrets.APP_ID }} - private-key: ${{ secrets.APP_PRIVATE_KEY }} - owner: ${{ github.repository_owner }} - - - name: Checkout Target Repo - uses: actions/checkout@v4 - with: - path: target-repo - fetch-depth: 0 - - - name: Checkout Sigs Repo - uses: actions/checkout@v4 - with: - repository: oreonhq/team-sigs - path: team-sigs - token: ${{ steps.get_token.outputs.token }} - - - name: Verify Commits - env: - GH_TOKEN: ${{ steps.get_token.outputs.token }} - run: | - cd target-repo - - # Fetch the exact PR commits - git fetch origin pull/${{ github.event.pull_request.number }}/head - - # 1. Import all team GPG public keys into the runner's fresh keyring - echo "Importing team GPG keys..." - for KEY_FILE in ../team-sigs/*.txt; do - if [ -f "$KEY_FILE" ]; then - gpg --import "$KEY_FILE" - fi - done - - # 2. Verify each commit - COMMITS=$(gh pr view ${{ github.event.pull_request.number }} --json commits --jq '.commits[].oid') - - for COMMIT in $COMMITS; do - echo "Verifying commit $COMMIT..." - - # git verify-commit will check the signature against the keys we just imported. - # If the commit was signed by ANY team member's key, it passes. - if ! git verify-commit $COMMIT; then - echo "❌ Error: Cryptographic verification failed for commit $COMMIT." - exit 1 - fi - - echo "✅ Commit $COMMIT verified successfully." - done