Skip to content

chore: merge develop → main #54

chore: merge develop → main

chore: merge develop → main #54

name: PR Rules Enforcer
on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
enforce-rules:
name: Enforce Main Branch Rules
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Validate PR Source and Author
env:
HEAD_REF: ${{ github.event.pull_request.head.ref }}
PR_USER: ${{ github.event.pull_request.user.login }}
run: |
echo "PR HEAD ref: $HEAD_REF"
echo "PR creator: $PR_USER"
if [ "$HEAD_REF" != "develop" ]; then
echo "::error::PRs to main must only come from the 'develop' branch. Found: '$HEAD_REF'."
exit 1
fi
if [ "$PR_USER" != "github-actions[bot]" ] && [ "$PR_USER" != "app/github-actions" ]; then
echo "::error::PRs from 'develop' to 'main' must be created by 'github-actions[bot]'. Manual PRs are not allowed. Found: '$PR_USER'."
exit 1
fi
echo "✓ PR source branch and creator are valid."
- name: Validate Commit Signatures
env:
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
# Fetch main branch to check commits differences
git fetch origin main
# Check signatures of all commits in the PR branch
echo "Checking commits signature up to: $HEAD_SHA"
HAS_UNSIGNED=0
# Get the list of all commit SHAs in the PR branch not in main
while read -r sha || [ -n "$sha" ]; do
if [ -z "$sha" ]; then
continue
fi
# Check if the commit has a gpgsig header containing GPG/SSH signature
if git cat-file -p "$sha" | grep -q "^gpgsig"; then
echo "✓ Commit $sha has a signature."
else
echo "::error::Commit $sha is NOT signed. All commits in a PR to main must be signed (GPG or SSH)."
HAS_UNSIGNED=1
fi
done < <(git log origin/main..$HEAD_SHA --pretty=format:"%H")
if [ "$HAS_UNSIGNED" -eq 1 ]; then
exit 1
fi
echo "✓ All commits are properly signed."