docs(security): add real reporting channel and fix stale repo names #108
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: PR Rules Enforcer | |
| on: | |
| push: | |
| branches: [main, develop] | |
| pull_request: | |
| branches: [main, develop] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| enforce-rules: | |
| name: "PR Rules Enforcer / Enforce Main Branch Rules" | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - name: Validate PR Source and Author | |
| env: | |
| EVENT_NAME: ${{ github.event_name }} | |
| BASE_REF: ${{ github.event.pull_request.base.ref }} | |
| HEAD_REF: ${{ github.event.pull_request.head.ref }} | |
| PR_USER: ${{ github.event.pull_request.user.login }} | |
| run: | | |
| if [ "$EVENT_NAME" = "pull_request" ] && [ "$BASE_REF" = "main" ]; then | |
| echo "PR HEAD ref: $HEAD_REF" | |
| echo "PR creator: $PR_USER" | |
| if [ "$HEAD_REF" != "develop" ]; then | |
| echo "::error::PRs to main must only come from the 'develop' branch. Found: '$HEAD_REF'." | |
| exit 1 | |
| fi | |
| if [ "$PR_USER" != "github-actions[bot]" ] && [ "$PR_USER" != "app/github-actions" ] && [ "$PR_USER" != "mendsec" ]; then | |
| echo "::error::PRs from 'develop' to 'main' must be created by 'github-actions[bot]' or maintainer. Manual PRs from unauthorized users are not allowed. Found: '$PR_USER'." | |
| exit 1 | |
| fi | |
| echo "✓ Source branch and author validation passed." | |
| else | |
| echo "Skipping PR source and author validation (event: '$EVENT_NAME', target: '$BASE_REF')." | |
| fi | |
| - name: Validate Commit Signatures | |
| env: | |
| HEAD_SHA: ${{ github.event.pull_request.head.sha }} | |
| run: | | |
| git fetch origin main | |
| HAS_UNSIGNED=0 | |
| while read -r sha || [ -n "$sha" ]; do | |
| if [ -z "$sha" ]; then | |
| continue | |
| fi | |
| if ! git cat-file -p "$sha" | grep -qE "^(gpgsig|gpgsig-sha256)"; then | |
| echo "::error::Commit $sha is NOT signed. All commits must be signed (SSH or GPG). Rule bypass is strictly forbidden." | |
| HAS_UNSIGNED=1 | |
| else | |
| echo "✓ Commit $sha has a signature." | |
| fi | |
| done < <(git log origin/main..${HEAD_SHA:-HEAD} --pretty=format:"%H") | |
| if [ "$HAS_UNSIGNED" -eq 1 ]; then | |
| echo "::error::Signature validation failed. Bypassing requirements or merging without satisfying status checks is strictly prohibited." | |
| exit 1 | |
| fi | |
| echo "✓ All commits are properly signed." |