Skip to content

docs(security): add real reporting channel and fix stale repo names #108

docs(security): add real reporting channel and fix stale repo names

docs(security): add real reporting channel and fix stale repo names #108

name: PR Rules Enforcer
on:
push:
branches: [main, develop]
pull_request:
branches: [main, develop]
workflow_dispatch:
permissions:
contents: read
jobs:
enforce-rules:
name: "PR Rules Enforcer / Enforce Main Branch Rules"
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Validate PR Source and Author
env:
EVENT_NAME: ${{ github.event_name }}
BASE_REF: ${{ github.event.pull_request.base.ref }}
HEAD_REF: ${{ github.event.pull_request.head.ref }}
PR_USER: ${{ github.event.pull_request.user.login }}
run: |
if [ "$EVENT_NAME" = "pull_request" ] && [ "$BASE_REF" = "main" ]; then
echo "PR HEAD ref: $HEAD_REF"
echo "PR creator: $PR_USER"
if [ "$HEAD_REF" != "develop" ]; then
echo "::error::PRs to main must only come from the 'develop' branch. Found: '$HEAD_REF'."
exit 1
fi
if [ "$PR_USER" != "github-actions[bot]" ] && [ "$PR_USER" != "app/github-actions" ] && [ "$PR_USER" != "mendsec" ]; then
echo "::error::PRs from 'develop' to 'main' must be created by 'github-actions[bot]' or maintainer. Manual PRs from unauthorized users are not allowed. Found: '$PR_USER'."
exit 1
fi
echo "✓ Source branch and author validation passed."
else
echo "Skipping PR source and author validation (event: '$EVENT_NAME', target: '$BASE_REF')."
fi
- name: Validate Commit Signatures
env:
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
git fetch origin main
HAS_UNSIGNED=0
while read -r sha || [ -n "$sha" ]; do
if [ -z "$sha" ]; then
continue
fi
if ! git cat-file -p "$sha" | grep -qE "^(gpgsig|gpgsig-sha256)"; then
echo "::error::Commit $sha is NOT signed. All commits must be signed (SSH or GPG). Rule bypass is strictly forbidden."
HAS_UNSIGNED=1
else
echo "✓ Commit $sha has a signature."
fi
done < <(git log origin/main..${HEAD_SHA:-HEAD} --pretty=format:"%H")
if [ "$HAS_UNSIGNED" -eq 1 ]; then
echo "::error::Signature validation failed. Bypassing requirements or merging without satisfying status checks is strictly prohibited."
exit 1
fi
echo "✓ All commits are properly signed."