Skip to content

feat(workflows): add a reusable commit-email check for public repos - #34

Open
CameronBrooks11 wants to merge 1 commit into
mainfrom
feat/commit-email-check
Open

CameronBrooks11 wants to merge 1 commit into
mainfrom
feat/commit-email-check

Conversation

@CameronBrooks11

Copy link
Copy Markdown
Contributor

Summary

Adds .github/workflows/commit-email.yml, a reusable check for public repos. It fails when a commit that a PR or push adds is authored or committed with an address outside @flowmatrixai.com. It allows:

  • GitHub-assigned bot identities: [bot]@users.noreply.github.com and Copilot
  • noreply@github.com as the committer of a web-UI merge

It checks only the commits being added, never existing history, so adopting it requires no rewrite.

tests/commit-email.test.sh extracts the workflow's run: block and runs it against throwaway git repos, so the tested code is the shipped code.

Part of the commit-identity standard (eng-governance#132). This is new code for review.

Reach: callers pin this repo's workflows by digest, so adding a file here changes nothing for anyone. A public repo adopts the check by adding a caller workflow, as shown in the header comment.

Proof

$ bash tests/commit-email.test.sh
ok   - work-address commit passes (exit 0)
ok   - personal-address commit fails (exit 1)
ok   - work author, personal committer fails (exit 1)
ok   - bot identities pass (exit 0)
ok   - existing personal history is not re-checked (exit 0)
ok   - new-branch push (zero base) checks HEAD (exit 1)
ok   - personal commit below a work HEAD in the range fails (exit 1)

Mutation sweep. Each mutation was hash-checked to confirm it applied, and each is caught:

allowed() always true                -> personal-address / personal committer / zero-base cases FAIL
check author only (drop committer)   -> "work author, personal committer fails" FAIL
check HEAD only (ignore the range)   -> "personal commit below a work HEAD in the range fails" FAIL

shellcheck is clean on the extracted run: block and on the test.

The bot allowlist was taken from this repo's own history: renovate[bot] (author) / noreply@github.com (committer), and Copilot@users.noreply.github.com.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant