fix: update repository references after reqsign rename - #885
Merged
Merged
Conversation
Xuanwo
marked this pull request as ready for review
September 25, 2026 09:48
PsiACE
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
After the repository was renamed to
apache/reqsign, CI bootstrap commands, release tooling, and package metadata still referenced the former name. Update those references and make the AWS trust template match the repository's current immutable OIDC subjects.Published crate manifests retain their historical repository URL. Accept that exact legacy URL when auditing crate metadata while requiring Trusted Publishers to target
apache/reqsign.The external AWS, Azure, and Google identity bindings were migrated separately. AWS, Azure, and Google live tests passed on
25629e59bdb1744edf0ae5e8d41c76877c36e73b; these runs validate the cloud configuration changes, not this PR's head. The independent Azure DevOps bootstrap clone URL was also updated, and fetching from the canonical repository URL was verified separately.