fix: use verified release signing identity #112
No reviewers
Labels
No labels
bug
duplicate
enhancement
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Slipstream/emc!112
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/release-pr-signing-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Rationale
Run #269 proved the wrapper created a signed commit, but Forgejo still rejected it as unverified. The remaining mismatch is the commit identity used for the signature verification path. Using the identity tied to the signing key should let Forgejo verify the release PR commit.
Verification
This PR updates the release workflow to use a verified signing identity, addressing an issue where commits were previously rejected as unverified. The changes appear safe to merge, with optional variables added for flexibility in signing identity configuration.
Walkthrough
RELEASE_SIGNING_NAMEandRELEASE_SIGNING_EMAILas environment variables to allow for customizable signing identities.RELEASE_SIGNING_NAMEandRELEASE_SIGNING_EMAIL, explaining their purpose and default behavior.LLM usage and cost
Estimated total USD: $0.010531 via https://api.openai.com and https://api.openai.com