Skip to main content

Module resign

Module resign 

Source
Expand description

The GitHub half of the Dependabot re-sign (§9, “Dependabot re-sign bot”).

verify-trust exempts a web-flow-signed commit only when it is a clean merge, so Dependabot’s single-parent commits fail the check: nothing in a commit binds it to Dependabot (any writer can have GitHub write and sign a commit with any author through the Contents API). The bridge re-signs them with its own DID instead — but only on provenance from signed push webhooks, never on authorship: every push to the branch since its creation must have come from Dependabot, or be the bridge’s own re-sign.

This module is what the bridge needs from GitHub for that:

  • GitHubForge::parse_push: verify a delivery (signature first) and, if it is a push, the fields the provenance ledger records — who pushed (login and numeric id), the branch, before / after, and the created / deleted / forced flags. The sender is GitHub’s statement of the authenticated actor; nothing in the pushed commits is read.
  • GitHubForge::contents_write_token: a token that can push to one repository, for the one force-push of the re-signed commits.

Who opened the pull request, and where its head is, come from GitHubForge::pull_request.

Structs§

PushEvent
One verified push delivery.

Constants§

ZERO_SHA
The all-zero object id GitHub reports as before for a created branch and as after for a deleted one.