Expand description
The GitHub half of the Dependabot re-sign (§9, “Dependabot re-sign bot”).
verify-trust exempts a web-flow-signed commit only when it is a clean
merge, so Dependabot’s single-parent commits fail the check: nothing in
a commit binds it to Dependabot (any writer can have GitHub write and
sign a commit with any author through the Contents API). The bridge
re-signs them with its own DID instead — but only on provenance from
signed push webhooks, never on authorship: every push to the branch
since its creation must have come from Dependabot, or be the bridge’s own
re-sign.
This module is what the bridge needs from GitHub for that:
GitHubForge::parse_push: verify a delivery (signature first) and, if it is apush, the fields the provenance ledger records — who pushed (login and numeric id), the branch,before/after, and thecreated/deleted/forcedflags. The sender is GitHub’s statement of the authenticated actor; nothing in the pushed commits is read.GitHubForge::contents_write_token: a token that can push to one repository, for the one force-push of the re-signed commits.
Who opened the pull request, and where its head is, come from
GitHubForge::pull_request.
Structs§
- Push
Event - One verified
pushdelivery.
Constants§
- ZERO_
SHA - The all-zero object id GitHub reports as
beforefor a created branch and asafterfor a deleted one.