This is an automated email from the ASF dual-hosted git repository.
ppkarwasz pushed a commit to branch gha/v0
in repository https://gitbox.apache.org/repos/asf/logging-parent.git
The following commit(s) were added to refs/heads/gha/v0 by this push:
new ecd8142 Sign site commits only if a GPG key is provided (#494)
ecd8142 is described below
commit ecd8142e8f6925fa83b22528f317aa4d35a08227
Author: Piotr P. Karwasz <[email protected]>
AuthorDate: Wed Jul 22 14:16:11 2026 +0200
Sign site commits only if a GPG key is provided (#494)
Make `GPG_SECRET_KEY` optional in `deploy-site-reusable` and drive
commit signing through `commit.gpgsign` instead of hardcoded
`git commit -S` flags. Callers that do not need signed commits no
longer have to expose their GPG key to the site deployment job.
Assisted-By: Claude Fable 5 <[email protected]>
---
.github/workflows/deploy-site-reusable.yaml | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/.github/workflows/deploy-site-reusable.yaml
b/.github/workflows/deploy-site-reusable.yaml
index e19f7f7..20fa019 100644
--- a/.github/workflows/deploy-site-reusable.yaml
+++ b/.github/workflows/deploy-site-reusable.yaml
@@ -42,8 +42,8 @@ on:
type: string
secrets:
GPG_SECRET_KEY:
- description: GPG secret key for signing commits
- required: true
+ description: GPG secret key for signing commits (if absent, commits
will not be signed)
+ required: false
# Explicitly drop all permissions inherited from the caller for security.
# Reference:
https://docs.github.com/en/actions/sharing-automations/reusing-workflows#access-and-permissions
@@ -104,10 +104,14 @@ jobs:
- name: Set up Git user
shell: bash
+ env:
+ GPG_KEY_PRESENT: ${{ secrets.GPG_SECRET_KEY != '' }}
run: |
# Set up user name and email required for `git commit`
git config user.name "ASF Logging Services RM"
git config user.email [email protected]
+ # Sign commits only if a GPG key is available
+ git config --type bool commit.gpgsign "$GPG_KEY_PRESENT"
# Checking out a new branch will delete the `node_modules` folder,
# so we need to save the cache here.
@@ -127,7 +131,7 @@ jobs:
git checkout --orphan "$TARGET_BRANCH"
echo "Content for initializing an orphan branch for the website to
be generated from \`$SOURCE_COMMIT_ID\`" > README.txt
git add README.txt
- git commit -S README.txt -m "Initial content for the website to be
generated from \`$SOURCE_COMMIT_ID\`"
+ git commit README.txt -m "Initial content for the website to be
generated from \`$SOURCE_COMMIT_ID\`"
git push origin "$TARGET_BRANCH"
}
@@ -163,7 +167,7 @@ jobs:
if [ -n "$(git status --porcelain)" ]; then
# Commit & push site changes
- git commit -S -a -m "Add website content generated from
\`$SOURCE_COMMIT_ID\`"
+ git commit -a -m "Add website content generated from
\`$SOURCE_COMMIT_ID\`"
git push -f origin
# Populate `.asf.yaml`
@@ -180,7 +184,7 @@ jobs:
# - Timestamp: $(date --utc '+%Y-%m-%dT%H:%M:%SZ')
EOF
git add .asf.yaml
- git commit -S .asf.yaml -m "Add \`.asf.yaml\` along with an INFRA
fix for the website content generated from \`$SOURCE_COMMIT_ID\`"
+ git commit .asf.yaml -m "Add \`.asf.yaml\` along with an INFRA fix
for the website content generated from \`$SOURCE_COMMIT_ID\`"
# Push changes *separately*!
# A separate small commit push necessary due to the INFRA issue
explained above.