Skip to content

[Due for payment 2026-01-23] [$125] verifySignedCommits doesn't paginate commits and can thus miss unsigned commits #78960

Description

@francoisl

Problem

The verifySignedCommits workflow doesn't paginate commits, so if a PR has more than 30 commits (default value for per_page), it doesn't properly detect unsigned commits after the 30th.

Repro steps

  1. Create a fresh branch
  2. Create 30 signed commits, then an unsigned one (this assumes your git config already has signature enabled by default)
    # Create 30 signed commits on a new branch
    for i in {1..30}; do
        git commit --allow-empty -m "Test commit $i"
    done
    
    # Create an unsigned commit
    git commit --no-gpg-sign --allow-empty -m "Unsigned commit test"
  3. Run the verifySignedCommits workflow
  4. Notice that it passes

Example PR – workflow passes despite unsigned 31st commit

Solution

Use octokit's pagination functionality to get all commits on the PR.

Upwork Automation - Do Not Edit
  • Upwork Job URL: https://www.upwork.com/jobs/~022008688139822676909
  • Upwork Job ID: 2008688139822676909
  • Last Price Increase: 2026-01-06
  • Automatic offers:
    • linhvovan29546 | Reviewer | 110029544
Issue OwnerCurrent Issue Owner: @
Issue OwnerCurrent Issue Owner: @CortneyOfstad

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Awaiting PaymentAuto-added when associated PR is deployed to productionBugSomething is broken. Auto assigns a BugZero manager.DailyKSv2ExternalAdded to denote the issue can be worked on by a contributorImprovementItem broken or needs improvement.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions