Skip to content

Verify postil-cli commit signature before building from source - #9

Merged
morgaesis merged 1 commit into
mainfrom
add-commit-signature-verification
Jul 11, 2026
Merged

Verify postil-cli commit signature before building from source#9
morgaesis merged 1 commit into
mainfrom
add-commit-signature-verification

Conversation

@morgaesis

Copy link
Copy Markdown
Contributor

When prebuilt binaries are unavailable, the action falls back to building postil-cli from source via cargo. Without signature verification, a compromised postil-cli repository could run arbitrary code in CI with access to secrets. This verifies the target commit is GPG-signed by a trusted key before building, both in the composite action and in a dedicated CI job covering the signed and unsigned cases.

@morgaesis
morgaesis merged commit 9c8cf2c into main Jul 11, 2026
10 of 11 checks passed
@morgaesis
morgaesis deleted the add-commit-signature-verification branch July 11, 2026 03:37

@postil-dev postil-dev Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • error error .postil/provider:1 — Model provider unavailable · confidence 1.00 · kind: uncertainty

Model: moonshotai/kimi-k2.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant