Skip to content

Repository files navigation

git-sha-verify

codecov

A simple utility to verify and checkout trusted git commits signed using GPG key.
This tool helps ensure that only authorized or validated commit hashes are checked out from a git repository, supporting better code integrity and security within the workflow.

Contribute

This project lives in https://github.com/openSUSE/git-sha-verify

Feel free to add issues in github or send pull requests.

Rules for commits

  • For git commit messages use the rules stated on How to Write a Git Commit Message as a reference.
  • Run make tidy before committing changes to format code according to our standards. Preferably also run other tests as described in the subsequent section.
  • As a SUSE colleague consider signing commits which we consider to use for automatic deployments within SUSE.

If this is too much hassle for you feel free to provide incomplete pull requests for consideration or create an issue with a code change proposal.

Local testing

Ensure you have the dependencies for development installed. The easiest way to install dependencies and run tests is with uv:

uv run make test

Alternatively if you are in an environment already providing all necessary dependencies run make test or pytest to execute Python-based unit tests.

Run make checkstyle to check coding style and make tidy for automated formatting.

License

This project is licensed under the MIT license, see LICENSE file for details. Some exceptions apply and are marked accordingly.

About

Verify and checkout trusted git commit

Resources

Stars

4 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages