Ensure automated backport commits have verified signatures
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- git, github, javascript
Research direction
Read .github/scripts/backport.js and the approach in NVIDIA/nvidia-container-toolkit PR #2012, then inspect the compatibility described in #2992. Verify both clean backports and conflict-resolved backports through backport CI. Done means generated commits report verified: true, preserve their trees and messages, and retain existing PR creation and conflict handling.
Written by the indexing model from the issue text.
Description
The cherry-pick workflow currently creates backport commits locally and pushes them without signing. Recent automated backports report verified: false with reason unsigned, even when the original commits were signed.
This is incompatible with CI signature verification proposed in #2992 and branch protection requiring signed commits.
Update .github/scripts/backport.js to produce verified backport commits. Follow the approach implemented in nvidia-container-toolkit PR #2012:
- Recreate each cherry-picked commit through GitHub’s Git Data API, preserving its tree, message, and commit order.
- Update the backport branch to reference the resulting signed commit chain.
- Preserve existing PR creation and conflict-handling behavior.
This approach avoids managing a separate GPG or SSH signing key for the bot.
Acceptance criteria:
- GitHub reports verified: true for every generated backport commit.
- Backports preserve the expected changes and commit messages.
- Backport CI passes the signature-verification gate when enabled.
- Both clean backports and backports requiring manual conflict resolution remain supported.
- Dominant language
- Go
- Stars
- 2.9k
- Forks
- 565
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 78
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from NVIDIA/gpu-operator
-
Make NVIDIADriver node-pool rendering deterministicPossibly taken @efegokdemir claimed this 6 days ago. Opendsx-ws-0930 good-first-issue
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
NVIDIA/gpu-operator#2981 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug]: GPUCluster common name label breaks DRA validator selectorPossibly taken @ajavanma claimed this 14 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
NVIDIA/gpu-operator#2955 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug]: Latest Nvidia GPU Operator v26.7.1 reports large numbers of critical and high CVEs in Trivy scan outputPossibly taken @rahulait claimed this 6 days ago. Openmore-information-needed needs-triage
NVIDIA/gpu-operator#2991 · 3 comments · 1 assignee ·
Maintainers usually reply within 1 day
-
Verify the triggering commit before running other CI jobsPossibly taken A pull request linked to this issue is open or already merged. Opengood-first-issue
Difficulty 3/5 1-2 days Newbie friendliness 78/100
NVIDIA/gpu-operator#2990 ·
Maintainers usually reply within 1 day
-
Indicate number of nodes that an NVIDIADriver CR matchesPossibly taken @mrhillsman claimed this 6 days ago. Opendsx-ws-0930 good-first-issue
NVIDIA/gpu-operator#2980 · 2 comments · 1 assignee ·
Maintainers usually reply within 1 day
All issues in NVIDIA/gpu-operator
Similar issues
-
automation models
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
bug llm-stack needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Alert email subjects don't identify the host — same container on multiple hosts, identical subjectsOpen
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Maintainers usually reply within 1 day
-
P3 Type: Bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
grpc/grpc-go#9483 · 2 comments ·
Maintainers usually reply within 2 days
-
needs-area needs-kind needs-priority needs-status needs-triage
Difficulty 2/5 Under an hour Newbie friendliness 85/100
cncf/automation#736 ·
Maintainers usually reply within 1 day