Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Ensure automated backport commits have verified signatures

Open
#2,997 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

@asivanadi0 is already working on this.

Since Oct 2, 2026.

  • #2998 by @asivanadi0 — open

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
git, github, javascript
Domain
ci-cd, devops

Research direction

Read .github/scripts/backport.js and the approach in NVIDIA/nvidia-container-toolkit PR #2012, then inspect the compatibility described in #2992. Verify both clean backports and conflict-resolved backports through backport CI. Done means generated commits report verified: true, preserve their trees and messages, and retain existing PR creation and conflict handling.

Written by the indexing model from the issue text.

Description

good-first-issue

The cherry-pick workflow currently creates backport commits locally and pushes them without signing. Recent automated backports report verified: false with reason unsigned, even when the original commits were signed.

This is incompatible with CI signature verification proposed in #2992 and branch protection requiring signed commits.

Update .github/scripts/backport.js to produce verified backport commits. Follow the approach implemented in nvidia-container-toolkit PR #2012:

  • Recreate each cherry-picked commit through GitHub’s Git Data API, preserving its tree, message, and commit order.
  • Update the backport branch to reference the resulting signed commit chain.
  • Preserve existing PR creation and conflict-handling behavior.
    This approach avoids managing a separate GPG or SSH signing key for the bot.

Acceptance criteria:

  • GitHub reports verified: true for every generated backport commit.
  • Backports preserve the expected changes and commit messages.
  • Backport CI passes the signature-verification gate when enabled.
  • Both clean backports and backports requiring manual conflict resolution remain supported.
Dominant language
Go
Stars
2.9k
Forks
565
Avg merge
1d 10h
Merged PRs (30d)
78

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NVIDIA/gpu-operator

All issues in NVIDIA/gpu-operator

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.