Ensure automated backport commits have verified signatures
Maintainer thường phản hồi trong vòng 1 ngày
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- git, github, javascript
Hướng nghiên cứu
Read .github/scripts/backport.js and the approach in NVIDIA/nvidia-container-toolkit PR #2012, then inspect the compatibility described in #2992. Verify both clean backports and conflict-resolved backports through backport CI. Done means generated commits report verified: true, preserve their trees and messages, and retain existing PR creation and conflict handling.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The cherry-pick workflow currently creates backport commits locally and pushes them without signing. Recent automated backports report verified: false with reason unsigned, even when the original commits were signed.
This is incompatible with CI signature verification proposed in #2992 and branch protection requiring signed commits.
Update .github/scripts/backport.js to produce verified backport commits. Follow the approach implemented in nvidia-container-toolkit PR #2012:
- Recreate each cherry-picked commit through GitHub’s Git Data API, preserving its tree, message, and commit order.
- Update the backport branch to reference the resulting signed commit chain.
- Preserve existing PR creation and conflict-handling behavior.
This approach avoids managing a separate GPG or SSH signing key for the bot.
Acceptance criteria:
- GitHub reports verified: true for every generated backport commit.
- Backports preserve the expected changes and commit messages.
- Backport CI passes the signature-verification gate when enabled.
- Both clean backports and backports requiring manual conflict resolution remain supported.
- Ngôn ngữ chính
- Go
- Star
- 2.9k
- Fork
- 565
- Merge trung bình
- 1 ngày 10 giờ
- Pull request đã merge (30 ngày)
- 78
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của NVIDIA/gpu-operator
-
Make NVIDIADriver node-pool rendering deterministicCó thể đã có người làm @efegokdemir đã nhận 6 ngày trước. Đang mởdsx-ws-0930 good-first-issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
NVIDIA/gpu-operator#2981 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: GPUCluster common name label breaks DRA validator selectorCó thể đã có người làm @ajavanma đã nhận 14 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
NVIDIA/gpu-operator#2955 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: Latest Nvidia GPU Operator v26.7.1 reports large numbers of critical and high CVEs in Trivy scan outputCó thể đã có người làm @rahulait đã nhận 6 ngày trước. Đang mởmore-information-needed needs-triage
NVIDIA/gpu-operator#2991 · 3 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Verify the triggering commit before running other CI jobsCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mởgood-first-issue
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 78/100
NVIDIA/gpu-operator#2990 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Indicate number of nodes that an NVIDIADriver CR matchesCó thể đã có người làm @mrhillsman đã nhận 6 ngày trước. Đang mởdsx-ws-0930 good-first-issue
NVIDIA/gpu-operator#2980 · 2 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của NVIDIA/gpu-operator
Issue tương tự
-
Helm IPv4 host checks accept addresses Go rejectsCó thể đã có người làm @ericcaiwx-star đã nhận hôm nay. Đang mởclawsweeper:bulk-filed clawsweeper:linked-pr-open clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:other issue-rating: 🦞 diamond lobster P2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
openclaw/openclaw-enterprise#1588 · 1 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
cvss-severity:high devguard l3montree-cybersecurity/devguard/devguard-web pkg:oci/devguard-web?rep...ch=amd64&tag=main-amd64 pkg:oci/devguard-web?rep...ch=arm64&tag=main-arm64 pkg:oci/web?repository_u...ch=amd64&tag=main-amd64 pkg:oci/web?repository_u...ch=arm64&tag=main-arm64 risk:low state:open
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
l3montree-dev/devguard#3168 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 1 ngày
-
status:approved type:bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Gentleman-Programming/gentle-ai#5326 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-acceptance wg/router-models-inference-runtime
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
vllm-project/semantic-router#4663 ·
Maintainer thường phản hồi trong vòng 1 ngày