Commits come from a known identity
git/author-identity-domain@v1
Every commit in the build range was authored and committed by an address on a domain the organisation controls.
| Id | git/author-identity-domain |
| Version | v1 |
| Category | git |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | git |
Collectors
This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.
| Collector | Gathers | Inputs it is given |
|---|---|---|
git | The repository, HEAD, the remotes, and every commit between the base ref and HEAD with its message, author, parents and the files the range changed. | baseRef |
The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.
Configuration
{
"guardrails": {
"failOn": "error",
"comment": true,
"checks": [
{
"use": "git/author-identity-domain@v1",
"severity": "warning",
"with": {
"baseRef": "origin/main",
"domains": "",
"allowBots": "true"
},
"exemptions": []
}
]
}
}2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
baseRef | Ref the range starts at. The commits checked are <baseRef>..HEAD. | origin/main | GUARDRAIL_INPUT_BASEREF |
domains | Comma separated domains an address may be on. Empty means the guardrail skips, because it cannot know your domains. | `` | GUARDRAIL_INPUT_DOMAINS |
allowBots | Whether an address ending [bot]@users.noreply.github.com is accepted, for a commit an app authored. | true | GUARDRAIL_INPUT_ALLOWBOTS |
How to fix
Set the git identity to the address the organisation issued, in the repository or globally:
git config user.email dana@acme.comGitHub's users.noreply.github.com addresses are excluded by default because they cannot be joined to an identity provider, which is what makes a commit attributable to a person who can be recertified.
More in git
git/changed-files-budget. The build range changes few enough files that a reviewer can hold the whole change in their head.git/conventional-commits. Every commit message in the build range follows the Conventional Commits specification: the subject line, the blank line before the body, and the BREAKING CHANGE footer.git/no-merge-commits. The build range contains no merge commits.git/no-wip-commits. The build range carries no commit that says it was never meant to be merged.git/work-item-reference. Every commit in the build range, or the branch it is on, names the change record it belongs to.