Skip to content
BETAGuardrails are in beta. The library, the configuration format and the CLI command can still change.

Guardrails / git

Commits come from a known identity

git/author-identity-domain@v1

Every commit in the build range was authored and committed by an address on a domain the organisation controls.

Idgit/author-identity-domain
Versionv1
Categorygit
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgit

Collectors

This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.

CollectorGathersInputs it is given
gitThe repository, HEAD, the remotes, and every commit between the base ref and HEAD with its message, author, parents and the files the range changed.baseRef

The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.

Configuration

json
{
  "guardrails": {
      "failOn": "error",
      "comment": true,
      "checks": [
          {
              "use": "git/author-identity-domain@v1",
              "severity": "warning",
              "with": {
                  "baseRef": "origin/main",
                  "domains": "",
                  "allowBots": "true"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs

InputDescriptionDefaultEnvironment variable
baseRefRef the range starts at. The commits checked are <baseRef>..HEAD.origin/mainGUARDRAIL_INPUT_BASEREF
domainsComma separated domains an address may be on. Empty means the guardrail skips, because it cannot know your domains.``GUARDRAIL_INPUT_DOMAINS
allowBotsWhether an address ending [bot]@users.noreply.github.com is accepted, for a commit an app authored.trueGUARDRAIL_INPUT_ALLOWBOTS

How to fix

Set the git identity to the address the organisation issued, in the repository or globally:

bash
git config user.email dana@acme.com

GitHub's users.noreply.github.com addresses are excluded by default because they cannot be joined to an identity provider, which is what makes a commit attributable to a person who can be recertified.

More in git

  • git/changed-files-budget. The build range changes few enough files that a reviewer can hold the whole change in their head.
  • git/conventional-commits. Every commit message in the build range follows the Conventional Commits specification: the subject line, the blank line before the body, and the BREAKING CHANGE footer.
  • git/no-merge-commits. The build range contains no merge commits.
  • git/no-wip-commits. The build range carries no commit that says it was never meant to be merged.
  • git/work-item-reference. Every commit in the build range, or the branch it is on, names the change record it belongs to.

All 6 git guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412