Skip to content

Guardrails / git

Commits come from a known identity ​

git/author-identity-domain@v1

Every commit in the build range was authored and committed with an email address on a domain your organisation controls.

Idgit/author-identity-domain
Versionv1
Categorygit
Default severitywarning
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsgit

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
gitThe repository, HEAD, the remotes, and every commit between the base ref and HEAD with its message, author, parents, and the files the range changed with the lines it added and removed to each.baseRef

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "git/author-identity-domain@v1",
              "severity": "warning",
              "with": {
                  "baseRef": "origin/main",
                  "domains": "",
                  "allowBots": "true"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
baseRefRef the range starts at. The commits checked are <baseRef>..HEAD.origin/mainGUARDRAIL_INPUT_BASEREF
domainsComma separated domains an address may be on. If empty, the guardrail skips, because it can't know your domains.``GUARDRAIL_INPUT_DOMAINS
allowBotsWhether an address ending in [bot]@users.noreply.github.com is accepted, for commits authored by an app.trueGUARDRAIL_INPUT_ALLOWBOTS

How to fix ​

Set your git identity to the email address your organisation issued, either for the repository or globally:

bash
git config user.email dana@company.com

GitHub's users.noreply.github.com addresses are excluded by default because they can't be matched to an identity provider, and that match is what ties a commit to a person whose access can be recertified.

More in git ​

  • git/changed-files-budget. The build range changes few enough files that a reviewer can hold the whole change in their head.
  • git/changed-lines-budget. The build range adds and removes few enough lines that a reviewer can read the whole change before approving it.
  • git/conventional-commits. Every commit message in the build range follows the Conventional Commits specification, including the subject line, the blank line before the body, and the BREAKING CHANGE footer.
  • git/no-merge-commits. The build range contains no merge commits.
  • git/no-wip-commits. The build range contains no commit whose subject says it was never meant to be merged.
  • git/work-item-reference. Every commit in the build range, or the branch it is on, references the change record it belongs to.

All 7 git guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412