Expose Commit Signing Status to the `GIT_PUSH` policy

We’re working on various security hardening efforts, and would love to be able to require verified commits be a precondition to spacelift planning/tracking a run.

For tracked runs we can get this as a side-effect of our github policy on main but for proposed runs on branches, this doesn’t appear to be possible.

This is valuable to us because it adds an additional layer of security in the case of any supply chain attack that results in malicious providers being proposed, since a malicious provider would still have access to the entire env.

Workaround
No
Problem
It is currently not possible to restrict `proposed` runs to verified commits.

Please authenticate to join the conversation.

Upvoters
Status

👀 In Review

Board

💡 Feature Requests

Tags

VCS

Date

About 3 hours ago

Subscribe to post

Get notified by email when there are changes.