Hi Adam,

Regarding the first point, I think we can improve the check by using
GitHub's verified status as the source of truth instead of relying only on
the local GPG/SSH signature check. I have used this approach in the
backoffice UI, where we check GitHub's commit verification result and can
also tell the contributor what exactly is wrong, such as an unknown signing
key or unverified email.

By "pull request target", I meant using the pull_request_target event. This
way, whenever a PR is opened or updated, the workflow from the base
repository can automatically run the signature check and inform the
contributor about any issue.

The idea is to give contributors this feedback as soon as they create the
PR, instead of depending on the approval workflow.

I have implemented a similar approach in the backoffice UI. The relevant
logic is in the check-commit-signatures script.

Regards,
Aman

On Sun, Sep 20, 2026 at 5:12 AM Adam Monsen <[email protected]> wrote:

> Hi Aman!
>
> On Wed, Sep 16, 2026 at 11:32 PM Aman Mittal <[email protected]>
> wrote:
>
>> However, the check is failing. I think we can improve that.
>>
>
> Improve it how?
>
>
>> One more thing is that i think it would be better that instead of
>> approval run we can make it run based on pull request target.
>>
>
> What does this mean?
>
> Best,
> -Adam
>
>>

Reply via email to