Hi Adam, Regarding the first point, I think we can improve the check by using GitHub's verified status as the source of truth instead of relying only on the local GPG/SSH signature check. I have used this approach in the backoffice UI, where we check GitHub's commit verification result and can also tell the contributor what exactly is wrong, such as an unknown signing key or unverified email.
By "pull request target", I meant using the pull_request_target event. This way, whenever a PR is opened or updated, the workflow from the base repository can automatically run the signature check and inform the contributor about any issue. The idea is to give contributors this feedback as soon as they create the PR, instead of depending on the approval workflow. I have implemented a similar approach in the backoffice UI. The relevant logic is in the check-commit-signatures script. Regards, Aman On Sun, Sep 20, 2026 at 5:12 AM Adam Monsen <[email protected]> wrote: > Hi Aman! > > On Wed, Sep 16, 2026 at 11:32 PM Aman Mittal <[email protected]> > wrote: > >> However, the check is failing. I think we can improve that. >> > > Improve it how? > > >> One more thing is that i think it would be better that instead of >> approval run we can make it run based on pull request target. >> > > What does this mean? > > Best, > -Adam > >>
