Skip to content

Conversation

ciarams87
Copy link
Contributor

@ciarams87 ciarams87 commented Sep 17, 2025

Proposed changes

Problem: We need to add the generation and publishing of a signed assertion document to our workflow. The goal of the signed assertion document is to provide a customer facing document that provides provenance for a build artifact. The document will contain information about each dependency included in the build and specifically will contain the signed acquisition document for each process. This will also be signed to guarantee that F5 is the source of the document.

Solution: Use the actions provided by compliance-rules to generate and sign the assertion document

Testing: See https://github.com/nginx/nginx-gateway-fabric/actions/runs/18093624043/job/51480400063

Checklist

Before creating a PR, run through this checklist and mark each as complete.

  • I have read the CONTRIBUTING doc
  • I have added tests that prove my fix is effective or that my feature works
  • I have checked that all unit tests pass after adding my changes
  • I have updated necessary documentation
  • I have rebased my branch onto main
  • I will ensure my PR is targeting the main branch and pulling from my branch from my own fork

Release notes

If this PR introduces a change that affects users and needs to be mentioned in the release notes,
please add a brief note that summarizes the change.

NONE

@github-actions github-actions bot added the chore Pull requests for routine tasks label Sep 17, 2025
Copy link

codecov bot commented Sep 17, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 86.77%. Comparing base (a2ee4c4) to head (bd529ba).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3929      +/-   ##
==========================================
- Coverage   86.82%   86.77%   -0.06%     
==========================================
  Files         128      128              
  Lines       16607    16607              
  Branches       62       62              
==========================================
- Hits        14419    14410       -9     
- Misses       2005     2012       +7     
- Partials      183      185       +2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Copy link

@jjngx jjngx left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏻

@ciarams87 ciarams87 force-pushed the chore/assertion-doc branch 17 times, most recently from e7d4804 to 795fdef Compare September 22, 2025 11:17
@ciarams87 ciarams87 force-pushed the chore/assertion-doc branch 5 times, most recently from 1da6167 to 58ecd2f Compare September 23, 2025 12:05
@ciarams87 ciarams87 marked this pull request as ready for review September 29, 2025 11:39
@ciarams87 ciarams87 requested a review from a team as a code owner September 29, 2025 11:39
@ciarams87 ciarams87 merged commit cf38a6f into main Sep 30, 2025
67 of 68 checks passed
@ciarams87 ciarams87 deleted the chore/assertion-doc branch September 30, 2025 08:57
@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in NGINX Gateway Fabric Sep 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
chore Pull requests for routine tasks
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

4 participants