Use GitHub Helper bot, fast-forward cookiecutter #156
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Pull Request Checklist:
number
) and pull request (:pull:number
) has been added.What kind of change does this PR introduce?
Does this PR introduce a breaking change?
No.
Other information:
"Why use a helper bot?"
Glad you asked. The commits that are coming from the workflow currently are "borrowing" a token I made then overwriting the committer information and, as such, the GPG signature is invalid. For security purposes, this makes it look like someone stole my account and committed changes pretending to be someone else, which is effectively what it is doing.
The helper bot is a verified way of indicating that these commits are genuine and coming from a verified source (by way of GPG signature). The bot makes a one-time-use token, creates a commit with it, pushes the changes, then destroys that token so that the risk of it leaking is diminished.