From f8d312902c680fb66cf9b52006e53fbe44b8d314 Mon Sep 17 00:00:00 2001 From: 4mGLn Date: Tue, 8 Sep 2026 17:11:29 +0900 Subject: [PATCH 1/2] ci: sign upstream sync commits --- .github/workflows/upstream-sync.yml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.github/workflows/upstream-sync.yml b/.github/workflows/upstream-sync.yml index fd7593d..09ccb70 100644 --- a/.github/workflows/upstream-sync.yml +++ b/.github/workflows/upstream-sync.yml @@ -34,12 +34,27 @@ jobs: echo "changed_count=$changed_count" >> "$GITHUB_OUTPUT" echo "changed_csv=$changed_csv" >> "$GITHUB_OUTPUT" + - name: Configure signed commits + if: steps.sync.outputs.changed_count != '0' + env: + SIGNING_KEY: ${{ secrets.COMMIT_SIGNING_KEY }} + run: | + set -euo pipefail + install -d -m 700 ~/.ssh + printf '%s\n' "$SIGNING_KEY" > ~/.ssh/commit_signing_key + chmod 600 ~/.ssh/commit_signing_key + git config --global gpg.format ssh + git config --global user.signingkey ~/.ssh/commit_signing_key + git config --global commit.gpgsign true + - name: Create PR id: cpr if: steps.sync.outputs.changed_count != '0' uses: peter-evans/create-pull-request@v6 with: commit-message: "chore(upstream): sync portable PostgreSQL releases (${{ steps.sync.outputs.changed_csv }})" + author: "4mGLn <127629+4mGLn@users.noreply.github.com>" + committer: "4mGLn <127629+4mGLn@users.noreply.github.com>" title: "chore(upstream): sync portable PostgreSQL releases (${{ steps.sync.outputs.changed_csv }})" body: | This PR was created automatically. From 139b34157a337b6a9ddc046f8b8fbea231044772 Mon Sep 17 00:00:00 2001 From: 4mGLn Date: Mon, 14 Sep 2026 11:51:23 +0900 Subject: [PATCH 2/2] add credcheck extension overlay --- README.md | 1 + ci/postgresql-release-config.json | 8 ++++++++ 2 files changed, 9 insertions(+) diff --git a/README.md b/README.md index 3dc8a1b..2b20f71 100644 --- a/README.md +++ b/README.md @@ -23,6 +23,7 @@ Third-party extensions are built and released as separate overlay archives: - `pg_partman` - `pg_cron` - `pgvector` +- `credcheck` Each overlay archive is intended to be extracted over the matching base package for the same PostgreSQL version and target. diff --git a/ci/postgresql-release-config.json b/ci/postgresql-release-config.json index 721c199..3afb0bc 100644 --- a/ci/postgresql-release-config.json +++ b/ci/postgresql-release-config.json @@ -64,6 +64,14 @@ } }, "separate_extensions": { + "credcheck": { + "repo": "https://github.com/HexaCluster/credcheck.git", + "ref": "v5.0", + "notes": [ + "Requires shared_preload_libraries = 'credcheck'.", + "Enable with CREATE EXTENSION credcheck;" + ] + }, "pg_cron": { "repo": "https://github.com/citusdata/pg_cron.git", "ref": "v1.6.7",