Skip to content

ci: enforce the DCO with a workflow the repository owns - #1

Merged
Alex (Alexkuva) merged 1 commit into
mainfrom
ci/dco-workflow
Oct 1, 2026
Merged

Alex (Alexkuva) merged 1 commit into
mainfrom
ci/dco-workflow

Conversation

@Alexkuva

Copy link
Copy Markdown
Contributor

Enforces the DCO again, with a workflow this repository owns.

.github/dco.yml configured the third-party DCO app, which is no longer installed: nothing has
verified sign-offs on pull requests since.

  • .github/workflows/dco.yml checks that every commit of a pull request carries a
    Signed-off-by trailer naming its author, skipping merge commits and bot accounts — Dependabot
    included —, and fails with the SHA of each commit that does not. It runs as it is on main
    (pull_request_target), so a pull request cannot edit the check that judges it, and it never
    checks out the pull request's code. Unlike the app, it has no button that sets the check to
    pass.
  • .github/dco.yml is deleted.
  • CONTRIBUTING.md: the DCO passage now explains -s versus -S, names the DCO check as
    the final word, and fixes several commits with git rebase --signoff origin/main, instead of
    the app's remediation instructions.

It is the workflow the Kaiten licensing pack ships to every repository, unchanged; sdk-python
runs it already.

After merging: the workflow runs from main, so it starts with the next pull request. Then
add DCO to the default-branch ruleset's required checks, with GitHub Actions as its source.

🤖 Generated with Claude Code · ✅ Tested and approved by Alex (@Alexkuva), maintainer

.github/dco.yml configured the third-party DCO app, which is no longer
installed: no check verified sign-offs on pull requests any more.

.github/workflows/dco.yml takes its place. It checks that every commit of
a pull request carries a Signed-off-by trailer naming its author, skipping
merge commits and bot accounts, and fails with the SHA of each commit that
does not. It runs as it is on main (pull_request_target), so a pull request
cannot edit the check that judges it, and it never checks out the pull
request's code: it reads commit metadata from the API. Unlike the app, it
has no button that sets the check to pass.

CONTRIBUTING.md's DCO passage follows: -s versus -S, the DCO check as the
final word, and git rebase --signoff for several commits, instead of the
app's remediation instructions.

The workflow is the one the Kaiten licensing pack ships to every
repository, unchanged.

Signed-off-by: Alexandre Bergere <alexandre.bergere@kaiten.sh>
@Alexkuva
Alex (Alexkuva) requested a review from a team as a code owner October 1, 2026 08:07
@Alexkuva
Alex (Alexkuva) merged commit 48b22d6 into main Oct 1, 2026
10 checks passed
@Alexkuva
Alex (Alexkuva) deleted the ci/dco-workflow branch October 1, 2026 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants