Skip to content

Require author-matching DCO sign-offs on pull requests - #30

Merged
kwisatzh merged 1 commit into
mainfrom
ci/dco-signoff
Oct 8, 2026
Merged

kwisatzh merged 1 commit into
mainfrom
ci/dco-signoff

Conversation

@kwisatzh

@kwisatzh kwisatzh commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Check every PR commit for a final Signed-off-by trailer matching its author name and email.
  • Use read-only API access, pinned actions, and no checkout in the enforcement job.
  • Exempt only verified GitHub branch-update merges; reject incomplete or changing commit lists.
  • Report each failing commit and the signed repair commands.

Validation

  • 64 local sign-off, API failure, pagination, and merge-exemption tests passed.
  • Workflow lint passed.
  • The separate read-only test job exercises the same inline workflow code.

No application behavior changes. All commits are signed and signed off. The exact-match rule also applies to bot commits; a mismatched Dependabot author email and trailer will fail.

Signed-off-by: Vijay <evijay@gmail.com>
@kwisatzh
kwisatzh merged commit a4ad1d3 into main Oct 8, 2026
14 checks passed
@kwisatzh
kwisatzh deleted the ci/dco-signoff branch October 8, 2026 02:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant