Skip to content

ci: replace the suspended DCO app with a required signoff check we own #2566

Description

@cliffhall

Problem

The probot DCO app on this repo has been suspended, and its check quietly disappeared. The last PR with a DCO check was #1981 (merged 2026-08-12). None of the 242 PRs merged since then has one. Nothing failed or blocked, because DCO was never a required check:

  • v2/main has no branch protection and no ruleset applies to it (gh api repos/modelcontextprotocol/inspector/rules/branches/v2/main → []). That is the branch every v2 PR targets.
  • On main, the ruleset's only required status check is build.

Signoff has held anyway: all 1,058 non-merge commits on v2/main since 2026-08-13 carry a Signed-off-by: trailer. That is habit, not a gate. pr-flow step 3 and AGENTS.md still describe the DCO check as "a hard merge gate", which is no longer true.

Proposal

Replace the third-party app with a check we own, and make it required so a future outage blocks merges instead of passing silently.

  1. A DCO job in CI. For every commit in the PR's range, require a Signed-off-by: Name <email> trailer whose name and email match the commit's author or committer. Keep the app's two exemptions: merge commits and bot-authored commits. One unsigned commit fails the job, and its output names the commit and the git rebase --signoff repair.
    • main.yml triggers on push only, so it doesn't know a PR's base. A small separate workflow on pull_request (with github.event.pull_request.base.sha..head.sha, or gh api …/pulls/N/commits --paginate) is probably cleaner than inferring a merge-base in a push job. Use contents: read only, which keeps it outside the SHA-pin rule (SHA-pin the GitHub Actions that hold secrets or publish (claude-code-action, release job) #2484).
    • Declare timeout-minutes per the CI timeout rule.
    • If the logic is more than a few lines, put it in a scripts/*.mjs with a sibling *.test.mjs.
  2. Make it required. Add the job's check as a required status check in a ruleset that covers v2/main. That ruleset doesn't exist today, so this is a repo-admin settings change, not something the PR can do. Consider main too.
  3. Update the docs.
    • Rewrite pr-flow step 3 so it describes the new job instead of the probot app.
    • Drop the .github/dco.yml / remediation-commit / override-button discussion, which only applies to the app.
    • Adjust the "DCO check is a hard merge gate" wording in AGENTS.md if anything changes.
  4. Uninstall the probot app once the replacement is live, so the two can't disagree later.

Out of scope / notes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

choreMaintenance: deps, build tooling, CI, cleanup — no user-facing behavior changev2Issues and PRs for v2

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions