You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
ci: replace the suspended DCO app with a required signoff check we own #2566
The probot DCO app on this repo has been suspended, and its check quietly disappeared. The last PR with a DCO check was #1981 (merged 2026-08-12). None of the 242 PRs merged since then has one. Nothing failed or blocked, because DCO was never a required check:
v2/main has no branch protection and no ruleset applies to it (gh api repos/modelcontextprotocol/inspector/rules/branches/v2/main → []). That is the branch every v2 PR targets.
On main, the ruleset's only required status check is build.
Signoff has held anyway: all 1,058 non-merge commits on v2/main since 2026-08-13 carry a Signed-off-by: trailer. That is habit, not a gate. pr-flow step 3 and AGENTS.md still describe the DCO check as "a hard merge gate", which is no longer true.
Proposal
Replace the third-party app with a check we own, and make it required so a future outage blocks merges instead of passing silently.
A DCO job in CI. For every commit in the PR's range, require a Signed-off-by: Name <email> trailer whose name and email match the commit's author or committer. Keep the app's two exemptions: merge commits and bot-authored commits. One unsigned commit fails the job, and its output names the commit and the git rebase --signoff repair.
main.yml triggers on push only, so it doesn't know a PR's base. A small separate workflow on pull_request (with github.event.pull_request.base.sha..head.sha, or gh api …/pulls/N/commits --paginate) is probably cleaner than inferring a merge-base in a push job. Use contents: read only, which keeps it outside the SHA-pin rule (SHA-pin the GitHub Actions that hold secrets or publish (claude-code-action, release job) #2484).
Declare timeout-minutes per the CI timeout rule.
If the logic is more than a few lines, put it in a scripts/*.mjs with a sibling *.test.mjs.
Make it required. Add the job's check as a required status check in a ruleset that covers v2/main. That ruleset doesn't exist today, so this is a repo-admin settings change, not something the PR can do. Consider main too.
Update the docs.
Rewrite pr-flow step 3 so it describes the new job instead of the probot app.
Drop the .github/dco.yml / remediation-commit / override-button discussion, which only applies to the app.
Adjust the "DCO check is a hard merge gate" wording in AGENTS.md if anything changes.
Uninstall the probot app once the replacement is live, so the two can't disagree later.
Problem
The probot DCO app on this repo has been suspended, and its check quietly disappeared. The last PR with a DCO check was #1981 (merged 2026-08-12). None of the 242 PRs merged since then has one. Nothing failed or blocked, because DCO was never a required check:
v2/mainhas no branch protection and no ruleset applies to it (gh api repos/modelcontextprotocol/inspector/rules/branches/v2/main→[]). That is the branch every v2 PR targets.main, the ruleset's only required status check isbuild.Signoff has held anyway: all 1,058 non-merge commits on
v2/mainsince 2026-08-13 carry aSigned-off-by:trailer. That is habit, not a gate.pr-flowstep 3 and AGENTS.md still describe the DCO check as "a hard merge gate", which is no longer true.Proposal
Replace the third-party app with a check we own, and make it required so a future outage blocks merges instead of passing silently.
Signed-off-by: Name <email>trailer whose name and email match the commit's author or committer. Keep the app's two exemptions: merge commits and bot-authored commits. One unsigned commit fails the job, and its output names the commit and thegit rebase --signoffrepair.main.ymltriggers onpushonly, so it doesn't know a PR's base. A small separate workflow onpull_request(withgithub.event.pull_request.base.sha..head.sha, orgh api …/pulls/N/commits --paginate) is probably cleaner than inferring a merge-base in a push job. Usecontents: readonly, which keeps it outside the SHA-pin rule (SHA-pin the GitHub Actions that hold secrets or publish (claude-code-action, release job) #2484).timeout-minutesper the CI timeout rule.scripts/*.mjswith a sibling*.test.mjs.v2/main. That ruleset doesn't exist today, so this is a repo-admin settings change, not something the PR can do. Considermaintoo.pr-flowstep 3 so it describes the new job instead of the probot app..github/dco.yml/ remediation-commit / override-button discussion, which only applies to the app.Out of scope / notes
v1/mainhas its own workflows and its own ruleset. Its four commits since 2026-08-13 with no trailer (fix(deps): bump js-yaml overrides to patched 3.15.1 / 4.3.1 #2073, fix(deps): clear remaining npm audit advisories #2075, chore: deny esbuild and fsevents install scripts #2077, chore: bump version to 1.0.2 #2081) look like squash merges whose message dropped the signoff. The app would never have checked those either. If v1 needs the same check, file it separately.