You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
ci: make DCO a required status check on v2/main (ruleset), after #2619 merges #2621
No ruleset or branch protection applies to v2/main: gh api repos/modelcontextprotocol/inspector/rules/branches/v2/main returns []. Both "L3 - full protection" rulesets (org and repo) target ~DEFAULT_BRANCH, which is main only.
So once #2619 (#2616) merges, the DCO check will run on every v2 PR, but nothing stops a PR from merging while it's red or missing. A missing check would pass silently, which is how the probot app's outage went unnoticed for seven weeks after #1981 (#2566). #2566 asked for a required check, and #2603 deliberately deferred that part: making it required while the workflow couldn't report would have blocked every PR.
Change
Add a repository ruleset for v2/main, modeled on the existing v1/main - full protection ruleset (19858989):
integration_id: 15368 (GitHub Actions) pins the check to the workflow. Without it, anyone with write access could post a commit status named DCO and satisfy the rule. v1/main's ruleset pins build the same way.
deletion + non_fast_forward: the DCO (v2/main push) backstop checks before..after and assumes v2/main is never rewritten. Today nothing prevents a force-push.
Bypass: repository admins (role 5), as on v1/main. Drop this if admins should be held to it too.
Direct pushes to v2/main will be refused unless the pusher can bypass, because a required check applies to every commit landing on the branch. The release flow uses PRs, so this shouldn't bite.
Severity 3: without it, the DCO check can be red or missing at merge time, so the gate is advisory only. The workaround (watching the check by hand) is partial.
Problem
No ruleset or branch protection applies to
v2/main:gh api repos/modelcontextprotocol/inspector/rules/branches/v2/mainreturns[]. Both "L3 - full protection" rulesets (org and repo) target~DEFAULT_BRANCH, which ismainonly.So once #2619 (#2616) merges, the
DCOcheck will run on every v2 PR, but nothing stops a PR from merging while it's red or missing. A missing check would pass silently, which is how the probot app's outage went unnoticed for seven weeks after #1981 (#2566). #2566 asked for a required check, and #2603 deliberately deferred that part: making it required while the workflow couldn't report would have blocked every PR.Change
Add a repository ruleset for
v2/main, modeled on the existingv1/main - full protectionruleset (19858989):integration_id: 15368(GitHub Actions) pins the check to the workflow. Without it, anyone with write access could post a commit status namedDCOand satisfy the rule.v1/main's ruleset pinsbuildthe same way.deletion+non_fast_forward: theDCO (v2/main push)backstop checksbefore..afterand assumesv2/mainis never rewritten. Today nothing prevents a force-push.5), as onv1/main. Drop this if admins should be held to it too.Preconditions and side effects
v2/main. Before that, PRs get noDCOcheck at all (the old workflow ispull_request_target, read frommain, which has nodco.yml), so a required check would block every merge.pull_requestrun starts only on an event, so a PR opened before ci: run the DCO check on every v2 PR now, before push, and after merge (#2616) #2619 merged has noDCOresult until its next push, a close/reopen, or a base edit. Push to (or close/reopen) any open v2 PR that shows the check as "expected".v2/mainwill be refused unless the pusher can bypass, because a required check applies to every commit landing on the branch. The release flow uses PRs, so this shouldn't bite.mainreceives the oldpull_request_targetdco.yml, and v2 PRs get twoDCOchecks until the following milestone merge. Both run the same script and agree, so requiring the nameDCOstays satisfiable.Done when
gh api repos/modelcontextprotocol/inspector/rules/branches/v2/mainlistsdeletion,non_fast_forwardandrequired_status_checks(DCO, integration15368).DCOfailing and merging blocked. Re-signing the commit unblocks it.AGENTS.md("it gates merges only as a required status check…"),pr-flowstep 3 and thedco.ymlheader no longer describe the requirement as pending.Out of scope
Requiring
build/coverageonv2/main, or apull_requestreview rule as onv1/main. Worth deciding, but that's a separate call.