Skip to content

ci: make DCO a required status check on v2/main (#2621) - #2635

Merged
cliffhall merged 2 commits into
v2/mainfrom
v2/chore/2621-dco-required-ruleset
Oct 7, 2026
Merged

cliffhall merged 2 commits into
v2/mainfrom
v2/chore/2621-dco-required-ruleset

Conversation

@cliffhall

@cliffhall cliffhall commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Closes #2621

Ruleset (applied, outside this diff)

#2619 merged at 2026-10-07T14:20Z, so I created the repository ruleset v2/main - DCO (id 24675476) exactly as the issue specifies:

  • required_status_checks: DCO, pinned to GitHub Actions (integration_id: 15368), so a status posted by hand under the name DCO can't satisfy it
  • deletion and non_fast_forward, which the DCO (v2/main push) backstop's before..after range depends on
  • bypass: repository admins (role 5), as on v1/main
$ gh api repos/modelcontextprotocol/inspector/rules/branches/v2/main
deletion
non_fast_forward
required_status_checks  [{"context":"DCO","integration_id":15368}]

When it was applied, the only open v2 PR was #2618, and its DCO check already passes, so nothing was left "expected". The ten unsigned commits #2618 certifies are ancestors of v2/main, so no PR range ever includes them again. #2618's merge-commit merge is allowed because the ruleset has no linear-history or merge-method rule. Nothing changes if #2618 misses this release.

Docs (this diff)

Four places no longer describe the requirement as pending:

  • AGENTS.md, under Issue-driven Work Style
  • pr-flow step 3: names the ruleset, the integration pin and the admin bypass, and notes that a stacked PR's check gates nothing until the PR is retargeted to v2/main
  • the dco.yml header: also warns that renaming the DCO job renames the check, which would leave the ruleset waiting on a name nothing reports
  • docs/quality-gate.md

Verification

  • rules/branches/v2/main lists all three rules (above).
  • An unsigned commit fails DCO and blocks merging. Throwaway PR DO NOT MERGE: DCO ruleset probe (#2621) #2636 into v2/main held one unsigned commit: DCO failed and the merge state was BLOCKED, mergeable only through the admin bypass, as configured. After the commit was re-signed, DCO passed and the state became UNSTABLE: only non-required checks were pending, so merging was unblocked. DO NOT MERGE: DCO ruleset probe (#2621) #2636 was closed unmerged and its branch deleted.
  • npm run local:gate: every stage passed except smoke:web:firefox, which fails locally per smoke:web:firefox cannot launch Playwright's Firefox on macOS 27 #2625 (Playwright's Firefox doesn't launch on macOS 27). That failure ends the gate's && chain before Storybook, so I ran it separately:
    • npm run local:storybook: 123 files, 529 tests passed.
    • The three Firefox smokes passed in the mcr.microsoft.com/playwright:v1.62.1-noble container, run from a clean git archive of this branch: smoke:web:browser, smoke:web:app and smoke:web:elicit each reported [firefox] OK.

🤖 Generated with Claude Code

The v2/main - DCO repository ruleset makes the DCO workflow a required
status check, pinned to GitHub Actions, and blocks deleting or
force-pushing v2/main. AGENTS.md, pr-flow step 3, the dco.yml header and
docs/quality-gate.md no longer describe the requirement as pending.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
@cliffhall cliffhall added the v2 Issues and PRs for v2 label Oct 7, 2026
@cliffhall
cliffhall requested a balanced review from Copilot October 7, 2026 19:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The issue’s required unsigned-commit merge-blocking test remains incomplete.

1 open finding
What changed in this PR

Documents the newly applied DCO ruleset protecting v2/main.

Changes:

  • Records DCO as a required GitHub Actions check.
  • Documents ruleset protections, admin bypass, and stacked-PR behavior.
  • Warns that renaming the job requires updating the ruleset.
File Description
.claude/​skills/​pr-flow/​SKILL.md Updates the contributor workflow.
.github/​workflows/​dco.yml Documents ruleset coupling.
AGENTS.md Updates repository policy.
docs/​quality-gate.md Describes DCO enforcement.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/dco.yml
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot review round 1 had one finding: the unsigned-commit merge-blocking test from #2621 was still open. It is now done (#2636), recorded in the PR body, and answered in its thread. Nothing else was raised, either inline or in a suppressed block.

Review loop closed. The finding was about verification, not code, so no commit was pushed and the diff Copilot reviewed is unchanged. Another round would re-review identical code.

@cliffhall
cliffhall merged commit 36db875 into v2/main Oct 7, 2026
7 checks passed
@cliffhall
cliffhall deleted the v2/chore/2621-dco-required-ruleset branch October 7, 2026 21:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v2 Issues and PRs for v2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: make DCO a required status check on v2/main (ruleset), after #2619 merges

2 participants