Repository navigation
ci: make DCO a required status check on v2/main (#2621) - #2635
Merged
Merged
Conversation
The v2/main - DCO repository ruleset makes the DCO workflow a required status check, pinned to GitHub Actions, and blocks deleting or force-pushing v2/main. AGENTS.md, pr-flow step 3, the dco.yml header and docs/quality-gate.md no longer describe the requirement as pending. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: cliffhall <cliff@futurescale.com>
There was a problem hiding this comment.
🟡 Changes recommended
The issue’s required unsigned-commit merge-blocking test remains incomplete.
1 open finding
What changed in this PR
Documents the newly applied DCO ruleset protecting v2/main.
Changes:
- Records DCO as a required GitHub Actions check.
- Documents ruleset protections, admin bypass, and stacked-PR behavior.
- Warns that renaming the job requires updating the ruleset.
| File | Description |
|---|---|
.claude/skills/pr-flow/SKILL.md |
Updates the contributor workflow. |
.github/workflows/dco.yml |
Documents ruleset coupling. |
AGENTS.md |
Updates repository policy. |
docs/quality-gate.md |
Describes DCO enforcement. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Member
Author
|
Copilot review round 1 had one finding: the unsigned-commit merge-blocking test from #2621 was still open. It is now done (#2636), recorded in the PR body, and answered in its thread. Nothing else was raised, either inline or in a suppressed block. Review loop closed. The finding was about verification, not code, so no commit was pushed and the diff Copilot reviewed is unchanged. Another round would re-review identical code. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Closes #2621
Ruleset (applied, outside this diff)
#2619 merged at 2026-10-07T14:20Z, so I created the repository ruleset
v2/main - DCO(id24675476) exactly as the issue specifies:required_status_checks:DCO, pinned to GitHub Actions (integration_id: 15368), so a status posted by hand under the nameDCOcan't satisfy itdeletionandnon_fast_forward, which theDCO (v2/main push)backstop'sbefore..afterrange depends on5), as onv1/mainWhen it was applied, the only open v2 PR was #2618, and its
DCOcheck already passes, so nothing was left "expected". The ten unsigned commits #2618 certifies are ancestors ofv2/main, so no PR range ever includes them again. #2618's merge-commit merge is allowed because the ruleset has no linear-history or merge-method rule. Nothing changes if #2618 misses this release.Docs (this diff)
Four places no longer describe the requirement as pending:
AGENTS.md, under Issue-driven Work Stylepr-flowstep 3: names the ruleset, the integration pin and the admin bypass, and notes that a stacked PR's check gates nothing until the PR is retargeted tov2/maindco.ymlheader: also warns that renaming theDCOjob renames the check, which would leave the ruleset waiting on a name nothing reportsdocs/quality-gate.mdVerification
rules/branches/v2/mainlists all three rules (above).DCOand blocks merging. Throwaway PR DO NOT MERGE: DCO ruleset probe (#2621) #2636 intov2/mainheld one unsigned commit:DCOfailed and the merge state wasBLOCKED, mergeable only through the admin bypass, as configured. After the commit was re-signed,DCOpassed and the state becameUNSTABLE: only non-required checks were pending, so merging was unblocked. DO NOT MERGE: DCO ruleset probe (#2621) #2636 was closed unmerged and its branch deleted.npm run local:gate: every stage passed exceptsmoke:web:firefox, which fails locally per smoke:web:firefox cannot launch Playwright's Firefox on macOS 27 #2625 (Playwright's Firefox doesn't launch on macOS 27). That failure ends the gate's&&chain before Storybook, so I ran it separately:npm run local:storybook: 123 files, 529 tests passed.mcr.microsoft.com/playwright:v1.62.1-noblecontainer, run from a cleangit archiveof this branch:smoke:web:browser,smoke:web:appandsmoke:web:eliciteach reported[firefox] OK.🤖 Generated with Claude Code