Problem
The DCO check added in #2603 (#2566) does not run on any PR into v2/main, and it won't until the next milestone merge.
dco.yml triggers on pull_request_target, and GitHub reads pull_request_target workflows from the default branch (main). The file is not on main yet. The workflow header documents this ("this file does nothing until a milestone merge carries it from v2/main to main"). The only recorded run is a pull_request event on #2603's own branch, and no PR since has a DCO check (#2603 at merge, #2612, #2613).
So until a milestone merge, unsigned commits can reach v2/main unchecked, and the first we'd hear of them is when the milestone PR into main is opened. That is too late to fix them cheaply.
Change
- PR check on
pull_request. Switch the trigger from pull_request_target to pull_request (still branches: [v2/main], same event types), so it runs from the PR's own ref as soon as this merges to v2/main.
- Trade-off, accepted deliberately: under
pull_request a PR could edit dco.yml or scripts/dco-check.mjs to pass itself. PRs here are opened by maintainers only, and the check exists to catch a forgotten signoff, not a forged one (dco-check.mjs already says the trailer is self-asserted). Keep running the script from the checked-out base and only fetching the PR head, so the job still never executes PR code.
- Edits to the workflow now take effect immediately, not one milestone later.
- Backstop on
push to v2/main. Run the same script over before..after for every push that lands on v2/main. That catches anything that reached the branch without a passing PR check while the workflow and script stayed intact (an admin merge, a direct push, a merge made while the check was red), at merge time rather than at the milestone merge. It does not catch a PR that edited the check itself: a push run reads the workflow and script from the pushed revision too. The control for that case is review. A zero before (branch creation) is skipped.
- Update the header comment, the
dco-check.mjs header, and pr-flow step 3, which all describe the pull_request_target / milestone-merge rollout.
Out of scope
Making DCO a required status check on v2/main is a ruleset change in repo settings, not something a file can do. Once this lands and the check reports, it can be made required.
Problem
The
DCOcheck added in #2603 (#2566) does not run on any PR intov2/main, and it won't until the next milestone merge.dco.ymltriggers onpull_request_target, and GitHub readspull_request_targetworkflows from the default branch (main). The file is not onmainyet. The workflow header documents this ("this file does nothing until a milestone merge carries it fromv2/maintomain"). The only recorded run is apull_requestevent on #2603's own branch, and no PR since has aDCOcheck (#2603 at merge, #2612, #2613).So until a milestone merge, unsigned commits can reach
v2/mainunchecked, and the first we'd hear of them is when the milestone PR intomainis opened. That is too late to fix them cheaply.Change
pull_request. Switch the trigger frompull_request_targettopull_request(stillbranches: [v2/main], same event types), so it runs from the PR's own ref as soon as this merges tov2/main.pull_requesta PR could editdco.ymlorscripts/dco-check.mjsto pass itself. PRs here are opened by maintainers only, and the check exists to catch a forgotten signoff, not a forged one (dco-check.mjsalready says the trailer is self-asserted). Keep running the script from the checked-out base and only fetching the PR head, so the job still never executes PR code.pushtov2/main. Run the same script overbefore..afterfor every push that lands onv2/main. That catches anything that reached the branch without a passing PR check while the workflow and script stayed intact (an admin merge, a direct push, a merge made while the check was red), at merge time rather than at the milestone merge. It does not catch a PR that edited the check itself: a push run reads the workflow and script from the pushed revision too. The control for that case is review. A zerobefore(branch creation) is skipped.dco-check.mjsheader, andpr-flowstep 3, which all describe thepull_request_target/ milestone-merge rollout.Out of scope
Making
DCOa required status check onv2/mainis a ruleset change in repo settings, not something a file can do. Once this lands and the check reports, it can be made required.