Repository navigation
ci: add DCO check, Mergify automation, and branch naming enforcement - #424
Conversation
- Add dco-check job using tim-actions/dco in pr-test-rust.yml - Add commit-msg pre-commit hook to verify Signed-off-by line - Document DCO sign-off requirement in development guide Signed-off-by: Chang Su <chang.s.su@oracle.com>
…, and stale PRs - Enforce branch naming convention (<type>/ or <username>/) with comment, failing check, and auto-close on violation - Comment with fix instructions when DCO sign-off check fails - Notify when PR has merge conflicts with rebase instructions - Remind and label PRs inactive for 14 days Signed-off-by: Chang Su <chang.s.su@oracle.com>
Add a pre-push hook that validates branch names follow the <type>/<description> or <username>/<description> format. Signed-off-by: Chang Su <chang.s.su@oracle.com>
Summary of ChangesHello @CatherineSue, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request significantly enhances the repository's automation and developer experience by introducing several new checks and workflows. It aims to improve code quality, maintain consistent development practices, and streamline the pull request lifecycle through automated enforcement of DCO sign-offs, branch naming conventions, and proactive communication regarding PR status like merge conflicts and staleness. These changes reduce manual overhead and guide contributors towards best practices. Highlights
Changelog
Ignored Files
Activity
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
|
Caution Review failedThe pull request is closed. 📝 WalkthroughWalkthroughThese changes implement a multi-layered enforcement system for Developer Certificate of Origin (DCO) sign-off requirements and branch naming conventions. Configuration is added for pre-commit hooks, a GitHub Actions workflow, Mergify automation rules, and corresponding documentation updates. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches🧪 Generate unit tests (beta)
Comment |
tim-actions/dco requires a commits input from tim-actions/get-pr-commits. Signed-off-by: Chang Su <chang.s.su@oracle.com>
There was a problem hiding this comment.
Code Review
This pull request introduces valuable CI automation using Mergify and pre-commit hooks to enforce repository conventions like DCO sign-off and branch naming. The changes are well-structured and the documentation updates are clear. I have a few suggestions to make the validation checks for branch naming and DCO sign-off more robust and consistent with the documented intentions.
Add $ anchor to prevent matching lines with trailing text after the email address in the Signed-off-by line. Signed-off-by: Chang Su <chang.s.su@oracle.com>
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Fix all issues with AI agents
In @.github/mergify.yml:
- Around line 4-23: The branch-name regex in the conditions block currently
allows any alphanumeric prefix but the docs state only specific types; update
the first condition to enforce either the allowed types or a username form
(e.g., change the regex to allow
^(feat|fix|chore|docs|refactor|test|ci|perf)/[a-z0-9._-]+$ OR a username
pattern) so it matches the documented `<type>/` values while still permitting
`<username>/` branches, and stop auto-closing PRs immediately by making the
close action conditional (use the existing post_check result + an inactivity
condition or replace immediate close with a timed/conditional close) so the
'close' action only runs after the warning/comment step and a grace period;
locate these fixes in the same .github/mergify.yml entries for the conditions
regex and the close action.
In @.github/workflows/pr-test-rust.yml:
- Around line 43-48: Replace mutable refs for the GitHub Actions usages to
pinned immutable refs: update the two action entries using
"tim-actions/get-pr-commits@master" and "tim-actions/dco@master" to specific
release tags or commit SHAs (e.g., tim-actions/get-pr-commits@v1.3.1 and
tim-actions/dco@v1.1.0, or preferably their full commit SHAs) so the workflow is
reproducible and secure; locate the two occurrences of the "uses:" lines in the
workflow and swap the `@master` suffixes for the chosen immutable tags/SHAs.
In @.pre-commit-config.yaml:
- Around line 55-62: The inline bash entry for the hook id "branch-name-check"
is causing YAML parsing issues; replace the single-line entry string with a
literal block scalar (using |) for the "entry" value so the entire bash script
is treated as literal text, preserve the same command logic (capturing branch
with git rev-parse, the regex check, and the echo + exit 1 behavior) and ensure
proper indentation under the "entry:" key; update the entry associated with id
branch-name-check rather than changing the hook name or its other keys.
- Pin tim-actions/get-pr-commits to v1.3.1 and tim-actions/dco to v1.1.0 instead of @master for security and reproducibility - Use YAML block scalar for branch-name-check entry to avoid parsing issues - Remove auto-close action from branch naming Mergify rule to avoid frustrating contributors; keep comment + failing check instead Signed-off-by: Chang Su <chang.s.su@oracle.com>
Contributors cannot rename a branch on an existing PR, so auto-closing with a clear message saves them a manual step. Signed-off-by: Chang Su <chang.s.su@oracle.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Fix all issues with AI agents
In @.pre-commit-config.yaml:
- Around line 71-78: The YAML parser is breaking on the inline entry for the
dco-check hook (id: dco-check) because the bash string contains colons and angle
brackets; replace the inline scalar for the entry with a literal block scalar so
the command is treated as a plain string. Locate the dco-check hook (id:
dco-check / name: DCO sign-off check) and change the entry to use a block scalar
(|) followed by the existing bash -c 'grep -q "^Signed-off-by: .* <.*>$" "$1"'
-- command on the next indented line so YAML treats it safely.
The colon in Signed-off-by: and angle brackets confuse the YAML parser when used inline. Signed-off-by: Chang Su <chang.s.su@oracle.com>
Move dco-check job from pr-test-rust.yml into its own dco.yml so it runs on all PRs independently of path filters and the main CI pipeline. Signed-off-by: Chang Su <chang.s.su@oracle.com>
…424) Signed-off-by: Chang Su <chang.s.su@oracle.com> Signed-off-by: ppraneth <pranethparuchuri@gmail.com>
…424) Signed-off-by: Chang Su <chang.s.su@oracle.com> Signed-off-by: ppraneth <pranethparuchuri@gmail.com>
Description
Problem
The repository lacks automated enforcement for DCO sign-off, branch naming conventions, merge conflict notification, and stale PR management.
Solution
Add layered enforcement via GitHub Actions, Mergify, and pre-commit hooks.
Changes
tim-actions/dcojob inpr-test-rust.ymlCI workflow and acommit-msgpre-commit hook to verifySigned-off-bylines.github/mergify.yml):git rebase --signoff, IDE settings)pre-pushhook enforcing<type>/<description>or<username>/<description>formatdocs/contributing/development.mdwith DCO sign-off instructions andcommit-msghook setupTest Plan
Checklist
cargo +nightly fmtpassescargo clippy --all-targets --all-features -- -D warningspassesSummary by CodeRabbit
Chores
Documentation