Skip to content

ci: add DCO check, Mergify automation, and branch naming enforcement - #424

Merged
CatherineSue merged 9 commits into
mainfrom
feat/dco-check
Feb 13, 2026
Merged

CatherineSue merged 9 commits into
mainfrom
feat/dco-check

Conversation

@CatherineSue

@CatherineSue CatherineSue commented Feb 13, 2026 •

Copy link
Copy Markdown
Member

Description

Problem

The repository lacks automated enforcement for DCO sign-off, branch naming conventions, merge conflict notification, and stale PR management.

Solution

Add layered enforcement via GitHub Actions, Mergify, and pre-commit hooks.

Changes

  • DCO sign-off check: Add tim-actions/dco job in pr-test-rust.yml CI workflow and a commit-msg pre-commit hook to verify Signed-off-by lines
  • Mergify automation (.github/mergify.yml):
    • Branch naming enforcement — comment, post failing check, and auto-close on violation
    • DCO failure — comment with fix instructions (git rebase --signoff, IDE settings)
    • Merge conflict notification — comment with rebase instructions
    • Stale PR reminder — comment and label after 14 days of inactivity
  • Branch naming pre-commit hook: pre-push hook enforcing <type>/<description> or <username>/<description> format
  • Documentation: Update docs/contributing/development.md with DCO sign-off instructions and commit-msg hook setup

Test Plan

  • Verify DCO check runs on PR and fails for unsigned commits
  • Verify Mergify rules trigger on matching conditions (branch name violation, DCO failure, merge conflict, stale PR)
  • Verify pre-commit hooks reject bad branch names and unsigned commit messages locally
Checklist
  • cargo +nightly fmt passes
  • cargo clippy --all-targets --all-features -- -D warnings passes
  • Documentation updated

Summary by CodeRabbit

  • Chores

    • Configured automated branch naming enforcement for pull requests
    • Implemented Developer Certificate of Origin (DCO) sign-off verification on all commits
    • Added automatic monitoring and notifications for merge conflicts and stale pull requests
  • Documentation

    • Updated contribution guidelines with Developer Certificate of Origin requirements and setup instructions

- Add dco-check job using tim-actions/dco in pr-test-rust.yml
- Add commit-msg pre-commit hook to verify Signed-off-by line
- Document DCO sign-off requirement in development guide

Signed-off-by: Chang Su <chang.s.su@oracle.com>
…, and stale PRs

- Enforce branch naming convention (<type>/ or <username>/) with
  comment, failing check, and auto-close on violation
- Comment with fix instructions when DCO sign-off check fails
- Notify when PR has merge conflicts with rebase instructions
- Remind and label PRs inactive for 14 days

Signed-off-by: Chang Su <chang.s.su@oracle.com>
Add a pre-push hook that validates branch names follow the
<type>/<description> or <username>/<description> format.

Signed-off-by: Chang Su <chang.s.su@oracle.com>
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello @CatherineSue, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the repository's automation and developer experience by introducing several new checks and workflows. It aims to improve code quality, maintain consistent development practices, and streamline the pull request lifecycle through automated enforcement of DCO sign-offs, branch naming conventions, and proactive communication regarding PR status like merge conflicts and staleness. These changes reduce manual overhead and guide contributors towards best practices.

Highlights

  • Automated DCO Check: Implemented a Developer Certificate of Origin (DCO) sign-off check in the CI workflow and as a commit-msg pre-commit hook to ensure all commits are properly signed.
  • Mergify Automation: Configured Mergify to automate various PR management tasks, including enforcing branch naming conventions, providing DCO failure instructions, notifying about merge conflicts, and reminding about stale PRs.
  • Branch Naming Enforcement: Added a pre-push pre-commit hook and a Mergify rule to enforce a consistent branch naming convention (e.g., <type>/<description> or <username>/<description>).
  • Documentation Updates: Updated the docs/contributing/development.md file with instructions on DCO sign-off and how to set up the new commit-msg pre-commit hook.
Changelog
  • .github/mergify.yml
    • Added a rule to enforce branch naming conventions, automatically commenting, posting a failing check, and closing PRs that violate the pattern.
    • Implemented a rule to comment with detailed fix instructions when the DCO sign-off check fails.
    • Included a rule to notify authors about merge conflicts and provide rebase instructions.
    • Added a rule to comment and label PRs as 'stale' if they have been inactive for 14 days.
  • .pre-commit-config.yaml
    • Introduced a pre-push hook (branch-name-check) to validate branch names against a defined <type>/<description> or <username>/<description> pattern.
    • Added a commit-msg hook (dco-check) to verify that commit messages include a DCO sign-off line.
  • docs/contributing/development.md
    • Updated the pre-commit install command to include the --hook-type commit-msg option for enabling the DCO sign-off check.
    • Added a new section titled 'DCO Sign-Off' providing detailed instructions on how to sign off commits using git commit -s and explaining the purpose of DCO.
Ignored Files
  • Ignored by pattern: .github/workflows/** (1)
    • .github/workflows/pr-test-rust.yml
Activity
  • The pull request introduces new CI checks and automation rules, indicating a focus on improving repository health and developer workflow from its inception.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@coderabbitai

coderabbitai Bot commented Feb 13, 2026 •

Copy link
Copy Markdown

Caution

Review failed

The pull request is closed.

📝 Walkthrough

Walkthrough

These changes implement a multi-layered enforcement system for Developer Certificate of Origin (DCO) sign-off requirements and branch naming conventions. Configuration is added for pre-commit hooks, a GitHub Actions workflow, Mergify automation rules, and corresponding documentation updates.

Changes

Cohort / File(s) Summary
DCO Sign-off Enforcement
.github/workflows/dco.yml, .pre-commit-config.yaml
Adds GitHub Actions workflow to verify DCO sign-offs on PR commits and a local pre-commit hook (dco-check) to validate Signed-off-by lines in commit messages.
Branch Naming Validation
.pre-commit-config.yaml, .github/mergify.yml
Implements branch naming enforcement via pre-commit hook (branch-name-check) requiring <type>/<description> or <username>/<description> format, plus Mergify rule to reject non-conforming branches with guidance.
PR Automation & Notifications
.github/mergify.yml
Adds Mergify rules for commenting on DCO check failures, notifying about merge conflicts, and reminding on stale PRs (14+ days inactive).
Documentation
docs/contributing/development.md
Documents DCO sign-off requirements, including pre-commit hook setup, commit-msg hook usage, and examples of signing commits with the -s flag.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Suggested reviewers

  • slin1237

Poem

🐰 A hoppy day for rules so fine,
Branch names pristine in format divine,
DCO signs seal every commit,
Mergify checks won't let bad PRs fit,
Automation blooms where order takes flight! 🌿✨

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The pull request title accurately summarizes the three main changes: DCO check, Mergify automation, and branch naming enforcement, matching the PR's primary objectives.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Merge Conflict Detection ✅ Passed ✅ No merge conflicts detected when merging into main

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch feat/dco-check

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions github-actions Bot added documentation Improvements or additions to documentation ci CI/CD configuration changes labels Feb 13, 2026
tim-actions/dco requires a commits input from tim-actions/get-pr-commits.

Signed-off-by: Chang Su <chang.s.su@oracle.com>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces valuable CI automation using Mergify and pre-commit hooks to enforce repository conventions like DCO sign-off and branch naming. The changes are well-structured and the documentation updates are clear. I have a few suggestions to make the validation checks for branch naming and DCO sign-off more robust and consistent with the documented intentions.

Comment thread .github/mergify.yml
Comment thread .pre-commit-config.yaml Outdated
Comment thread .pre-commit-config.yaml Outdated
Add $ anchor to prevent matching lines with trailing text after
the email address in the Signed-off-by line.

Signed-off-by: Chang Su <chang.s.su@oracle.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Fix all issues with AI agents
In @.github/mergify.yml:
- Around line 4-23: The branch-name regex in the conditions block currently
allows any alphanumeric prefix but the docs state only specific types; update
the first condition to enforce either the allowed types or a username form
(e.g., change the regex to allow
^(feat|fix|chore|docs|refactor|test|ci|perf)/[a-z0-9._-]+$ OR a username
pattern) so it matches the documented `<type>/` values while still permitting
`<username>/` branches, and stop auto-closing PRs immediately by making the
close action conditional (use the existing post_check result + an inactivity
condition or replace immediate close with a timed/conditional close) so the
'close' action only runs after the warning/comment step and a grace period;
locate these fixes in the same .github/mergify.yml entries for the conditions
regex and the close action.

In @.github/workflows/pr-test-rust.yml:
- Around line 43-48: Replace mutable refs for the GitHub Actions usages to
pinned immutable refs: update the two action entries using
"tim-actions/get-pr-commits@master" and "tim-actions/dco@master" to specific
release tags or commit SHAs (e.g., tim-actions/get-pr-commits@v1.3.1 and
tim-actions/dco@v1.1.0, or preferably their full commit SHAs) so the workflow is
reproducible and secure; locate the two occurrences of the "uses:" lines in the
workflow and swap the `@master` suffixes for the chosen immutable tags/SHAs.

In @.pre-commit-config.yaml:
- Around line 55-62: The inline bash entry for the hook id "branch-name-check"
is causing YAML parsing issues; replace the single-line entry string with a
literal block scalar (using |) for the "entry" value so the entire bash script
is treated as literal text, preserve the same command logic (capturing branch
with git rev-parse, the regex check, and the echo + exit 1 behavior) and ensure
proper indentation under the "entry:" key; update the entry associated with id
branch-name-check rather than changing the hook name or its other keys.

Comment thread .github/mergify.yml
Comment thread .github/workflows/pr-test-rust.yml Outdated
Comment thread .pre-commit-config.yaml
- Pin tim-actions/get-pr-commits to v1.3.1 and tim-actions/dco to v1.1.0
  instead of @master for security and reproducibility
- Use YAML block scalar for branch-name-check entry to avoid parsing issues
- Remove auto-close action from branch naming Mergify rule to avoid
  frustrating contributors; keep comment + failing check instead

Signed-off-by: Chang Su <chang.s.su@oracle.com>
Contributors cannot rename a branch on an existing PR, so auto-closing
with a clear message saves them a manual step.

Signed-off-by: Chang Su <chang.s.su@oracle.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In @.pre-commit-config.yaml:
- Around line 71-78: The YAML parser is breaking on the inline entry for the
dco-check hook (id: dco-check) because the bash string contains colons and angle
brackets; replace the inline scalar for the entry with a literal block scalar so
the command is treated as a plain string. Locate the dco-check hook (id:
dco-check / name: DCO sign-off check) and change the entry to use a block scalar
(|) followed by the existing bash -c 'grep -q "^Signed-off-by: .* <.*>$" "$1"'
-- command on the next indented line so YAML treats it safely.

Comment thread .pre-commit-config.yaml
The colon in Signed-off-by: and angle brackets confuse the YAML parser
when used inline.

Signed-off-by: Chang Su <chang.s.su@oracle.com>
Move dco-check job from pr-test-rust.yml into its own dco.yml so it
runs on all PRs independently of path filters and the main CI pipeline.

Signed-off-by: Chang Su <chang.s.su@oracle.com>
@CatherineSue
CatherineSue merged commit ab8f672 into main Feb 13, 2026
2 of 3 checks passed
@CatherineSue
CatherineSue deleted the feat/dco-check branch February 13, 2026 21:25
ppraneth pushed a commit that referenced this pull request Feb 14, 2026
…424)

Signed-off-by: Chang Su <chang.s.su@oracle.com>
Signed-off-by: ppraneth <pranethparuchuri@gmail.com>
ppraneth pushed a commit that referenced this pull request Feb 18, 2026
…424)

Signed-off-by: Chang Su <chang.s.su@oracle.com>
Signed-off-by: ppraneth <pranethparuchuri@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD configuration changes documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants