返回 CodeWhale
dco.yml
根目录 / .github / workflows / dco.yml
1 name: DCO
2
3 on:
4 pull_request:
5 types: [opened, synchronize, reopened]
6
7 permissions:
8 pull-requests: write
9
10 jobs:
11 dco:
12 name: Check Signed-off-by
13 runs-on: ubuntu-latest
14 timeout-minutes: 10
15 steps:
16 - uses: actions/checkout@v4
17 with:
18 repository: ${{ github.event.pull_request.head.repo.full_name }}
19 ref: ${{ github.event.pull_request.head.sha }}
20 fetch-depth: 0
21
22 - name: Report missing Signed-off-by (dry-run advisory)
23 shell: bash
24 run: |
25 set -euo pipefail
26
27 base_rev=$(git merge-base origin/${{ github.base_ref }} HEAD 2>/dev/null || echo "HEAD~1")
28 echo "✅ merge-base: $base_rev"
29 echo ""
30
31 bad=()
32 while IFS= read -r commit; do
33 msg=$(git log --format=%B -n1 "$commit")
34 if ! echo "$msg" | grep -qi "^Signed-off-by:"; then
35 bad+=("$commit")
36 fi
37 done < <(git rev-list "${base_rev}..HEAD")
38
39 if [ ${#bad[@]} -eq 0 ]; then
40 echo "✅ All commits have Signed-off-by."
41 exit 0
42 fi
43
44 echo "⚠️ Advisory — the following commit(s) are missing Signed-off-by:"
45 for c in "${bad[@]}"; do
46 echo " • $c $(git log --format=%s -n1 "$c")"
47 done
48 echo ""
49 echo "This check is advisory and does not block merging."
50 echo "Please amend commits with:"
51 echo " git commit --amend -s"
52 echo "See CONTRIBUTING.md for details."
53 echo ""
54 echo "::warning title=DCO: missing Signed-off-by::Some commits are missing Signed-off-by — amend with git commit --amend -s"
55
56 # Dry-run: always pass, but surface the warning
57 exit 0
58
58 lines YAML