Skip to content

docs(contributing): retire mandatory DCO sign-off - #418

Merged
masarray merged 1 commit into
mainfrom
maintenance/remove-mandatory-dco-20260926
Sep 26, 2026
Merged

masarray merged 1 commit into
mainfrom
maintenance/remove-mandatory-dco-20260926

Conversation

@masarray

@masarray masarray commented Sep 26, 2026 •

Copy link
Copy Markdown
Owner

Owner-directed contribution policy update

At the repository owner's explicit request in this ARSAS maintenance conversation, stop requiring DCO Signed-off-by trailers for future commits and remove the repeated manual-amend bottleneck. This is an intentional, visible change to project policy, not a fabricated contributor sign-off or an undocumented bypass.

Exact scope

Only three governance files:

  • CONTRIBUTING.md: remove per-commit DCO sign-off rule and example; explicitly state the existing DCO.txt and historical trailers are retained as historical records, not an active gate.
  • docs/LICENSING.md: synchronize contribution policy.
  • .github/pull_request_template.md: replace DCO checkbox with an affirmative CLA/rights acknowledgement.

Retain CLA, GPL and commercial-license wording, accurate Git author identity, source/third-party provenance review, independent-implementation policy, CI and IEC 61850 operational safety. Do not change the CLA's substantive terms or historical commits.

No-regression boundary

Base is the freshly merged two-file formatter PR #417 at 40355bca78341f02ecdc2c10199a1df062570897. No application, engine, tests, discovery, reporting, release, tag, engine pin, build, or runtime file changes. No new physical IED acceptance is claimed.

Validation

Diff is exactly 3 policy/template files, 1 commit, and no Signed-off-by trailer is claimed. Full PR CI and post-merge main checks will be used as the engineering gate. Any repository action that still enforces DCO must be identified and removed explicitly rather than silently disabled. Tracks #380.

Integration result

  • Owner-directed policy change merged into main via GitHub rebase as 7ef6cadaaa15fb47dc234fe9519bbdb0163a8036.
  • Verified the merged tree and exactly three files; CONTRIBUTING.md, docs/LICENSING.md, and the PR template all state the new contribution requirements. No DCO trailer was added to the policy commit.
  • Pre-merge Build ARSAS succeeded with 1,319 application tests and no failures. Both post-merge main workflows succeeded on exact SHA 7ef6cadaaa15fb47dc234fe9519bbdb0163a8036: Build ARSAS (1,319 app tests; portable EXE publish and smoke test) and Smart Discovery Post-Merge Production Verification (988 engine + 1,319 app tests; zero failures).
  • Existing historical sign-offs remain; future DCO sign-off is not a project merge requirement. CLA and provenance/security/engineering requirements remain unchanged.

Copy link
Copy Markdown
Owner Author

Policy-gate audit for owner-directed removal of mandatory DCO trailers:

  • Repository code search for exact Signed-off-by, DCO.txt and DCO sign-off identified the active requirement in CONTRIBUTING.md, docs/LICENSING.md and .github/pull_request_template.md; this three-file PR updates all three. No DCO-enforcing GitHub rulesets are configured. The original DCO.txt and historical commit metadata are not rewritten or discarded.
  • Contribution rights/provenance remain explicitly covered by affirmative CLA agreement, accurate Git authorship, third-party/license review and independent implementation policy. No waiver of GPL, commercial licensing, CI or safety controls.
  • refactor(formatting): avoid second legacy scalar extraction #417 is already merged on main at 40355bca78341f02ecdc2c10199a1df062570897 with 2/2 post-merge CI success, 1,319 app and 988 engine tests green. This PR only changes policy docs/template, not runtime.
  • Transitional governance choice: the repository owner's explicit instruction is to retire the DCO requirement; this policy-change commit intentionally does not contain an impersonated owner sign-off. Do not retroactively claim a contributor certification. The project owner directs the policy change, while the existing CLA text itself remains intact.

@masarray
masarray marked this pull request as ready for review September 26, 2026 10:44
@masarray
masarray merged commit 7ef6cad into main Sep 26, 2026
1 check passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8a0d3377a1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

- [ ] Third-party components and licenses are identified.
- [ ] Public license, commercial-license, and trademark wording remains accurate.
- [ ] Commits include the required DCO sign-off.
- [ ] I have read and affirmatively agree to the [Contributor License Agreement](../CONTRIBUTOR-LICENSE-AGREEMENT.md) for this contribution, and I have the rights and any required authorization to submit it.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use a working CLA URL in generated PR bodies

When this template is used to create a pull request, the Markdown is rendered at /masarray/arsas/pull/<number>, where ../CONTRIBUTOR-LICENSE-AGREEMENT.md resolves to /masarray/arsas/CONTRIBUTOR-LICENSE-AGREEMENT.md rather than the repository file under /blob/<branch>/. The agreement checkbox therefore sends contributors to a missing page precisely when they need to review the now-required CLA; use a repository-root URL containing /blob/main/ (or a full permanent URL) instead. This matters because the repository explicitly makes the PR template part of its validation workflow.

AGENTS.md reference: AGENTS.md:L227-L227

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant