Skip to content

Sign off the sync commit for DCO, and declare vale-linting permissions - #175

Merged
Bill Traynor (wmat) merged 2 commits into
mainfrom
fix/template-sync-dco-and-vale-permissions
Oct 5, 2026
Merged

Bill Traynor (wmat) merged 2 commits into
mainfrom
fix/template-sync-dco-and-vale-permissions

Conversation

@wmat

Copy link
Copy Markdown
Collaborator

Two defects that surface on every repository adopting template-sync.yml,
found while bringing riscv/riscv-high-assurance-cryptography onto the
template.

1. The sync commit is not signed off, so DCO blocks the PR.
peter-evans/create-pull-request authors the commit as the user who
triggered the workflow and adds no trailer, so every sync PR lands with
the DCO check failing and cannot merge until someone amends it by hand.
The trailer now names the same user the action authors as, mirroring what
milestone-pr in version-bot.yml already does for this exact reason.

The action's own signoff: true input does not solve it: that signs as
the committer, which defaults to github-actions[bot], while the author
remains the triggering user -- so the trailer would not match the author
and DCO would still fail. There is a comment in the file recording this,
so nobody "simplifies" it to signoff: true later.

2. vale-linting.yml declares no permissions.
CodeQL raises "Workflow does not contain permissions" in every repository
that adopts the file. It was flagged that way on
riscv/riscv-high-assurance-cryptography#184 and fixed there by hand -- but
the file is template-owned, so the next sync would have reverted the fix
and the finding would have returned. The reusable workflow only reads the
tree in order to lint it, so contents: read is all it needs.

Observed on riscv/riscv-high-assurance-cryptography#184 and #185, the
first sync PRs this template has ever opened.

🤖 Generated with Claude Code

Bill Traynor (wmat) and others added 2 commits October 5, 2026 13:24
RISC-V spec repositories run the DCO check, which requires every commit
to carry a Signed-off-by matching its author.
peter-evans/create-pull-request authors the sync commit as the user who
triggered the workflow and adds no trailer, so every sync PR lands with
DCO failing and cannot merge until someone amends the commit by hand.

Add the trailer to commit-message, naming the same user the action
authors as. This mirrors what milestone-pr in version-bot.yml already
does for exactly this reason.

Note that the action's own `signoff: true` input does not solve it: that
adds a Signed-off-by for the *committer*, which defaults to
github-actions[bot], while the author remains the triggering user -- so
the trailer would not match the author and DCO would still fail.

Observed on riscv/riscv-high-assurance-cryptography#184, the first sync
PR this template has ever opened.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Bill Traynor <wmat@riscv.org>
The workflow declares no `permissions`, so it inherits the repository
default and CodeQL raises "Workflow does not contain permissions" in
every repository that adopts the file. It was flagged that way on
riscv/riscv-high-assurance-cryptography#184 and fixed there by hand --
but vale-linting.yml is template-owned, so the next sync would have
overwritten the fix and the finding would have returned.

The reusable workflow only reads the tree in order to lint it, so
`contents: read` is all it needs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Bill Traynor <wmat@riscv.org>
@wmat
Bill Traynor (wmat) merged commit 84b5d85 into main Oct 5, 2026
3 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant