Repository navigation
Sign off the sync commit for DCO, and declare vale-linting permissions - #175
Merged
Bill Traynor (wmat) merged 2 commits intoOct 5, 2026
Merged
Conversation
RISC-V spec repositories run the DCO check, which requires every commit to carry a Signed-off-by matching its author. peter-evans/create-pull-request authors the sync commit as the user who triggered the workflow and adds no trailer, so every sync PR lands with DCO failing and cannot merge until someone amends the commit by hand. Add the trailer to commit-message, naming the same user the action authors as. This mirrors what milestone-pr in version-bot.yml already does for exactly this reason. Note that the action's own `signoff: true` input does not solve it: that adds a Signed-off-by for the *committer*, which defaults to github-actions[bot], while the author remains the triggering user -- so the trailer would not match the author and DCO would still fail. Observed on riscv/riscv-high-assurance-cryptography#184, the first sync PR this template has ever opened. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Bill Traynor <wmat@riscv.org>
The workflow declares no `permissions`, so it inherits the repository default and CodeQL raises "Workflow does not contain permissions" in every repository that adopts the file. It was flagged that way on riscv/riscv-high-assurance-cryptography#184 and fixed there by hand -- but vale-linting.yml is template-owned, so the next sync would have overwritten the fix and the finding would have returned. The reusable workflow only reads the tree in order to lint it, so `contents: read` is all it needs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Bill Traynor <wmat@riscv.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two defects that surface on every repository adopting
template-sync.yml,found while bringing
riscv/riscv-high-assurance-cryptographyonto thetemplate.
1. The sync commit is not signed off, so DCO blocks the PR.
peter-evans/create-pull-requestauthors the commit as the user whotriggered the workflow and adds no trailer, so every sync PR lands with
the DCO check failing and cannot merge until someone amends it by hand.
The trailer now names the same user the action authors as, mirroring what
milestone-prinversion-bot.ymlalready does for this exact reason.The action's own
signoff: trueinput does not solve it: that signs asthe committer, which defaults to
github-actions[bot], while the authorremains the triggering user -- so the trailer would not match the author
and DCO would still fail. There is a comment in the file recording this,
so nobody "simplifies" it to
signoff: truelater.2.
vale-linting.ymldeclares no permissions.CodeQL raises "Workflow does not contain permissions" in every repository
that adopts the file. It was flagged that way on
riscv/riscv-high-assurance-cryptography#184 and fixed there by hand -- but
the file is template-owned, so the next sync would have reverted the fix
and the finding would have returned. The reusable workflow only reads the
tree in order to lint it, so
contents: readis all it needs.Observed on riscv/riscv-high-assurance-cryptography#184 and #185, the
first sync PRs this template has ever opened.
🤖 Generated with Claude Code