Skip to content

ci: Add the /signoff PR command - #16

Draft
cgwalters-bot wants to merge 1 commit into
mainfrom
bot/signoff-command
Draft

cgwalters-bot wants to merge 1 commit into
mainfrom
bot/signoff-command

Conversation

@cgwalters-bot

@cgwalters-bot cgwalters-bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Adds the /signoff PR command. A maintainer comments /signoff, and their Signed-off-by is added to all of the PR's commits, which otherwise stay byte for byte the same. /rebase-signoff also moves the commits onto main. DCO is a required check here, so PRs from contributors who forgot to sign off, and all of cgwalters-bot's PRs, stay blocked until someone rewrites them by hand.

The file is the org-wide stub from bootc-dev/infra's common/ (cgwalters-forge/infra#8). Adding it here first just gets it to bootc sooner; the sync then finds an identical file. The logic is the pr-signoff reusable workflow in bootc-dev/actions (cgwalters-forge/actions#2), which has the design, the security notes and the test runs.

It uses the bootc-bot App, whose credentials (GH_AW_APP_CLIENT_ID/GH_AW_APP_PRIVATE_KEY) are installed org-wide on bootc-dev, so nothing needs setting up here. The stub pins that workflow by commit, since it hands over the bootc-bot App key. The pin is currently the actions PR's head, and must be bumped to the commit that lands in bootc-dev/actions before merging.

It doesn't touch the merge queue: it runs only for issue_comment, and dco-2 already passes merge_group checks by itself. Like any push, the signoff push removes a queued PR from the queue, so sign off before queueing.

actionlint is clean. The same stub was tested on cgwalters-forge/infra (see the actions PR). The App-token path is untested and needs one real run before anyone relies on it.

Related: bootc-dev/infra#260

Generated-by: https://github.com/cgwalters/#llms


Review draft in cgwalters-forge, not upstream yet. This section is removed when the PR is opened upstream.

  • Upstream: bootc-dev/bootc, base main
  • Board item: PVTI_lADOE9oHIs4BlJLczg9kERg
  • Fork CI: off; the devspace testing described above is this PR's CI, and upstream CI runs once it is opened there

To review:

  • Approve, or comment /promote on a line of its own, to open it upstream, ready for review. Either covers only the commits pushed so far.
  • If upstream requires DCO, approving also signs off: promote adds Signed-off-by: Colin Walters <walters@verbum.org> to the commits lacking it (the bot's and yours; anyone else's only if you ask), with you as committer.
  • Add a /draft line (in the same comment or before) to open it upstream as a draft (/ready undoes that).
  • Close to drop it.
  • Edit the title and description freely: they become the upstream PR's. Review comments are squashed into the commits they concern, with a reply here.

DCO is a required check here, and PRs from contributors who forgot to
sign off (or from the bot, which never does) sit blocked until someone
rewrites them by hand. This lets a maintainer comment `/signoff` to add
their own Signed-off-by to all of a PR's commits, leaving them otherwise
unchanged, or `/rebase-signoff` to also rebase onto main.

The file is the org-wide stub from bootc-dev/infra's common/ directory,
which sync-common will install everywhere; adding it here first just gets
it to bootc sooner, and the sync then finds it already identical. The
logic is the pr-signoff reusable workflow in bootc-dev/actions. Other
comments only produce a skipped run, without a runner.

Generated-by: AI
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant