From 9aea93dbc64a28defc82f925198c7af900aa1769 Mon Sep 17 00:00:00 2001 From: "quality-runtime[bot]" <330432719+quality-runtime[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 19:06:45 +0200 Subject: [PATCH] fix(ci): exempt the real bot login from the DCO check The project bot signs in as quality-runtime[bot]; qualityruntime[bot] does not exist, so the exemption never matched and a pull request the bot opened without a sign-off would fail the dco job. Signed-off-by: quality-runtime[bot] <330432719+quality-runtime[bot]@users.noreply.github.com> --- .github/workflows/ci.yml | 2 +- AGENTS.md | 2 +- CONTRIBUTING.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f609666..090d3e2 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -50,7 +50,7 @@ jobs: # as itself. Commit author fields are self-reported and must not gate this. if: > github.event_name == 'pull_request' && - github.event.pull_request.user.login != 'qualityruntime[bot]' + github.event.pull_request.user.login != 'quality-runtime[bot]' runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 diff --git a/AGENTS.md b/AGENTS.md index 745c2d5..2f77d0c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -41,7 +41,7 @@ Apps go in `apps/`, shared code in `packages/` — extract a package only when t - Add or update tests for important behavior. - Never weaken tenant isolation, authorization, auditability, or data integrity for convenience. - Never modify an existing applied database migration; add a new one. -- Sign off commits with `git commit -s` (Developer Certificate of Origin); pull requests opened by `qualityruntime[bot]` are exempt. +- Sign off commits with `git commit -s` (Developer Certificate of Origin); pull requests opened by `quality-runtime[bot]` are exempt. ## Licensing diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 6b97f31..1f9037e 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -51,7 +51,7 @@ Signed-off-by: Jane Doe The sign-off certifies your contribution under the [Developer Certificate of Origin 1.1](https://developercertificate.org/). CI rejects pull requests whose commits are not signed off. -Pull requests opened by Quality Runtime's trusted project automation, `qualityruntime[bot]`, are exempt: a bot cannot make the DCO's first-person certification. The exemption covers automation acting for the project, not an external contribution rewritten by it — when automation submits someone else's work, that person's sign-off stays in the contribution. +Pull requests opened by Quality Runtime's trusted project automation, `quality-runtime[bot]`, are exempt: a bot cannot make the DCO's first-person certification. The exemption covers automation acting for the project, not an external contribution rewritten by it — when automation submits someone else's work, that person's sign-off stays in the contribution. AI-assisted contributions are welcome. The sign-off certifies the contribution under DCO 1.1 whether or not a coding agent assisted: review what you submit, make sure you can make that certification, and make sure you have the right to submit the work under Apache-2.0. It does not mean you typed every line. Do not submit code copied from third-party sources unless its license permits inclusion and you preserve the required attribution and notices.