Skip to content

fix: sign off release bumps and drop the dead Pages path filter - #198

Merged
TMHSDigital merged 2 commits into
mainfrom
fix/dco-signoff-and-pages-filter
Sep 22, 2026
Merged

TMHSDigital merged 2 commits into
mainfrom
fix/dco-signoff-and-pages-filter

Conversation

@TMHSDigital

Copy link
Copy Markdown
Owner

Two one-line workflow fixes, one commit each. These are the only sanctioned changes to release.yml and pages.yml; nothing else in either file moves.

#193 — DCO on release bumps (b66b197)

CONTRIBUTING.md § DCO sign-off requires a Signed-off-by: trailer matching the commit author, and the inbound grant it describes is what resolves the CC-BY-NC-ND outbound/inbound conflict. Every bump commit on main carries none:

$ git log --format='%h %s' --grep='^chore: bump version' -3
bd5d15b chore: bump version to 0.78.20 [skip ci]
c6a7951 chore: bump version to 0.78.19 [skip ci]
ab005ff chore: bump version to 0.78.18 [skip ci]

The "Commit version bump" step now runs git commit -s. git config user.name / user.email are already set to github-actions[bot] two lines above, so the trailer matches the author with no further change:

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

Release-path risk. This touches the step that pushes to protected main. That push has survived two live releases under the main-integrity ruleset (c6a7951→v0.78.19, bd5d15b→v0.78.20), and -s only appends a trailer — it changes neither the ref, the push, nor the commit's parentage, so the ruleset evaluates it identically. This PR is fix:-prefixed and will cut a release, so the next bump is the live test: verify it lands, tags, cuts the GitHub release, dispatches Pages, and carries the trailer.

#195 — mcp-tools.json in the Pages filter (d6b8bb3)

The path has never existed here:

$ git log --oneline --all -- mcp-tools.json
(no output)

Fleet scaffolding, not residue — scripts/site/build_site.py:274 reads it optionally and returns [] when absent, because the vendored builder serves tool repos generally and some do ship an MCP server. The filter was inert: a path that cannot change never matches, so it neither triggered nor suppressed a deploy. Removing it costs nothing and stops a reader concluding an MCP server was half-removed.

Every other path in the filter is byte-identical. Diff is a single deleted line.

Pages verification. This PR touches only .github/workflows/, which is not in the Pages path filter, so merging it will not deploy Pages by push — expected, and consistent with the documented behaviour in CONTRIBUTING.md. It will deploy via the post-tag workflow_dispatch that release.yml fires. A true content-merge deploy is proven by the next showcase PR, which touches showcase/, examples/, and docs/gallery/.

Evidence status

Both changes are inspection-only in this PR — neither workflow runs its changed step on a pull_request event. Both become live-run-proven on merge, and that verification is reported back on the follow-up PR.

Closes #193
Closes #195

🤖 Generated with Claude Code

TMHSDigital and others added 2 commits September 21, 2026 21:41
CONTRIBUTING.md § DCO sign-off requires a Signed-off-by trailer matching the
commit author, and the inbound grant it describes is what resolves this
project's CC-BY-NC-ND outbound/inbound conflict. Every release bump commit on
main since automation landed carries no trailer.

Add -s to the "Commit version bump" step. git config user.name and
user.email are already set to github-actions[bot] two lines above, so the
trailer matches the author with no further change:

  Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

Only the bump commit's -s flag changes; the rest of release.yml is untouched.
Existing history is not rewritten — main is force-push protected.

Closes #193

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: TMHSDigital <154358121+TMHSDigital@users.noreply.github.com>
pages.yml path-filtered its push trigger on mcp-tools.json, a file that has
never existed in this repository:

  $ git log --oneline --all -- mcp-tools.json
  (no output)

It is fleet scaffolding, not removed-feature residue. The vendored landing
builder (scripts/site/build_site.py:274) reads it optionally and returns []
when absent, because the builder serves tool repos generally and some of
those do ship an MCP server. This one does not.

The filter was inert — a path that cannot change never matches, so it neither
triggered nor suppressed a deploy. Removing it costs nothing and stops a
reader auditing pages.yml concluding an MCP server was half-removed. Nothing
else in pages.yml changes; every other path stays exactly as it was.

Closes #195

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: TMHSDigital <154358121+TMHSDigital@users.noreply.github.com>
@github-actions github-actions Bot added the ci label Sep 22, 2026
@TMHSDigital
TMHSDigital merged commit d3fba79 into main Sep 22, 2026
11 checks passed
@TMHSDigital
TMHSDigital deleted the fix/dco-signoff-and-pages-filter branch September 22, 2026 01:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

ci: pages.yml path-filters on mcp-tools.json, which this repo has never had ci: release.yml bump commits carry no DCO sign-off

1 participant