From 75e7deeaf9dc6d80dfa8da68b9975fa6ff0f8aa9 Mon Sep 17 00:00:00 2001 From: Nelson Spence Date: Mon, 25 May 2026 15:07:52 -0500 Subject: [PATCH 1/2] docs: adopt the Developer Certificate of Origin (DCO) Add the DCO 1.1 text (DCO) and require contributions to be signed off via git commit -s, documented in CONTRIBUTING.md. Enforced by the DCO check now installed on the repo. Satisfies the OpenSSF Best Practices silver dco criterion. Signed-off-by: Nelson Spence --- CONTRIBUTING.md | 22 ++++++++++++++++++++++ DCO | 34 ++++++++++++++++++++++++++++++++++ 2 files changed, 56 insertions(+) create mode 100644 DCO diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index be596ff7..673113a9 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -81,3 +81,25 @@ Changelog and release notes are generated with By contributing, you agree that your contributions are dual-licensed under **MIT OR Apache-2.0**, matching the project. + +## Developer Certificate of Origin (DCO) + +All contributions must be signed off under the +[Developer Certificate of Origin](DCO) (DCO 1.1) — signing off certifies that +you wrote the change, or otherwise have the right to submit it under the +project's license. Add a sign-off line to every commit with: + +```sh +git commit -s +``` + +which appends a trailer using your `git config` identity: + +``` +Signed-off-by: Your Name +``` + +A DCO check runs on every pull request, so commits missing a valid +`Signed-off-by` will be flagged. To fix a commit you already made, use +`git commit --amend -s`; to sign off a range, `git rebase --signoff `. +(This is separate from commit *signing* — `git commit -s -S` does both.) diff --git a/DCO b/DCO new file mode 100644 index 00000000..49b8cb05 --- /dev/null +++ b/DCO @@ -0,0 +1,34 @@ +Developer Certificate of Origin +Version 1.1 + +Copyright (C) 2004, 2006 The Linux Foundation and its contributors. + +Everyone is permitted to copy and distribute verbatim copies of this +license document, but changing it is not allowed. + + +Developer's Certificate of Origin 1.1 + +By making a contribution to this project, I certify that: + +(a) The contribution was created in whole or in part by me and I + have the right to submit it under the open source license + indicated in the file; or + +(b) The contribution is based upon previous work that, to the best + of my knowledge, is covered under an appropriate open source + license and I have the right under that license to submit that + work with modifications, whether created in whole or in part + by me, under the same open source license (unless I am + permitted to submit under a different license), as indicated + in the file; or + +(c) The contribution was provided directly to me by some other + person who certified (a), (b) or (c) and I have not modified + it. + +(d) I understand and agree that this project and the contribution + are public and that a record of the contribution (including all + personal information I submit with it, including my sign-off) is + maintained indefinitely and may be redistributed consistent with + this project or the open source license(s) involved. From 7b6d50a4aa5b491d3d9e7945c8f275906bbdf894 Mon Sep 17 00:00:00 2001 From: Nelson Spence Date: Mon, 25 May 2026 15:18:59 -0500 Subject: [PATCH 2/2] docs: use ./DCO relative link in CONTRIBUTING.md Signed-off-by: Nelson Spence --- CONTRIBUTING.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 673113a9..b146acd3 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -85,7 +85,7 @@ By contributing, you agree that your contributions are dual-licensed under ## Developer Certificate of Origin (DCO) All contributions must be signed off under the -[Developer Certificate of Origin](DCO) (DCO 1.1) — signing off certifies that +[Developer Certificate of Origin](./DCO) (DCO 1.1) — signing off certifies that you wrote the change, or otherwise have the right to submit it under the project's license. Add a sign-off line to every commit with: