Skip to content

chore: adopt the Kaiten licensing pack and enforce the DCO - #1

Merged
Alex (Alexkuva) merged 1 commit into
mainfrom
chore/oss-licensing
Oct 1, 2026
Merged

Alex (Alexkuva) merged 1 commit into
mainfrom
chore/oss-licensing

Conversation

@Alexkuva

Copy link
Copy Markdown
Contributor

Brings the CLI to the open-source pack the Kaiten repositories share, and enforces the DCO.

Licensing

  • LICENSE is now the text apache.org publishes, byte for byte. The previous one reworded
    section 9, and an Apache-2.0 SPDX identifier promises the verbatim text.
  • NOTICE, DCO.md, CONTRIBUTING.md and SECURITY.md come from the pack,
    named for the CLI. SECURITY.md gives two private channels: GitHub private vulnerability
    reporting and [email protected].
  • README: the license section now covers the DCO and links to Kaiten's
    trademark policy.
  • GoReleaser ships NOTICE in every archive, next to LICENSE and README.md: Apache-2.0
    asks redistributions to carry it, and GoReleaser only includes LICENSE by default. Checked
    with goreleaser check and a local snapshot build: both the .tar.gz and .zip archives
    hold the three files.

Contributions

  • .github/workflows/dco.yml checks that every commit of a pull request is signed off by
    its author. It runs as it is on main (pull_request_target), so a pull request cannot edit
    it, and it never checks out the pull request's code.
  • .github/PULL_REQUEST_TEMPLATE.md asks for the sign-off.
  • .github/CODEOWNERS makes @kaitencloud/engineering the owner of every path.

CI

Split into three jobs, lint, build and test — the checks the default-branch
ruleset requires. The steps are unchanged; govulncheck runs with lint.

After merging: add DCO to the ruleset's required checks; the workflow runs from main, so
it starts with the next pull request.

🤖 Generated with Claude Code · ✅ Tested and approved by Alex (@Alexkuva), maintainer

The CLI shipped a LICENSE and nothing else of the open-source pack the
Kaiten repositories share, and that LICENSE reworded Apache-2.0's section
9: an SPDX identifier promises the verbatim text.

- LICENSE is now the text apache.org publishes, byte for byte. NOTICE,
  DCO.md, CONTRIBUTING.md and SECURITY.md come from the pack, named for
  the CLI; the README's license section links to Kaiten's trademark policy.
- .github/workflows/dco.yml checks that every commit of a pull request is
  signed off by its author. It runs as it is on main (pull_request_target),
  so a pull request cannot edit it, and never checks out the pull
  request's code. The pull request template asks for the sign-off.
- .github/CODEOWNERS makes @kaitencloud/engineering the owner of every
  path, so the ruleset's code-owner rule means an engineer's approval.
- CI is split into three jobs, lint, build and test -- the checks the
  repositories' default-branch ruleset requires. Their steps are
  unchanged; govulncheck runs with lint.
- GoReleaser ships NOTICE in every archive next to LICENSE and README:
  Apache-2.0 asks redistributions to carry it, and GoReleaser only
  includes LICENSE by default. A local snapshot build confirms both
  archive formats now hold the three files.

Signed-off-by: Alexandre Bergere <[email protected]>
@Alexkuva
Alex (Alexkuva) requested a review from fuzcap October 1, 2026 08:23
@Alexkuva
Alex (Alexkuva) merged commit 9f50c98 into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants