Repository navigation
chore: adopt the Kaiten licensing pack and enforce the DCO - #1
Merged
Merged
Conversation
The CLI shipped a LICENSE and nothing else of the open-source pack the Kaiten repositories share, and that LICENSE reworded Apache-2.0's section 9: an SPDX identifier promises the verbatim text. - LICENSE is now the text apache.org publishes, byte for byte. NOTICE, DCO.md, CONTRIBUTING.md and SECURITY.md come from the pack, named for the CLI; the README's license section links to Kaiten's trademark policy. - .github/workflows/dco.yml checks that every commit of a pull request is signed off by its author. It runs as it is on main (pull_request_target), so a pull request cannot edit it, and never checks out the pull request's code. The pull request template asks for the sign-off. - .github/CODEOWNERS makes @kaitencloud/engineering the owner of every path, so the ruleset's code-owner rule means an engineer's approval. - CI is split into three jobs, lint, build and test -- the checks the repositories' default-branch ruleset requires. Their steps are unchanged; govulncheck runs with lint. - GoReleaser ships NOTICE in every archive next to LICENSE and README: Apache-2.0 asks redistributions to carry it, and GoReleaser only includes LICENSE by default. A local snapshot build confirms both archive formats now hold the three files. Signed-off-by: Alexandre Bergere <[email protected]>
fuzcap
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings the CLI to the open-source pack the Kaiten repositories share, and enforces the DCO.
Licensing
LICENSEis now the text apache.org publishes, byte for byte. The previous one rewordedsection 9, and an
Apache-2.0SPDX identifier promises the verbatim text.NOTICE,DCO.md,CONTRIBUTING.mdandSECURITY.mdcome from the pack,named for the CLI.
SECURITY.mdgives two private channels: GitHub private vulnerabilityreporting and [email protected].
trademark policy.
NOTICEin every archive, next toLICENSEandREADME.md: Apache-2.0asks redistributions to carry it, and GoReleaser only includes
LICENSEby default. Checkedwith
goreleaser checkand a local snapshot build: both the.tar.gzand.ziparchiveshold the three files.
Contributions
.github/workflows/dco.ymlchecks that every commit of a pull request is signed off byits author. It runs as it is on
main(pull_request_target), so a pull request cannot editit, and it never checks out the pull request's code.
.github/PULL_REQUEST_TEMPLATE.mdasks for the sign-off..github/CODEOWNERSmakes@kaitencloud/engineeringthe owner of every path.CI
Split into three jobs,
lint,buildandtest— the checks thedefault-branchruleset requires. The steps are unchanged;
govulncheckruns withlint.After merging: add
DCOto the ruleset's required checks; the workflow runs frommain, soit starts with the next pull request.
🤖 Generated with Claude Code · ✅ Tested and approved by Alex (@Alexkuva), maintainer