From adc8acba9bd20dc8c7ad9a9131f6e5c06e118acb Mon Sep 17 00:00:00 2001 From: John McCall Date: Fri, 11 Sep 2026 10:04:33 -0400 Subject: [PATCH] fix(ci): pin uv-lock-refresh commit author to overture-pull-requester create-pull-request's author input defaults to github.actor (the triggering user) when unset, not the app token's identity. That mismatched the Signed-off-by trailer and failed DCO on PR #739 (triggered manually via workflow_dispatch). Pin author/committer to the app so this doesn't vary by trigger actor. Fixes #740 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: John McCall --- .github/workflows/uv-lock-refresh.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/uv-lock-refresh.yml b/.github/workflows/uv-lock-refresh.yml index 27b3934ea..0747fb0fa 100644 --- a/.github/workflows/uv-lock-refresh.yml +++ b/.github/workflows/uv-lock-refresh.yml @@ -55,6 +55,11 @@ jobs: - uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 with: # zizmor: ignore[superfluous-actions] token: ${{ steps.app-token.outputs.token }} + # author/committer must match the Signed-off-by address for DCO to pass. + # create-pull-request otherwise defaults author to whoever triggered the + # run (github.actor), which fails DCO on a manual workflow_dispatch. + author: overture-pull-requester[bot] + committer: overture-pull-requester[bot] commit-message: | [CHORE](deps) refresh uv.lock