Skip to content

Requiring Signed-off-by moving forward #62577

Description

@jasnell

As a heads up... moving forward, the project will require all contributors to explicitly sign-off on commits using the Signed-off-by: Name <Email> trailer in commits. This will be enforced by a new commit lint check.

The use of Signed-off-by is an explicit acceptance of the Developer Certificate of Origin (DCO) that attests that you have the right to submit the code under the OSS license used by the project (MIT in our case).

Why now?

This is really something that we should have been doing all along.

How?

When you create a commit, use the -s flag, e.g. git commit -s. This will automatically add the Signed-off-by trailer in your commit message using your configured named and email address.

Guidelines

  • The name and email used in the Signed-off-by trailer must match the name and email used in the commit author metadata. Use whatever name you want, but the email address must be a valid email.

  • Only people can sign off. The Signed-off-by trailer should not be added by bots or AI-agents.

  • If a commit has multiple authors, there should be one Signed-off-by for each author. One of those must match the author metadata for the commit.

  • Backport commits, release commits, dependency updates, and WPT fixtures added by bots are exempt.

What about existing PRs

Existing PRs will likely need to be updated before they can land, as the new commit message lint rule will flag commits that do not have the Signed-off-by trailer.

There may be rough edges

If the lint check flags your commits but you do not think the sign off should be necessary on that commit, add the Signed-off-by anyway and open an issue. We'll determine if the sign off is necessary or whether the lint rule needs to be adjusted.

/cc @nodejs/tsc @nodejs/collaborators

Activity

  1. pinned this issue on Apr 3, 2026
  2. juanarbol commented on Apr 3, 2026

    @juanarbol
    Member

    If the lint check flags your commits but you do not think the sign off should be necessary on that commit

    James, what does this mean? Are we enforcing this or not? Maybe just check first commit as we do? (In case of squash)

    I'm +1 on this

  3. cclauss commented on Apr 3, 2026

    @cclauss
    Contributor
    • Only people can sign off. The Signed-off-by trailer should not be added by bots or AI-agents.

    https://github.blog/changelog/2026-04-03-copilot-cloud-agent-signs-its-commits

  4. jasnell commented on Apr 3, 2026

    @jasnell
    MemberAuthor

    @juanarbol:

    James, what does this mean...

    Yes, I just merged the policy update and the tooling updates. All commits moving forward need to have the Signed-off-by attestation.

    @cclauss ... yes, those will be ignored. The tooling should emit a warning for detected bot commits but otherwise should not block them. We'll tweak the tooling as necessary. It might take a day or two for the tooling to start kicking in.. I don't know how often that is updated.

  5. Qard commented on Apr 3, 2026

    @Qard
    Member

    The lack of a sign-off on the commit adding a requirement to sign-off amuses me slightly. 😆

    But yes, adding a sign-off requirement sounds perfectly reasonable to me. 👍🏻

  6. jasnell commented on Apr 3, 2026

    @jasnell
    MemberAuthor

    The lack of a sign-off on the commit ...

    Sigh.. ha! Good catch. See, this is why we need tools to help enforce it.

  7. JakobJingleheimer commented on Apr 3, 2026

    @JakobJingleheimer
    Member

    I like the idea.

    Is it possible to get GitHub Desktop to do this automatically? Looks like yes desktop/desktop#21741

  8. jasnell commented on Apr 3, 2026

    @jasnell
    MemberAuthor

    Is it possible to GitHub Desktop to do this automatically?

    I'm not sure about that as I don't use GitHub Desktop. I do know that git commit -s will add it automatically, and vscode has a setting to always add it.

  9. aduh95 commented on Apr 3, 2026

    @aduh95
    Contributor
    • Only people can sign off. The Signed-off-by trailer should not be added by bots or AI-agents.

    https://github.blog/changelog/2026-04-03-copilot-cloud-agent-signs-its-commits

    This article deals with PGP signature, aka the green Verified badge; it has nothing to do with the Signed-off-by trailer, which is what this issue is about.

  10. jasnell commented on Apr 3, 2026

    @jasnell
    MemberAuthor

    And to be clear, we expect hiccups. The tooling might need tweaks here and there to correct the checks. For now, do your best and call it out when things slip through. We'll iterate until we get it right

  11. MikeMcC399 commented on Apr 3, 2026

    @MikeMcC399
    Contributor

    Will this allow for continued usage of GitHub's email privacy feature? @users.noreply.github.com

    Mine is
    66998419+MikeMcC399@users.noreply.github.com
    and I use this for all commits to GitHub

  12. jasnell commented on Apr 3, 2026

    @jasnell
    MemberAuthor

    Yes, as long as the Sign off email and commit email are the same.

  13. MikeMcC399 commented on Apr 3, 2026

    @MikeMcC399
    Contributor

    Does Node.js use the OpenJSF https://openjsf.org/cla ? I know I signed this before committing the first time to ESLint.

  14. added
    metaIssues and PRs related to the general management of the project.
    on Apr 3, 2026
  15. targos commented on Apr 3, 2026

    @targos
    Member

    Another way to add the sign off automatically that I have set up is:

    • Create a file with two empty lines followed by the commit trailer
    • Run git config commit.template /path/to/the/file
  16. 26 remaining items

  17. aduh95 commented on Apr 14, 2026

    @aduh95
    Contributor

    Tooling doesn't like my commit addition because it's too long, being 75 characters:

    Signed-off-by: Mike McCready <66998419+MikeMcC399@users.noreply.github.com>
    

    Commit message linting allows only 72 characters.

    Does linting need to be changed to allow longer e-mail addresses such as are created by GitHub private addresses? Should I log this as a separate issue?

    According to https://git-scm.com/docs/git-interpret-trailers:

    The may be split over multiple lines with each subsequent line starting with at least one whitespace, like the "folding" in RFC 822. Example:

    key: This is a very long value, with spaces and
      newlines in it.
    

    It would be interesting to check whether you could use:

    Signed-off-by: Mike McCready
      <66998419+MikeMcC399@users.noreply.github.com>
    
  18. MikeMcC399 commented on Apr 14, 2026

    @MikeMcC399
    Contributor

    @aduh95

    https://git-scm.com/docs/git-interpret-trailers:

    Thanks for finding that reference!

    It would be interesting to check whether you could use:

    Signed-off-by: Mike McCready
      <66998419+MikeMcC399@users.noreply.github.com>
    

    I can try that. There is a typo that I wouldn't otherwise have raised a PR for, but I can use that as a test case.

  19. MikeMcC399 commented on Apr 14, 2026

    @MikeMcC399
    Contributor

    @aduh95 PR #62738 has passed linting with a split-line Signed-off-by submission as you suggested.

  20. aduh95 commented on Apr 14, 2026

    @aduh95
    Contributor

    @aduh95 PR #62738 has passed linting with a split-line Signed-off-by submission as you suggested.

    But here's how NCU rephrase it:

    doc: correct typo in PR contribution instructions
    
      <66998419+MikeMcC399@users.noreply.github.com>
    
    Signed-off-by: Mike McCready <66998419+MikeMcC399@users.noreply.github.com>
    PR-URL: https://github.com/nodejs/node/pull/62738
    

    Which does not pass the validation afterwards. We need to remove the assumption that trailers are always single-line

  21. aduh95 commented on Apr 16, 2026

    @aduh95
    Contributor

    I've opened nodejs/core-validate-commit#144 and nodejs/node-core-utils#1062 to make our tooling handle longer and/or multi-line trailers. Please review!

  22. jasnell commented on Apr 17, 2026

    @jasnell
    MemberAuthor

    To clarify, bot/automations adding the Signed-off-by is something we should ignore but generate cannot prevent. The automated check applies heuristics to detect known bot patterns but they are imperfect and will require some tuning as we go.

  23. paulmillr commented on Apr 18, 2026

    @paulmillr

    IMO Signed-off-by is useless. It can't prevent forgery at all. The requirement is bureaucracy that doesn't solve the underlying issue.

    The better way would've been actually signing commits using GPG or SSH. The cryptographic signatures can't be forged, unless private keys are stolen from developer machine. Commit signing is the basic assurance functionality which has been present in git for many years.

  24. ChALkeR commented on Apr 20, 2026

    @ChALkeR
    Member

    The name and email used in the Signed-off-by trailer must match the name and email used in the commit author metadata.

    Does a co-author count here?
    If not, this will automatically make people obscure the fact that the contribution was mainly authored by claude
    I think that information is valuable for commit history

    Re-authoring commits is not nice even if the original one is by an agent
    And would make this rule followed only in letter but not in spirit

    I suggest allowing something like this in such cases (only on condition that this is not auto-added by the agent):

    Co-authored-by: human
    Signed-off-by: human
    

    See #62839 (comment)

    I think that is valid under DCO.

  25. ChALkeR commented on Apr 20, 2026

    @ChALkeR
    Member
    - If a commit has multiple authors, there should be one Signed-off-by for each author.
    + If a commit has multiple authors, there should be one Signed-off-by for each human author.

    Do not create it a requirement to obscure the fact that code was partially auto-generated.

  26. unpinned this issue on Apr 23, 2026
  27. jasnell commented on Apr 23, 2026

    @jasnell
    MemberAuthor

    Been open long enough!

  28. MikeMcC399 commented on Apr 23, 2026

    @MikeMcC399
    Contributor

    This will be enforced by a new commit lint check.

    I'm confused why this is now closed, as I would have expected that the commit link check would have been implemented before closing. That is however not yet the case.

    There are plenty of new commits in https://github.com/nodejs/node/commits/main/ that have no Signed-off-by.

    Additionally, the PR #62738 I submitted as a test case remains stuck and I can't use my regular identity:

    Signed-off-by: Mike McCready <66998419+MikeMcC399@users.noreply.github.com>
    

    Should those points be captured in separate new meta issues here?

  29. ChALkeR commented on Apr 26, 2026

    @ChALkeR
    Member

    I don't think #62577 (comment) was answered
    Especially given that Assisted-by does not even work at the moment

    At the moment, this policy requires just removing Assisted-by and Co-authored-by from tools.


    On a side note, I'm unsure of the reasoning behind Signed-off-by usage at all, as on GitHub all commits going through PRs are "signed off" by default: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service#6-contributions-under-repository-license

    Whenever you add Content to a repository containing notice of a license, you license that Content under the same terms, and you agree that you have the right to license that Content under those terms. If you have a separate agreement to license that Content under different terms, such as a contributor license agreement, that agreement will supersede.

  30. M9005 commented on Apr 26, 2026

    @M9005
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    metaIssues and PRs related to the general management of the project.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions