> For clean Markdown content of this page, append .md to this URL. For the complete documentation index, see https://docs.nvidia.com/dynamo/llms.txt. For full content including API reference and SDK examples, see https://docs.nvidia.com/dynamo/llms-full.txt.

# DCO and Licensing

Dynamo requires every commit to include a Developer Certificate of Origin (DCO) sign-off. The
sign-off certifies that you have the right to submit the contribution under the project's
[Apache 2.0 License](https://github.com/ai-dynamo/dynamo/blob/v1.5.0/LICENSE).

## Create a Signed-off Commit

Configure your Git identity with the name and email you intend to use:

```bash
git config user.name "Your Name"
git config user.email "you@example.com"
```

Add the sign-off trailer with `git commit -s`:

```bash
git commit -s -m "fix(component): describe the change"
```

The resulting commit message ends with:

```text
Signed-off-by: Your Name <you@example.com>
```

Use your real name. The trailer's name and email must match the commit author identity.

## Verify the Latest Commit

Display the complete commit message:

```bash
git show -s --format='%B' HEAD
```

Confirm that it contains the expected `Signed-off-by` line.

## Verify Every Commit

Check all commits on your branch relative to upstream `main`:

```bash
git log --format='%h %s%n%(trailers:key=Signed-off-by)' upstream/main..HEAD
```

Each listed commit must have a sign-off trailer.

## Automatic Trusted CI for Fork Pull Requests

For a fork pull request that qualifies for automatic trusted-CI approval, GitHub must report every
commit in the pull request as `Verified`. A DCO sign-off from `git commit -s` does not add a
cryptographic signature. Configure [GitHub-supported commit
signing](https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits)
and use that configuration whenever you create, amend, or rebase a commit.

Open the pull request's **Commits** tab and confirm that GitHub shows `Verified` for every commit.
If any commit is not verified, the automatic `/ok to test` comment is not posted. Signing commits
does not by itself qualify a pull request for automatic approval. When automatic approval is
unavailable, a maintainer can review the current head and comment `/ok to test <sha>` to start CI.

The repair commands below add DCO sign-offs. To add or preserve a cryptographic signature while
rewriting a commit, include `--gpg-sign` after configuring commit signing.

## Repair the Latest DCO Sign-off

If only the latest commit is missing its sign-off, amend it:

```bash
git commit --amend --signoff --no-edit
git push --force-with-lease
```

Amending changes the commit SHA. Use `--force-with-lease`, not `--force`, when updating a published
branch.

## Repair Multiple DCO Sign-offs

Start an interactive rebase that includes the unsigned commits:

```bash
git rebase -i upstream/main
```

Mark each unsigned commit as `edit`. For each stop, run:

```bash
git commit --amend --signoff --no-edit
git rebase --continue
```

After the rebase, verify every commit again, then update the remote branch:

```bash
git log --format='%h %s%n%(trailers:key=Signed-off-by)' upstream/main..HEAD
git push --force-with-lease
```

For additional recovery options, see the repository's
[DCO troubleshooting guide](https://github.com/ai-dynamo/dynamo/blob/v1.5.0/DCO.md).

## Licensing

By contributing, you agree that your contribution is licensed under the
[Apache 2.0 License](https://github.com/ai-dynamo/dynamo/blob/v1.5.0/LICENSE). All participation is
also governed by the
[Code of Conduct](https://github.com/ai-dynamo/dynamo/blob/v1.5.0/CODE_OF_CONDUCT.md).