fix(stella-tools): name real forge inputs in gh redirects #14812
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Contributor License Agreement gate. | |
| # | |
| # Stella is dual-licensed (AGPL-3.0-only + commercial — see LICENSING.md), which | |
| # only works if every contribution carries a sublicensing grant. A contribution | |
| # merged without one is AGPL-only forever and can never ship in a commercial | |
| # build, so this is a real gate on external pull requests. | |
| # | |
| # Signatures are recorded in a separate repo (macanderson/stella-cla-signatures) | |
| # so the signature ledger is not rewritable by anyone with push access here. | |
| # Contributors sign once by commenting on their first PR; later PRs pass | |
| # automatically. | |
| # | |
| # SETUP (one time, before this gate can pass): | |
| # 1. Create the PRIVATE repo macanderson/stella-cla-signatures with an | |
| # initial commit on `main`. | |
| # 2. Create a PAT with `repo` scope on that repo and add it to this repo's | |
| # secrets as PERSONAL_ACCESS_TOKEN. | |
| # Until then this job fails closed on external PRs — which is the safe | |
| # direction, but merge nothing from outside until setup is done. | |
| name: cla | |
| on: | |
| issue_comment: | |
| types: [created] | |
| pull_request_target: | |
| types: [opened, synchronize, reopened] | |
| permissions: | |
| # Genuinely required, not copy-pasted from the upstream README (#918): | |
| # signing happens via an `issue_comment` on the PR, which has no commit SHA | |
| # of its own to attach a passing status to. `contributor-assistant`'s | |
| # `setupClaCheck.ts` reacts to "all contributors now signed" by calling | |
| # `reRunLastWorkFlowIfRequired()` (src/pullRerunRunner.ts), which calls | |
| # `octokit.actions.reRunWorkflow()` on the ORIGINAL `pull_request_target` | |
| # run that failed before the signature existed — that's what flips the | |
| # PR's check to green without waiting for a new push. Without `actions: | |
| # write` a contributor could sign and the PR would stay red forever. | |
| actions: write | |
| contents: read | |
| pull-requests: write | |
| statuses: write | |
| jobs: | |
| cla: | |
| runs-on: ubuntu-latest | |
| # Maintainers and bots do not sign: Oxagen already holds the rights to its | |
| # own commits, and dependabot/github-actions produce mechanical changes | |
| # (lockfile bumps, version syncs) that carry no separable copyright. | |
| if: >- | |
| (github.event.issue.pull_request && contains(github.event.comment.body, 'I have read the CLA Document and I hereby sign the CLA')) | |
| || (github.event_name == 'pull_request_target' | |
| && github.event.pull_request.user.login != 'macanderson' | |
| && github.event.pull_request.user.type != 'Bot') | |
| steps: | |
| - name: Check or record CLA signature | |
| uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08 # v2.6.1 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| PERSONAL_ACCESS_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }} | |
| with: | |
| path-to-signatures: signatures/v1/cla.json | |
| path-to-document: https://github.com/macanderson/stella/blob/main/CLA.md | |
| branch: main | |
| remote-organization-name: macanderson | |
| remote-repository-name: stella-cla-signatures | |
| allowlist: macanderson,dependabot[bot],github-actions[bot] | |
| custom-notsigned-prcomment: >- | |
| Thanks for the pull request! Before it can be merged we need you to | |
| sign the [Contributor License Agreement](https://github.com/macanderson/stella/blob/main/CLA.md). | |
| Stella is dual-licensed — AGPL-3.0-only for everyone, plus | |
| commercial licenses for users who cannot accept the AGPL's terms. | |
| The CLA is what keeps both tracks possible. **You keep your | |
| copyright**, and your contribution stays open under the AGPL; the | |
| agreement adds the right for Oxagen to also include it in | |
| commercially licensed builds. It takes one comment, once. | |
| Please read the CLA and reply below with: | |
| custom-pr-sign-comment: "I have read the CLA Document and I hereby sign the CLA" | |
| custom-allsigned-prcomment: "All contributors have signed the CLA. Thanks!" | |
| lock-pullrequest-aftermerge: false |