Skip to content

fix(stella-tools): name real forge inputs in gh redirects #14812

fix(stella-tools): name real forge inputs in gh redirects

fix(stella-tools): name real forge inputs in gh redirects #14812

Workflow file for this run

# Contributor License Agreement gate.
#
# Stella is dual-licensed (AGPL-3.0-only + commercial — see LICENSING.md), which
# only works if every contribution carries a sublicensing grant. A contribution
# merged without one is AGPL-only forever and can never ship in a commercial
# build, so this is a real gate on external pull requests.
#
# Signatures are recorded in a separate repo (macanderson/stella-cla-signatures)
# so the signature ledger is not rewritable by anyone with push access here.
# Contributors sign once by commenting on their first PR; later PRs pass
# automatically.
#
# SETUP (one time, before this gate can pass):
# 1. Create the PRIVATE repo macanderson/stella-cla-signatures with an
# initial commit on `main`.
# 2. Create a PAT with `repo` scope on that repo and add it to this repo's
# secrets as PERSONAL_ACCESS_TOKEN.
# Until then this job fails closed on external PRs — which is the safe
# direction, but merge nothing from outside until setup is done.
name: cla
on:
issue_comment:
types: [created]
pull_request_target:
types: [opened, synchronize, reopened]
permissions:
# Genuinely required, not copy-pasted from the upstream README (#918):
# signing happens via an `issue_comment` on the PR, which has no commit SHA
# of its own to attach a passing status to. `contributor-assistant`'s
# `setupClaCheck.ts` reacts to "all contributors now signed" by calling
# `reRunLastWorkFlowIfRequired()` (src/pullRerunRunner.ts), which calls
# `octokit.actions.reRunWorkflow()` on the ORIGINAL `pull_request_target`
# run that failed before the signature existed — that's what flips the
# PR's check to green without waiting for a new push. Without `actions:
# write` a contributor could sign and the PR would stay red forever.
actions: write
contents: read
pull-requests: write
statuses: write
jobs:
cla:
runs-on: ubuntu-latest
# Maintainers and bots do not sign: Oxagen already holds the rights to its
# own commits, and dependabot/github-actions produce mechanical changes
# (lockfile bumps, version syncs) that carry no separable copyright.
if: >-
(github.event.issue.pull_request && contains(github.event.comment.body, 'I have read the CLA Document and I hereby sign the CLA'))
|| (github.event_name == 'pull_request_target'
&& github.event.pull_request.user.login != 'macanderson'
&& github.event.pull_request.user.type != 'Bot')
steps:
- name: Check or record CLA signature
uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08 # v2.6.1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PERSONAL_ACCESS_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }}
with:
path-to-signatures: signatures/v1/cla.json
path-to-document: https://github.com/macanderson/stella/blob/main/CLA.md
branch: main
remote-organization-name: macanderson
remote-repository-name: stella-cla-signatures
allowlist: macanderson,dependabot[bot],github-actions[bot]
custom-notsigned-prcomment: >-
Thanks for the pull request! Before it can be merged we need you to
sign the [Contributor License Agreement](https://github.com/macanderson/stella/blob/main/CLA.md).
Stella is dual-licensed — AGPL-3.0-only for everyone, plus
commercial licenses for users who cannot accept the AGPL's terms.
The CLA is what keeps both tracks possible. **You keep your
copyright**, and your contribution stays open under the AGPL; the
agreement adds the right for Oxagen to also include it in
commercially licensed builds. It takes one comment, once.
Please read the CLA and reply below with:
custom-pr-sign-comment: "I have read the CLA Document and I hereby sign the CLA"
custom-allsigned-prcomment: "All contributors have signed the CLA. Thanks!"
lock-pullrequest-aftermerge: false