Skip to content

ci: migrate CLA enforcement to in-repo action (off cla-assistant.io)#3

Merged
chaholl merged 3 commits into
mainfrom
chore/cla-action-migration
Jun 24, 2026
Merged

ci: migrate CLA enforcement to in-repo action (off cla-assistant.io)#3
chaholl merged 3 commits into
mainfrom
chore/cla-action-migration

Conversation

@chaholl

@chaholl chaholl commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

Migrate CLA enforcement off the cla-assistant.io SaaS to an in-repo Action

Replaces the third-party cla-assistant.io status check (which had an outage that blocked merges org-wide) with the in-repo contributor-assistant/github-action@v2.6.1. Signatures are stored in the private central ledger AltairaLabs/cla-signatures (which we own — also our relicensing evidence). DCO enforcement is unchanged.

Do not merge yet. This PR is part of a coordinated rollout:

  1. Org secret PERSONAL_ACCESS_TOKEN must be set first (the Action writes signatures cross-repo; GITHUB_TOKEN can't).
  2. Validate signing + the posted status on one repo.
  3. Then merge across all gated repos; reconcile the required status check; uninstall the cla-assistant.io GitHub App.

Signing UX is unchanged: comment "I have read the CLA Document and I hereby sign the CLA". CLA doc: https://gist.github.com/chaholl/acc8f1f6c38376d00a162351f566b93e

Note: re-collect cutover — existing signers re-sign on their next PR; export the old cla-assistant.io ledger when it recovers to backfill.

@chaholl
chaholl merged commit de9dd36 into main Jun 24, 2026
6 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Jun 24, 2026
@chaholl
chaholl deleted the chore/cla-action-migration branch June 24, 2026 18:08
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant