Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 14 additions & 1 deletion .github/workflows/required-compliance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,20 @@ on:

jobs:
policy-enforcement:
name: Check CLA/DCO
# This name MUST NOT match STATUS_CONTEXT in scripts/policy_selector.py
# (currently "Check CLA/DCO"), which is also the context the org ruleset
# requires. A required status check is satisfied by EITHER a commit status
# or a check run of that name — verified experimentally: a green check run
# alone yields mergeStateStatus=CLEAN with zero commit statuses present.
#
# While the names matched, this job merely *finishing* satisfied the gate.
# That was survivable only because the script always posted a status before
# exiting; any path that returns without posting one (a failed status POST,
# or a deliberate bail on unreadable data) silently turned the gate from
# fail-closed into fail-open, merging a PR with no verification at all.
#
# Keeping the names distinct means only a real status can satisfy the gate.
name: Compliance Gate
runs-on: ubuntu-latest
permissions:
actions: write
Expand Down
3 changes: 3 additions & 0 deletions scripts/policy_selector.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,9 @@ def requires_CLA(repo, token=None, licenses_data=None, permissive_data=None, all
# --- [INTEGRATION END] -------------------------------------

# --- CONFIGURATION ---
# The context the org ruleset requires. MUST NOT match the job name in
# .github/workflows/required-compliance.yml — see the comment there for why
# letting them collide makes the gate fail open.
STATUS_CONTEXT = "Check CLA/DCO"
BOT_ALLOWLIST = ["dependabot[bot]", "github-actions[bot]", "renovate[bot]"]

Expand Down
Loading