Skip to content

Record individual CLA signatures from the signing comment - #28

Merged
kentcdodds merged 3 commits into
mainfrom
cursor/cla-auto-record
Aug 16, 2026
Merged

kentcdodds merged 3 commits into
mainfrom
cursor/cla-auto-record

Conversation

@kentcdodds

@kentcdodds kentcdodds commented Aug 16, 2026 •

Copy link
Copy Markdown
Owner

The exact PR comment now writes the commenter onto main and re-runs the check. Jobs use glanceable emoji (✍️ CLA, 📝 Record CLA) to match Validate/Preview.

Matches kentcdodds/kody#1468.


Note

Medium Risk
The record job can push commits to main with contents: write, so correctness of phrase matching and concurrency on cla-signers-main matter; scope is limited to the signers file and existing CLA rules.

Overview
Individual CLA signing no longer needs a maintainer to edit .github/cla-signers.json. Contributors still comment the exact phrase I have read the CLA and I hereby sign the CLA; a new record job on issue_comment (PR comments from human users containing that phrase) validates the comment via check-cla.mjs, commits the signer to main, posts or updates a confirmation comment, and re-runs the PR CLA workflow when possible.

The existing PR cla job is unchanged in behavior (still checks identities against signers on the base branch) but is limited to pull_request events; workflow copy now tells contributors the workflow records them automatically. tools/ci/check-cla.mjs gains --record-signer recording, exact-phrase matching, idempotent signer append, and stable serialization of the signers file; tests cover recording and serialization.

Contributor docs and ADR 0001 describe the automated path; maintainer steps now only cover entity CLAs.

Reviewed by Cursor Bugbot for commit 1096e58. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Aug 16, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@kentcdodds, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 56 minutes

Limit details: You’ve used all 1 included review currently available under your plan.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 7ba2d5a7-49fa-48de-a827-12cd7a003519

📥 Commits

Reviewing files that changed from the base of the PR and between 129818f and 1096e58.

📒 Files selected for processing (5)
  • .github/workflows/cla.yml
  • docs/contributing/decisions/0001-inbound-cla.md
  • docs/contributing/inbound-contributions.md
  • tools/ci/check-cla.mjs
  • tools/ci/check-cla.node.test.ts
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch cursor/cla-auto-record

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kentcdodds
kentcdodds merged commit 5b754c5 into main Aug 16, 2026
5 checks passed
@kentcdodds
kentcdodds deleted the cursor/cla-auto-record branch August 16, 2026 06:51

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1096e58. Configure here.

Comment thread .github/workflows/cla.yml
git add .github/cla-signers.json
git commit -m "Record @${CLA_GITHUB} as an individual CLA signer"
git pull --rebase origin main
git push origin HEAD:main

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shallow clone breaks signer rebase push

Medium Severity

The record job checks out main with the default shallow fetch-depth of 1, then runs git pull --rebase before pushing the new signer commit. If main moved during the job (for example a merged PR), the shallow rebase often fails, so the signature never lands on main and the CLA check stays red.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 1096e58. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant