Record individual CLA signatures from the signing comment - #28
Conversation
|
Warning Review limit reached
Next review available in: 56 minutes Limit details: You’ve used all 1 included review currently available under your plan. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 1096e58. Configure here.
| git add .github/cla-signers.json | ||
| git commit -m "Record @${CLA_GITHUB} as an individual CLA signer" | ||
| git pull --rebase origin main | ||
| git push origin HEAD:main |
There was a problem hiding this comment.
Shallow clone breaks signer rebase push
Medium Severity
The record job checks out main with the default shallow fetch-depth of 1, then runs git pull --rebase before pushing the new signer commit. If main moved during the job (for example a merged PR), the shallow rebase often fails, so the signature never lands on main and the CLA check stays red.
Reviewed by Cursor Bugbot for commit 1096e58. Configure here.


The exact PR comment now writes the commenter onto
mainand re-runs the check. Jobs use glanceable emoji (✍️ CLA,📝 Record CLA) to match Validate/Preview.Matches kentcdodds/kody#1468.
Note
Medium Risk
The
recordjob can push commits tomainwithcontents: write, so correctness of phrase matching and concurrency oncla-signers-mainmatter; scope is limited to the signers file and existing CLA rules.Overview
Individual CLA signing no longer needs a maintainer to edit
.github/cla-signers.json. Contributors still comment the exact phraseI have read the CLA and I hereby sign the CLA; a newrecordjob onissue_comment(PR comments from human users containing that phrase) validates the comment viacheck-cla.mjs, commits the signer tomain, posts or updates a confirmation comment, and re-runs the PRCLAworkflow when possible.The existing PR
clajob is unchanged in behavior (still checks identities against signers on the base branch) but is limited topull_requestevents; workflow copy now tells contributors the workflow records them automatically.tools/ci/check-cla.mjsgains--record-signerrecording, exact-phrase matching, idempotent signer append, and stable serialization of the signers file; tests cover recording and serialization.Contributor docs and ADR 0001 describe the automated path; maintainer steps now only cover entity CLAs.
Reviewed by Cursor Bugbot for commit 1096e58. Bugbot is set up for automated code reviews on this repo. Configure here.