Repository navigation
Welcome first-time contributors and credit their work - #13955
Conversation
Of 824 open PRs from outside the team, 779 had only bot comments. First-time contributors now get one short human-written note on their first PR, and CLAUDE.md tells agents to land or credit an outside PR before writing their own fix for the same problem. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Warning Review limit reachedNext included review available in 40 seconds. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An independent review found the gate does not do what its name says, and measured the consequence rather than theorising it. `author_association` answers "has no merged commit in this repo", not "this is their first pull request". cmux merges almost no outside PRs -- that is this change's own premise -- so a persistent contributor stays FIRST_TIME_CONTRIBUTOR indefinitely. Of 205 open PRs carrying that association, only 145 are distinct authors: 29% would have been greeted at least twice. `brodynies` has 16 open PRs and would have received 16 copies of "thanks for opening your first cmux pull request". `danielraffel` would have got a sixth greeting three and a half months after the first. That is precisely the "you are only talking to a bot" experience this workflow exists to fix, aimed at the outside contributors who kept showing up anyway. Count the author's pull requests instead; this one is always included, so more than one means it is not their first. An unusable answer is treated as "skip" rather than as an error: the search API can rate-limit or 422, and a non-numeric reply would otherwise abort the step under `set -e` and leave a red X on a newcomer's first PR. A missed greeting is recoverable; a wrong greeting or a red check is not. A marker comment makes a duplicate impossible even when the count is stale, which search results can be for PRs opened in a burst. The note also contradicted the template the contributor had just filled in. It said not to @mention review bots and named two of them, while `pull_request_template.md` ships a "Review Trigger" block of four mentions to paste as a comment, and the checklist asks the contributor to confirm they did. Point at the template instead of against it. Finally, the note promised "a person on the team reads every outside PR" while 765 of 810 open outside PRs have only bot comments. Posting that to every new contributor is a promise the repo does not keep, and it invited a bump comment on nearly all of them. Say what is true: the queue is long, a reply can take a while, and a nudge is welcome. Also declare the `contents: read` the API read needs, pin `branches: [main]` to match every other `pull_request_target` workflow here, and read the note from `github.workflow_sha` rather than `base.sha`. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Independent review: NEEDS CHANGES — fixed in
|
| author | PRs | greetings they'd receive |
|---|---|---|
brodynies |
16 | 16 × "thanks for opening your first cmux pull request" |
aliyansajid |
7 | 7, inside 3 days |
danielraffel |
6 | a 6th arriving 3.5 months after the first |
That is precisely the "I'm only talking to a bot" experience this workflow
exists to fix, aimed squarely at the outside contributors who kept showing up
anyway. Shipping it would have been worse than shipping nothing.
Fixed by counting the author's PRs (this one is always included, so >1 means
not their first), plus a marker comment so a duplicate is impossible even when
search results are stale — which they are for PRs opened in a burst.
While testing that, I hit a failure mode of my own fix: for an unresolvable
author the search returns 422, count becomes error text, and
[ "$count" -gt 1 ] aborts the step under bash -e — a red X on a
newcomer's first PR. Now an unusable answer means skip, not error. A missed
greeting is recoverable; a wrong greeting or a red check on someone's first
contribution is not.
Two more, both real:
- The note told contributors not to @mention review bots and named two of
them — whilepull_request_template.mdships a "Review Trigger" block of
four mentions to paste, and the checklist asks them to confirm they did. Their
first automated message contradicted the template they'd just filled in. Now
points at it. - It promised "a person on the team reads every outside PR" while 765 of 810
open outside PRs have only bot comments. Posting that to every newcomer is a
promise the repo doesn't keep, and the follow-up line invited a bump comment
on nearly all of them. Replaced with what's true: the queue is long, a reply
can take a while, a nudge is welcome.
Also added the contents: read the API read needs, pinned branches: [main] to
match the other pull_request_target workflows, and switched the note read to
github.workflow_sha.
Security posture was already right and I want that on the record, since it's
the part that would actually be dangerous: pull_request_target with no
actions/checkout anywhere, so PR code is never fetched or run; no ${{ }}
inside any run: block at all, so no script-injection vector; top-level
permissions: {}; and reading the note at a base commit so a fork can't rewrite
its own welcome. No bot loop, no per-push spam.
🤖 Generated with Claude Code
Most outside contributors hear only from bots. On 2026-09-23, 765 of 810 open outside PRs had no comment or review from anyone on the team. Several were fixed on
mainby other work while the PR sat open, and the contributor found out on their own (#12434).Changes
.github/workflows/contributor-welcome.ymlposts.github/contributor/welcome.mdonce, when a first-time contributor opens a PR. The note says a person reads every outside PR, when to expect a reply, not to @mention review bots, and that we credit work we end up replacing.pull_request_targetwith onlypull-requests: write, never checks out PR code, and reads the note from the base commit so a PR can't rewrite its own welcome.CLAUDE.md: before fixing something, search open PRs for an outside one. Land theirs when you can. If you write your own fix, addCo-authored-byfor them and comment on their PR with a link. Never close an outside PR without a human-written comment.Verification
Ran locally against this branch; all pass:
tests/test_ci_workflow_guards_are_wired.pytests/test_ci_merge_queue_required_checks.pytests/test_ci_required_checks_are_bounded.pytests/test_ci_reusable_job_name_lookups.pytests/test_ci_reusable_workflow_permissions.pytests/test_ci_change_areas.pyscripts/ci/check_reusable_workflow_permissions.pyscripts/ci/validate_test_execution_registry.pyThe workflow itself hasn't run yet. It first fires on the next first-time contributor's PR after merge.
🤖 Generated with Claude Code