Skip to content

Welcome first-time contributors and credit their work - #13955

Merged
teamleaderleo merged 3 commits into
manaflow-ai:mainfrom
teamleaderleo:contributor-welcome
Sep 23, 2026
Merged

teamleaderleo merged 3 commits into
manaflow-ai:mainfrom
teamleaderleo:contributor-welcome

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Most outside contributors hear only from bots. On 2026-09-23, 765 of 810 open outside PRs had no comment or review from anyone on the team. Several were fixed on main by other work while the PR sat open, and the contributor found out on their own (#12434).

Changes

  • Welcome note. .github/workflows/contributor-welcome.yml posts .github/contributor/welcome.md once, when a first-time contributor opens a PR. The note says a person reads every outside PR, when to expect a reply, not to @mention review bots, and that we credit work we end up replacing.
    • It runs on pull_request_target with only pull-requests: write, never checks out PR code, and reads the note from the base commit so a PR can't rewrite its own welcome.
  • Credit rule for agents. A new "Outside contributors" section in CLAUDE.md: before fixing something, search open PRs for an outside one. Land theirs when you can. If you write your own fix, add Co-authored-by for them and comment on their PR with a link. Never close an outside PR without a human-written comment.

Verification

Ran locally against this branch; all pass:

  • tests/test_ci_workflow_guards_are_wired.py
  • tests/test_ci_merge_queue_required_checks.py
  • tests/test_ci_required_checks_are_bounded.py
  • tests/test_ci_reusable_job_name_lookups.py
  • tests/test_ci_reusable_workflow_permissions.py
  • tests/test_ci_change_areas.py
  • scripts/ci/check_reusable_workflow_permissions.py
  • scripts/ci/validate_test_execution_registry.py

The workflow itself hasn't run yet. It first fires on the next first-time contributor's PR after merge.

🤖 Generated with Claude Code

Of 824 open PRs from outside the team, 779 had only bot comments.
First-time contributors now get one short human-written note on their first
PR, and CLAUDE.md tells agents to land or credit an outside PR before
writing their own fix for the same problem.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 40 seconds.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8b635ada-3068-40c6-8491-33bfa959466b

📥 Commits

Reviewing files that changed from the base of the PR and between 270d970 and f831f05.

📒 Files selected for processing (3)
  • .github/contributor/welcome.md
  • .github/workflows/contributor-welcome.yml
  • CLAUDE.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

teamleaderleo and others added 2 commits September 23, 2026 06:45
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
An independent review found the gate does not do what its name says, and
measured the consequence rather than theorising it.

`author_association` answers "has no merged commit in this repo", not "this is
their first pull request". cmux merges almost no outside PRs -- that is this
change's own premise -- so a persistent contributor stays
FIRST_TIME_CONTRIBUTOR indefinitely. Of 205 open PRs carrying that association,
only 145 are distinct authors: 29% would have been greeted at least twice.
`brodynies` has 16 open PRs and would have received 16 copies of "thanks for
opening your first cmux pull request". `danielraffel` would have got a sixth
greeting three and a half months after the first. That is precisely the
"you are only talking to a bot" experience this workflow exists to fix, aimed
at the outside contributors who kept showing up anyway.

Count the author's pull requests instead; this one is always included, so more
than one means it is not their first. An unusable answer is treated as "skip"
rather than as an error: the search API can rate-limit or 422, and a
non-numeric reply would otherwise abort the step under `set -e` and leave a red
X on a newcomer's first PR. A missed greeting is recoverable; a wrong greeting
or a red check is not. A marker comment makes a duplicate impossible even when
the count is stale, which search results can be for PRs opened in a burst.

The note also contradicted the template the contributor had just filled in. It
said not to @mention review bots and named two of them, while
`pull_request_template.md` ships a "Review Trigger" block of four mentions to
paste as a comment, and the checklist asks the contributor to confirm they did.
Point at the template instead of against it.

Finally, the note promised "a person on the team reads every outside PR" while
765 of 810 open outside PRs have only bot comments. Posting that to every new
contributor is a promise the repo does not keep, and it invited a bump comment
on nearly all of them. Say what is true: the queue is long, a reply can take a
while, and a nudge is welcome.

Also declare the `contents: read` the API read needs, pin `branches: [main]` to
match every other `pull_request_target` workflow here, and read the note from
`github.workflow_sha` rather than `base.sha`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Independent review: NEEDS CHANGES — fixed in f831f05725

This posts public comments to real people, so I had it reviewed properly rather
than merging on green. The review found the gate doesn't do what its name says,
and measured the consequence instead of theorising it.

author_association answers "has no merged commit in this repo", not "this is
their first pull request". cmux merges almost no outside PRs — which is this
change's own premise — so a persistent contributor stays
FIRST_TIME_CONTRIBUTOR forever. Of 205 open PRs with that association, only
145 are distinct authors: 29% would have been greeted at least twice.

I verified the worst cases directly against the API:

author PRs greetings they'd receive
brodynies 16 16 × "thanks for opening your first cmux pull request"
aliyansajid 7 7, inside 3 days
danielraffel 6 a 6th arriving 3.5 months after the first

That is precisely the "I'm only talking to a bot" experience this workflow
exists to fix, aimed squarely at the outside contributors who kept showing up
anyway. Shipping it would have been worse than shipping nothing.

Fixed by counting the author's PRs (this one is always included, so >1 means
not their first), plus a marker comment so a duplicate is impossible even when
search results are stale — which they are for PRs opened in a burst.

While testing that, I hit a failure mode of my own fix: for an unresolvable
author the search returns 422, count becomes error text, and
[ "$count" -gt 1 ] aborts the step under bash -e — a red X on a
newcomer's first PR
. Now an unusable answer means skip, not error. A missed
greeting is recoverable; a wrong greeting or a red check on someone's first
contribution is not.

Two more, both real:

  • The note told contributors not to @mention review bots and named two of
    them — while pull_request_template.md ships a "Review Trigger" block of
    four mentions to paste, and the checklist asks them to confirm they did. Their
    first automated message contradicted the template they'd just filled in. Now
    points at it.
  • It promised "a person on the team reads every outside PR" while 765 of 810
    open outside PRs have only bot comments. Posting that to every newcomer is a
    promise the repo doesn't keep, and the follow-up line invited a bump comment
    on nearly all of them. Replaced with what's true: the queue is long, a reply
    can take a while, a nudge is welcome.

Also added the contents: read the API read needs, pinned branches: [main] to
match the other pull_request_target workflows, and switched the note read to
github.workflow_sha.

Security posture was already right and I want that on the record, since it's
the part that would actually be dangerous: pull_request_target with no
actions/checkout anywhere, so PR code is never fetched or run; no ${{ }}
inside any run: block at all, so no script-injection vector; top-level
permissions: {}; and reading the note at a base commit so a fork can't rewrite
its own welcome. No bot loop, no per-push spam.

🤖 Generated with Claude Code

@teamleaderleo
teamleaderleo merged commit 081be0f into manaflow-ai:main Sep 23, 2026
46 checks passed
@teamleaderleo
teamleaderleo deleted the contributor-welcome branch September 23, 2026 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant