Repository navigation
ci: let CLA Assistant run on Blacksmith as well as GitHub-hosted - #18179
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe CLA Assistant workflow now selects a runner based on repository ownership and the ChangesCLA workflow runner
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Merge Risk: ⚪ Minimal · up to The CLA workflow has no established outstanding issue from this change and is ready to merge after normal checks. 🚥 Pre-merge checks | ✅ 25✅ Passed checks (25 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Holding this one. The review found that the runner guard only admits Blacksmith names with |
runs-on uses the CI_TRUSTED_RUNNER selector (GitHub-hosted ubuntu-24.04 or the two Blacksmith Ubuntu labels, defaulting to Blacksmith), plus a first step that refuses any runner that is neither GitHub-hosted nor a Blacksmith VM for those labels, or that is one of our glaeda hosts. These are the exact successor bytes validate-cla-policy.rb pins (#18186). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
cfacb36 to
e24be8c
Compare
|
merge-override: CLA policy guard fails only on the trusted exact-head review for this policy change; validator reproduces that as the sole reason, bytes match the reviewed pin, Leo OKed admin merge |
|
Merge receipt for
|
Same CI_TRUSTED_RUNNER selector and runner-identity guard as cla.yml (#18179), so the required check survives a GitHub-hosted outage. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Second of three changes letting the CLA checks run on Blacksmith (the first is #17453, merged as
abe78bc141f5).cla.ymlnow picks its runner with the sameCI_TRUSTED_RUNNERselector backend-migrations uses. That selector allows only GitHub-hostedubuntu-24.04or the two Blacksmith Ubuntu labels, and defaults toblacksmith-4vcpu-ubuntu-2404. A new first step refuses any runner that is neither GitHub-hosted nor a Blacksmith VM, plus anyglaedahost. These bytes hash to exactly the successor pin invalidate-cla-policy.rb(317432cd…→6ef80bb2…, re-pinned in #18186 for Blacksmith's current runner names).If Blacksmith misbehaves, setting
CI_TRUSTED_RUNNER=ubuntu-24.04moves the check back to GitHub-hosted without a PR.Tests: fork_runner_routing, self_hosted_guard, cla_guard_metadata_routing, job-scoped permissions and required-check path filters all pass, and actionlint is clean.
🤖 Generated with Claude Code
Note
Medium Risk
The job still runs with write permissions on fork pull requests; runner choice is broader but constrained by the new guard and existing policy validation.
Overview
CLA Assistant no longer hardcodes
ubuntu-24.04. Formanaflow-aiit uses the sameCI_TRUSTED_RUNNERselector asbackend-migrations: only GitHub-hostedubuntu-24.04or the two Blacksmith Ubuntu labels, defaulting toblacksmith-4vcpu-ubuntu-2404. Forks and other owners still getubuntu-24.04.A new first step fails the job if the runner is not GitHub-hosted or a Blacksmith VM (prefix checks on
runner.name), or if the name containsglaeda, so ephemeral-only policy still holds when Blacksmith shows up as self-hosted. Comments note thatvalidate-cla-policy.rbpins this workflow text.Reviewed by Cursor Bugbot for commit e24be8c. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by CodeRabbit