Repository navigation
ci: let CLA policy guard run on Blacksmith as well as GitHub-hosted - #18180
Conversation
|
All contributors have signed the CLA ✍️ ✅ |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe CLA policy workflow selects a runner based on repository owner and configured runner labels. Its guard accepts GitHub-hosted runners and specified Blacksmith runners, and rejects runner names containing ChangesCLA policy runner selection
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The CLA policy guard is configured to accept the allowed Blacksmith runners, so the reported runner-name concern does not appear to block the check. No actionable merge risk is apparent from the supplied change context. 🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
Full details: Description checkExplanation The description includes a useful summary and test results, but it claims the guard supports Blacksmith runners without disclosing the reported runner-name mismatch that can make the check fail. It also omits the required Changelog, Proof, and Checklist sections. Resolution Update the runner guard to accept current Blacksmith runner names, rerun the relevant checks, and revise the description to reflect verified behavior. Add a Changelog line (or “none”), a Proof note explaining why proof does not apply to this CI-only change, and the applicable Checklist information.
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Holding this one. The review found that the runner guard only admits Blacksmith names with |
Same CI_TRUSTED_RUNNER selector and runner-identity guard as cla.yml (#18179), so the required check survives a GitHub-hosted outage. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
8c69aea to
b89235c
Compare
|
merge-override: CLA policy guard fails only on the trusted exact-head review for this guard change; validator reproduces that as the sole reason, bytes reviewed in 18186, Leo OKed admin merge |
|
Merge receipt for
|
Third of three changes letting the CLA checks run on Blacksmith. It follows #17453 (merged) and #18179 (
cla.yml).cla-policy-guard.ymlgets the sameCI_TRUSTED_RUNNERselector and the same runner check ascla.yml. That way the required "CLA policy guard" check also survives a GitHub-hosted outage. The validator does not allow guard and policy files to change in the same PR, so this PR is separate from thecla.ymlone.Tests: fork_runner_routing, self_hosted_guard, cla_guard_metadata_routing, job-scoped permissions and required-check path filters all pass, and actionlint is clean.
🤖 Generated with Claude Code
Note
Low Risk
CI-only change that mirrors an existing
cla.ymlpattern; runner selection stays on a short allowlist with an explicit runtime check, so the security model for thispull_request_targetguard is unchanged in intent.Overview
Aligns the CLA policy guard workflow with the same trusted-runner routing already used in
cla.yml, so the required check can run on GitHub-hostedubuntu-24.04or approved Blacksmith Ubuntu VMs whenCI_TRUSTED_RUNNERis set (defaulting to Blacksmith formanaflow-ai).runs-onis no longer pinned toubuntu-24.04; it uses theCI_TRUSTED_RUNNERallowlist with a safe fallback. The guard step now accepts GitHub-hosted or Blacksmith runners by name and still fails on disallowed environments (including runners whose name containsglaeda).Reviewed by Cursor Bugbot for commit b89235c. Bugbot is set up for automated code reviews on this repo. Configure here.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit
glaedaare rejected. These changes affect validation workflows only and do not change application behavior or user-facing features.