From 4685421d45d7d1e6b577bf25a8ebc25387972e8b Mon Sep 17 00:00:00 2001 From: Peter Gonda Date: Wed, 2 Sep 2026 09:23:51 +0200 Subject: [PATCH] ci: add CLA Assistant bot Adds a self-hosted contributor-assistant workflow that asks contributors to sign the CLA (CLA.md) on their PRs and records signatures under signatures/. Also adds signatures/** to the Docker publish paths-ignore so signature commits don't trigger image rebuilds. Requires a repo secret PERSONAL_ACCESS_TOKEN (classic PAT, repo scope) for the bot to store signatures. Co-Authored-By: Claude Opus 4.8 --- .github/workflows/cla.yml | 47 +++++++++++++++++++++++++++++++++++ .github/workflows/nomploy.yml | 1 + 2 files changed, 48 insertions(+) create mode 100644 .github/workflows/cla.yml diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml new file mode 100644 index 000000000..e2316edc6 --- /dev/null +++ b/.github/workflows/cla.yml @@ -0,0 +1,47 @@ +name: CLA Assistant + +# Asks first-time contributors to sign the CLA (see CLA.md) by commenting on +# their PR, and records signatures. Uses the self-hosted contributor-assistant +# action — no external SaaS needed. +# +# REQUIRED ONE-TIME SETUP (by a repo admin): +# Create a classic Personal Access Token with "repo" scope and add it as a +# repository secret named PERSONAL_ACCESS_TOKEN. The action needs it to store +# the signatures file. GITHUB_TOKEN alone is not sufficient. + +on: + issue_comment: + types: [created] + pull_request_target: + types: [opened, closed, synchronize] + +permissions: + actions: write + contents: write + pull-requests: write + statuses: write + +jobs: + cla: + runs-on: ubuntu-latest + steps: + - name: CLA Assistant + if: > + (github.event.comment.body == 'recheck' || + github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || + github.event_name == 'pull_request_target' + uses: contributor-assistant/github-action@v2.6.1 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + PERSONAL_ACCESS_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }} + with: + path-to-document: "https://github.com/Nomploy/nomploy/blob/main/CLA.md" + path-to-signatures: "signatures/version1/cla.json" + branch: "main" + allowlist: "dependabot[bot],*[bot]" + custom-notsigned-prcomment: > + Thank you for your contribution! Please sign our + [Contributor License Agreement](https://github.com/Nomploy/nomploy/blob/main/CLA.md) + by posting the following comment: + custom-pr-sign-comment: "I have read the CLA Document and I hereby sign the CLA" + custom-allsigned-prcomment: "✅ All contributors have signed the CLA." diff --git a/.github/workflows/nomploy.yml b/.github/workflows/nomploy.yml index 6e6f1de52..b459e6781 100644 --- a/.github/workflows/nomploy.yml +++ b/.github/workflows/nomploy.yml @@ -22,6 +22,7 @@ on: - "NOTICE" - ".github/ISSUE_TEMPLATE/**" - ".github/FUNDING.yml" + - "signatures/**" workflow_dispatch: permissions: