Skip to content

feat(convex): webhook-driven sandbox state sync #231

feat(convex): webhook-driven sandbox state sync

feat(convex): webhook-driven sandbox state sync #231

Workflow file for this run

name: '[PR] CLA Assistant'

Check warning on line 1 in .github/workflows/cla.yml

View workflow run for this annotation

GitHub Actions / [PR] CLA Assistant

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
on:
issue_comment:
types: [created]
pull_request_target:
types: [opened, closed, synchronize]
# PRs created with the repo's own GITHUB_TOKEN (release-please's release PRs,
# always authored by github-actions[bot]) never fire `pull_request_target`,
# which leaves the required "CLA signed" check stuck at "Expected" forever.
# The plain `pull_request` event does fire for them, so listen to it too; the
# step condition below restricts this path to exactly that author, so human
# PRs and app-authored bot PRs (dependabot, renovate -- whose
# `pull_request_target` works) are not double-checked, and fork PRs
# (read-only token) are not picked up here.
pull_request:
types: [opened, reopened, synchronize]
# Least-privilege token. `pull_request_target` runs in the BASE repo context so
# that PRs from forks can still write the signature file and set the status
# check. This job must ONLY run the trusted CLA action -- never check out or
# execute the PR head's code here.
permissions:
actions: write # re-run the check via the rerun API
contents: write # commit the signature file to the signatures branch
pull-requests: write # post / refresh the CLA comment
statuses: write # set the pass/fail commit status that gates merge
# Serialize CLA runs repo-wide: every PR writes the same signatures branch/file,
# so concurrent signatures could otherwise race and lose a write. Queue, don't
# cancel, so no signature is dropped.
concurrency:
group: cla-signatures
cancel-in-progress: false
jobs:
cla-assistant:
name: CLA signed
runs-on: ubuntu-latest
steps:
- name: CLA Assistant
if: >-
(github.event_name == 'issue_comment' &&
github.event.issue.pull_request != null &&
(github.event.comment.body == 'recheck' ||
github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA')) ||
(github.event_name == 'pull_request_target' &&
(github.event.action != 'closed' ||
(github.event.pull_request.merged == true &&
github.event.pull_request.user.login != 'github-actions[bot]'))) ||
(github.event_name == 'pull_request' &&
github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.user.login == 'github-actions[bot]')
# contributor-assistant/github-action v2.6.1 (upstream archived -- pin by SHA)
uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
# Where signatures are stored, committed to `branch` below. That branch
# may be protected against force-pushes and deletions, but must NOT
# restrict who can push, require pull requests, or be locked -- the
# default GITHUB_TOKEN pushes normal signature commits directly to it.
path-to-signatures: 'signatures/version1/cla.json'
branch: 'cla-signatures'
# The document contributors are agreeing to.
path-to-document: 'https://github.com/daytona/integrations/blob/main/CLA.md'
# Bots and automation cannot sign -- exempt them. Explicit logins only:
# a `bot*` wildcard would let a human register a matching username
# (e.g. "bottle") and bypass the CLA gate.
allowlist: 'dependabot[bot],renovate[bot],github-actions[bot]'
# Lock the PR conversation after merge so a signature comment can't be
# deleted/revoked after the fact. Not applied to release-please's PRs
# (authored by github-actions[bot]; the merge-close path above skips
# them): they carry no signature, and the lock lands seconds before
# release-please posts its own post-merge comment and relabel, which
# then fails with "issue is locked" after the tag and release exist.
lock-pullrequest-aftermerge: true
custom-notsigned-prcomment: >-
Thank you for your contribution! Before we can merge it, we need you
to sign the [Daytona Contributor License Agreement](https://github.com/daytona/integrations/blob/main/CLA.md).
You only need to do this once, and it will cover all of your future
contributions to this repository. If you are signing on behalf of an
entity (for example, your employer), please also reply with the
entity's legal name and your role or title, and confirm that you are
authorized to bind it. Please read the CLA and, if you agree, post the
following comment on this PR:
custom-pr-sign-comment: 'I have read the CLA Document and I hereby sign the CLA'
custom-allsigned-prcomment: >-
All contributors have signed the CLA. ✅ Thank you!