feat(convex): webhook-driven sandbox state sync #231
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: '[PR] CLA Assistant' | ||
|
Check warning on line 1 in .github/workflows/cla.yml
|
||
| on: | ||
| issue_comment: | ||
| types: [created] | ||
| pull_request_target: | ||
| types: [opened, closed, synchronize] | ||
| # PRs created with the repo's own GITHUB_TOKEN (release-please's release PRs, | ||
| # always authored by github-actions[bot]) never fire `pull_request_target`, | ||
| # which leaves the required "CLA signed" check stuck at "Expected" forever. | ||
| # The plain `pull_request` event does fire for them, so listen to it too; the | ||
| # step condition below restricts this path to exactly that author, so human | ||
| # PRs and app-authored bot PRs (dependabot, renovate -- whose | ||
| # `pull_request_target` works) are not double-checked, and fork PRs | ||
| # (read-only token) are not picked up here. | ||
| pull_request: | ||
| types: [opened, reopened, synchronize] | ||
| # Least-privilege token. `pull_request_target` runs in the BASE repo context so | ||
| # that PRs from forks can still write the signature file and set the status | ||
| # check. This job must ONLY run the trusted CLA action -- never check out or | ||
| # execute the PR head's code here. | ||
| permissions: | ||
| actions: write # re-run the check via the rerun API | ||
| contents: write # commit the signature file to the signatures branch | ||
| pull-requests: write # post / refresh the CLA comment | ||
| statuses: write # set the pass/fail commit status that gates merge | ||
| # Serialize CLA runs repo-wide: every PR writes the same signatures branch/file, | ||
| # so concurrent signatures could otherwise race and lose a write. Queue, don't | ||
| # cancel, so no signature is dropped. | ||
| concurrency: | ||
| group: cla-signatures | ||
| cancel-in-progress: false | ||
| jobs: | ||
| cla-assistant: | ||
| name: CLA signed | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: CLA Assistant | ||
| if: >- | ||
| (github.event_name == 'issue_comment' && | ||
| github.event.issue.pull_request != null && | ||
| (github.event.comment.body == 'recheck' || | ||
| github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA')) || | ||
| (github.event_name == 'pull_request_target' && | ||
| (github.event.action != 'closed' || | ||
| (github.event.pull_request.merged == true && | ||
| github.event.pull_request.user.login != 'github-actions[bot]'))) || | ||
| (github.event_name == 'pull_request' && | ||
| github.event.pull_request.head.repo.full_name == github.repository && | ||
| github.event.pull_request.user.login == 'github-actions[bot]') | ||
| # contributor-assistant/github-action v2.6.1 (upstream archived -- pin by SHA) | ||
| uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08 | ||
| env: | ||
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| with: | ||
| # Where signatures are stored, committed to `branch` below. That branch | ||
| # may be protected against force-pushes and deletions, but must NOT | ||
| # restrict who can push, require pull requests, or be locked -- the | ||
| # default GITHUB_TOKEN pushes normal signature commits directly to it. | ||
| path-to-signatures: 'signatures/version1/cla.json' | ||
| branch: 'cla-signatures' | ||
| # The document contributors are agreeing to. | ||
| path-to-document: 'https://github.com/daytona/integrations/blob/main/CLA.md' | ||
| # Bots and automation cannot sign -- exempt them. Explicit logins only: | ||
| # a `bot*` wildcard would let a human register a matching username | ||
| # (e.g. "bottle") and bypass the CLA gate. | ||
| allowlist: 'dependabot[bot],renovate[bot],github-actions[bot]' | ||
| # Lock the PR conversation after merge so a signature comment can't be | ||
| # deleted/revoked after the fact. Not applied to release-please's PRs | ||
| # (authored by github-actions[bot]; the merge-close path above skips | ||
| # them): they carry no signature, and the lock lands seconds before | ||
| # release-please posts its own post-merge comment and relabel, which | ||
| # then fails with "issue is locked" after the tag and release exist. | ||
| lock-pullrequest-aftermerge: true | ||
| custom-notsigned-prcomment: >- | ||
| Thank you for your contribution! Before we can merge it, we need you | ||
| to sign the [Daytona Contributor License Agreement](https://github.com/daytona/integrations/blob/main/CLA.md). | ||
| You only need to do this once, and it will cover all of your future | ||
| contributions to this repository. If you are signing on behalf of an | ||
| entity (for example, your employer), please also reply with the | ||
| entity's legal name and your role or title, and confirm that you are | ||
| authorized to bind it. Please read the CLA and, if you agree, post the | ||
| following comment on this PR: | ||
| custom-pr-sign-comment: 'I have read the CLA Document and I hereby sign the CLA' | ||
| custom-allsigned-prcomment: >- | ||
| All contributors have signed the CLA. ✅ Thank you! | ||