mirror of
https://github.com/lightpanda-io/browser.git
synced 2026-07-30 17:25:58 -04:00
Mutable tags like @v6 can be re-pointed by whoever controls the action, so the next run executes code nobody here reviewed, with the job's token and secrets. Pinning to the full commit sha freezes what runs. Version tags are kept as comments so renovate or dependabot can still track updates. dtolnay/rust-toolchain is pinned to a master commit with the toolchain moved to an explicit input, as its readme recommends for sha pinning.
35 lines
1.1 KiB
YAML
35 lines
1.1 KiB
YAML
name: "CLA Assistant"
|
|
on:
|
|
issue_comment:
|
|
types: [created]
|
|
pull_request_target:
|
|
types: [opened,closed,synchronize]
|
|
|
|
permissions:
|
|
actions: write
|
|
contents: read
|
|
pull-requests: write
|
|
statuses: write
|
|
|
|
jobs:
|
|
CLAAssistant:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
|
|
steps:
|
|
- name: "CLA Assistant"
|
|
if: (github.event.comment.body == 'recheck' || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || github.event_name == 'pull_request_target'
|
|
uses: contributor-assistant/github-action@ca4a40a7d1004f18d9960b404b97e5f30a505a08 # v2.6.1
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
PERSONAL_ACCESS_TOKEN: ${{ secrets.CLA_GH_PAT }}
|
|
with:
|
|
path-to-signatures: 'signatures/browser/version1/cla.json'
|
|
path-to-document: 'https://github.com/lightpanda-io/browser/blob/main/CLA.md'
|
|
# branch should not be protected
|
|
branch: 'main'
|
|
allowlist: krichprollsch,francisbouvier,katie-lpd,sjorsdonkers,bornlex
|
|
|
|
remote-organization-name: lightpanda-io
|
|
remote-repository-name: cla
|