-
Notifications
You must be signed in to change notification settings - Fork 5
104 lines (91 loc) · 4.26 KB
/
Copy pathcla-check.yml
File metadata and controls
104 lines (91 loc) · 4.26 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
name: CLA Check
on:
pull_request:
types: [opened, synchronize, reopened]
permissions:
pull-requests: write
contents: read
jobs:
cla-check:
runs-on: ubuntu-latest
if: "!contains(fromJSON('[\"app/dependabot\", \"app/renovate\", \"github-actions[bot]\"]'), github.event.pull_request.user.login)"
steps:
- name: Fetch & check CLA signature
id: check
run: |
# Fetch signatures.json directly from raw GitHub (public repo)
# Use wget as primary (handles 200-with-404-body better than curl)
wget -q -O signatures.json "https://raw.githubusercontent.com/codecoradev/.github/main/.cla/signatures.json" 2>/dev/null \
|| curl -sfL "https://raw.githubusercontent.com/codecoradev/.github/main/.cla/signatures.json" -o signatures.json 2>/dev/null \
|| echo '{"signatures":[]}' > signatures.json
# Validate JSON — if invalid, use empty
python3 -c "import json; json.load(open('signatures.json'))" 2>/dev/null \
|| echo '{"signatures":[]}' > signatures.json
python3 - << 'EOF'
import json, os
author = os.environ["PR_AUTHOR"]
with open("signatures.json") as f:
data = json.load(f)
signatures = data.get("signatures", [])
found = any(
s.get("github_username", "").lower() == author.lower()
for s in signatures
)
with open(os.environ["GITHUB_OUTPUT"], "a") as f:
f.write(f"signed={'true' if found else 'false'}\n")
print(f"CLA signed by @{author}: {found}")
EOF
env:
PR_AUTHOR: ${{ github.event.pull_request.user.login }}
- name: Comment on PR (same-repo, best effort)
if: steps.check.outputs.signed != 'true' && github.event.pull_request.head.repo.full_name == github.repository
continue-on-error: true
uses: actions/github-script@v9
with:
script: |
const author = '${{ github.event.pull_request.user.login }}';
const prNumber = ${{ github.event.pull_request.number }};
const body = [
'## ⚠️ CodeCoraDev CLA Bot',
'',
`Hi @${author}! Thanks for your contribution.`,
'',
'Before this PR can be reviewed, please sign our Contributor License Agreement:',
'',
'- 📋 **Individual?** → [Sign CLA Individual](https://codecoradev.github.io/cla/?type=individual)',
'- 🏢 **Corporate?** → [Sign CLA Corporate](https://codecoradev.github.io/cla/?type=corporate)',
'',
'---',
'<sub>By signing, you agree to the terms in [CLA_INDIVIDUAL.md](https://github.com/codecoradev/.github/blob/main/CLA_INDIVIDUAL.md) or [CLA_CORPORATE.md](https://github.com/codecoradev/.github/blob/main/CLA_CORPORATE.md).</sub>',
].join('\n');
// Find existing CLA bot comment
const comments = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: prNumber,
});
const botComment = comments.data.find(c =>
c.user.login === 'github-actions[bot]' &&
c.body.includes('CodeCoraDev CLA Bot')
);
if (botComment) {
await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: botComment.id,
body,
});
} else {
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: prNumber,
body,
});
}
- name: Fail if not signed
if: steps.check.outputs.signed != 'true'
run: |
echo "::error title=CLA not signed::Sign the CodeCoraDev CLA at https://codecoradev.github.io/cla — once the signature PR is merged, this check turns green automatically (re-run it or wait ~1 hour)."
echo "❌ CLA not signed by ${{ github.event.pull_request.user.login }}"
exit 1