Skip to content

fix(ci): CLA check skips bot PRs with exact allowlist - #12

Merged
ajianaz merged 1 commit into
developfrom
fix/cla-bot-allowlist
Aug 29, 2026
Merged

ajianaz merged 1 commit into
developfrom
fix/cla-bot-allowlist

Conversation

@ajianaz

@ajianaz ajianaz commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

What (description of the issues)

What (description of the change)

Add a job-level if: skip for bot PRs to the cla-check job: dependabot[bot], renovate[bot], github-actions[bot] (legacy app/ forms kept as fallback). This workflow version had no bot allowlist at all.

Why (reasoning and context)

Same bug family as uteke#1148. Live proof in this repo: open dependabot PR #10 (bump actions/github-script from 7 to 8) shows cla-check FAILURE — the synchronize event will now skip cla-check entirely.

Testing (how the change was tested)

  • YAML validated (parse + if: condition present with exact dependabot[bot] login)
  • One-line diff, identical pattern already CI-green and merged in uteke#1148
  • Once merged, PR chore(deps): bump actions/github-script from 7 to 9 #10's next push will skip cla-check — live E2E fixture

Same fix as uteke#1148 / vecq#14: dependabot PRs report their login as
'dependabot[bot]' in github.event.pull_request.user.login (REST form), so
bot PRs (e.g. #10) failed cla-check. This workflow version had no bot
allowlist at all — add the job-level skip with exact bot logins plus
legacy app/ forms as fallback.
@ajianaz
ajianaz merged commit 78749a9 into develop Aug 29, 2026
2 checks passed
@ajianaz
ajianaz deleted the fix/cla-bot-allowlist branch August 29, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant