Skip to content

Contributor License Agreement (CLA) Flow

Marcel Boersma edited this page Feb 14, 2024 · 1 revision

Overview

Our repository utilizes the CLA Assistant GitHub Action to manage the Contributor License Agreement (CLA) signing process. This action enforces contributors to sign the CLA before their contributions can be merged. This document outlines the high-level workflow of the CLA signing process facilitated by the CLA Assistant.

Workflow

Trigger Events

The CLA Assistant is configured to react to specific events:

  • Issue Comments: Created comments on issues.
  • Pull Request Target: Actions such as opened, closed, and synchronized pull requests.

Permissions

The GitHub Action is explicitly granted permissions to write to actions, contents, pull requests, and statuses, ensuring it can operate effectively within the repository's workflow.

Jobs and Steps

  • The job runs on an ubuntu-latest environment.
  • The CLA Assistant step is triggered under the following conditions:
    • A comment in the issue contains 'recheck' or the CLA signing statement.
    • Any pull request target event occurs (opened, closed, synchronize).

Signature and Document Paths

  • Path to Signatures: Specifies where within the repository the signatures are stored.
  • Path to Document: The URL to the CLA or DCO document that contributors must sign.

Signing Process

  1. When a pull request is opened or a specific comment is made, the CLA Assistant checks if the contributor has signed the CLA.
  2. If not signed, the contributor is prompted to sign the CLA, guided by a link to the document.
  3. Upon signing, the CLA Assistant updates the status of the pull request, allowing it to proceed towards merging if all other conditions are met.

Additional Features

  • Whitelisting of specific users or bots, we whitelisted the dependabot.

This process ensures that all contributions are compliant with the repository's legal requirements, maintaining a clear record of CLA agreements.