Conversation
The CLA check has been failing on every PR with "Could not retrieve repository contents: Bad credentials. Status: 401" followed by "Cannot read properties of undefined (reading 'data')". The root cause is the expired CLA_BOT_SECRET PAT, which has to be rotated in repository secrets -- that is not fixable from this file. These are the surrounding cleanups: - Upgrade contributor-assistant/github-action from v2.1.3-beta to v2.6.1, clearing the Node 20 deprecation warning. Upstream archived the project in March 2026, so the action is pinned by commit SHA rather than the mutable tag. - Add an explicit permissions block. v2.6.1 needs statuses/pull-requests write to post the check and comment, and actions:write to re-run it; relying on the repository default is fragile. - Point path-to-document at the actual Autodesk Individual CLA. It was referencing Autodesk/CLA-Assistant-Test-Signatures, a setup leftover that does not match the signature store configured above. Co-authored-by: Cursor <cursoragent@cursor.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
The CLA Assistant check has been failing on every PR (e.g. #64) with:
Because this workflow stores signatures in a separate repository (
Autodesk/CLA-Signatures), the built-inGITHUB_TOKENcannot reach it and the action falls back to theCLA_BOT_SECRETPAT. That PAT is expired or revoked, hence the 401. The second error is just fallout — the signature file fetch returned nothing and the action dereferenced.dataonundefined.The token lives in repository secrets, not in this file. An admin still has to rotate
CLA_BOT_SECRET(Settings → Secrets and variables → Actions) with a token that has write access toAutodesk/CLA-Signatures: a classic PAT withreposcope, or a fine-grained PAT with Contents: Read and write. If SAML SSO is enforced on the Autodesk org, the new token must also be authorized for the org — a separate step after creation, and a common reason a fresh token still returns 401.This PR clears the surrounding rot so the check works cleanly once the token is valid.
Changes
contributor-assistant/github-actionfromv2.1.3-betatov2.6.1, which clears the Node 20 deprecation warning currently emitted on every run. Upstream archived the project in March 2026, sov2.6.1is the final release and the tag is mutable and unmaintained — it is pinned by commit SHA (ca4a40a7d1004f18d9960b404b97e5f30a505a08) so a compromised tag cannot inject code into a workflow that runs onpull_request_target.permissions:block. The action needsstatuses: writeandpull-requests: writeto post the check and the comment, plusactions: writeto re-run itself. Inheriting the repository default is fragile if org-level workflow permissions change.path-to-documentat the actual Autodesk Individual CLA. It referencedAutodesk/CLA-Assistant-Test-Signatures, a setup leftover that does not match the signature store configured directly above it. The new URL matches the one already used incustom-notsigned-prcomment.Verification
The action SHA was confirmed against the GitHub tags API, and the YAML parses. Full behaviour can only be verified after the token is rotated.
Made with Cursor