Skip to content

ci(cla): upgrade CLA Assistant action and fix CLA document link - #66

Open
massimim wants to merge 1 commit into
mainfrom
fix/cla-workflow-auth
Open

massimim wants to merge 1 commit into
mainfrom
fix/cla-workflow-auth

Conversation

@massimim

Copy link
Copy Markdown
Collaborator

Context

The CLA Assistant check has been failing on every PR (e.g. #64) with:

Error: Could not retrieve repository contents: Bad credentials. Status: 401
Error: Cannot read properties of undefined (reading 'data')

Because this workflow stores signatures in a separate repository (Autodesk/CLA-Signatures), the built-in GITHUB_TOKEN cannot reach it and the action falls back to the CLA_BOT_SECRET PAT. That PAT is expired or revoked, hence the 401. The second error is just fallout — the signature file fetch returned nothing and the action dereferenced .data on undefined.

⚠️ This PR does not fix the 401

The token lives in repository secrets, not in this file. An admin still has to rotate CLA_BOT_SECRET (Settings → Secrets and variables → Actions) with a token that has write access to Autodesk/CLA-Signatures: a classic PAT with repo scope, or a fine-grained PAT with Contents: Read and write. If SAML SSO is enforced on the Autodesk org, the new token must also be authorized for the org — a separate step after creation, and a common reason a fresh token still returns 401.

This PR clears the surrounding rot so the check works cleanly once the token is valid.

Changes

  • Upgrade contributor-assistant/github-action from v2.1.3-beta to v2.6.1, which clears the Node 20 deprecation warning currently emitted on every run. Upstream archived the project in March 2026, so v2.6.1 is the final release and the tag is mutable and unmaintained — it is pinned by commit SHA (ca4a40a7d1004f18d9960b404b97e5f30a505a08) so a compromised tag cannot inject code into a workflow that runs on pull_request_target.
  • Add an explicit permissions: block. The action needs statuses: write and pull-requests: write to post the check and the comment, plus actions: write to re-run itself. Inheriting the repository default is fragile if org-level workflow permissions change.
  • Point path-to-document at the actual Autodesk Individual CLA. It referenced Autodesk/CLA-Assistant-Test-Signatures, a setup leftover that does not match the signature store configured directly above it. The new URL matches the one already used in custom-notsigned-prcomment.

Verification

The action SHA was confirmed against the GitHub tags API, and the YAML parses. Full behaviour can only be verified after the token is rotated.

Made with Cursor

The CLA check has been failing on every PR with "Could not retrieve
repository contents: Bad credentials. Status: 401" followed by "Cannot
read properties of undefined (reading 'data')". The root cause is the
expired CLA_BOT_SECRET PAT, which has to be rotated in repository
secrets -- that is not fixable from this file. These are the surrounding
cleanups:

- Upgrade contributor-assistant/github-action from v2.1.3-beta to
  v2.6.1, clearing the Node 20 deprecation warning. Upstream archived
  the project in March 2026, so the action is pinned by commit SHA
  rather than the mutable tag.
- Add an explicit permissions block. v2.6.1 needs statuses/pull-requests
  write to post the check and comment, and actions:write to re-run it;
  relying on the repository default is fragile.
- Point path-to-document at the actual Autodesk Individual CLA. It was
  referencing Autodesk/CLA-Assistant-Test-Signatures, a setup leftover
  that does not match the signature store configured above.

Co-authored-by: Cursor <cursoragent@cursor.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant